Principal Cyber Security Engineer, Technology and Digital, FT, 8:30A - 5P
Baptist Health26 days ago
Remote, United StatesStaff+
Base Salary
$145k - $188k/yr
Responsibilities
- Own the implementation, management, and continuous enhancement of security controls across organizational data, applications, systems, and networks.
- Define and maintain security standards, technical requirements, patterns, guardrails, and practices for cloud platforms, applications, APIs, AI solutions, and enterprise technologies.
- Provide senior technical direction for complex security issues involving cloud infrastructure, applications, AI solutions, third-party technologies, and emerging risks.
- Own AI security for LLM-based solutions, including AI gateways, model interactions, access controls, data protection, and security monitoring.
- Evaluate application security across IAM, authentication and authorization, machine-to-machine authentication, secrets, certificates, logging, monitoring, network controls, APIs, and data protection.
- Administer Cloudflare security capabilities, including WAF, access controls, traffic protections, and edge security for externally facing applications.
- Lead vulnerability and security-risk analysis across cloud, AI, applications, APIs, and infrastructure, including infrastructure-as-code and configuration reviews.
- Work with cross-functional engineering, operations, risk, and leadership teams to identify risks and drive secure implementations.
Requirements
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Electrical Engineering, or a related field.
- Minimum required experience of 8 years; the qualifications also state 12+ years of progressively responsible experience in information security or related technical disciplines.
- Deep experience securing enterprise applications, cloud platforms, APIs, infrastructure, and emerging technologies.
- Strong knowledge of AWS and GCP security, with familiarity with Azure and cloud infrastructure and operations.
- Knowledge of OWASP Top 10 risks for web applications, APIs, and LLM applications, including mitigation strategies.
- Advanced knowledge of IAM, OAuth, OIDC, SAML, JWT, machine identities, secrets management, certificates, encryption, authentication, and authorization.
- Experience securing AI and LLM-based applications, AI gateways, model access, data flows, third-party model integrations, and enterprise AI use cases.
- Strong experience with Cloudflare, WAFs, API protection, access controls, rate limiting, and edge-security protections.
- Familiarity with CI/CD, Git, infrastructure as code, containers, Terraform, configuration management, and cloud operations.
- Ability to review infrastructure-as-code, configurations, scripts, or source code for security weaknesses and drive remediation.
- Ability to independently analyze complex security risks, make decisions, and communicate requirements to engineers, stakeholders, and senior leadership.
- Master's degree and certifications such as AWS, GCP, Azure, OSCP, GWAPT, or eWPT are preferred.
Benefits
- Career growth and development opportunities with clear pathways and ongoing support.
- Comprehensive health and wellness resources.
- Wellness program that can help employees eliminate their medical plan deductible.
- Tuition reimbursement.
- Full-time schedule of 8:30 AM to 5:00 PM.