
Sr Security Engineer I - IAM / Cloud Security
CSX Corporation8 days ago
Jacksonville, FL, USASenior
Responsibilities
- Design, implement, integrate, and manage enterprise IAM and cloud security capabilities.
- Translate cybersecurity, architecture, operational risk, and compliance requirements into scalable controls, standards, architectures, engineering patterns, and implementation road maps.
- Automate provisioning, policy enforcement, evidence collection, configuration validation, remediation, reporting, and security control integrations.
- Develop and secure AI-enabled cybersecurity tooling and agentic workflows for identity and cloud security use cases.
- Integrate models, security tools, APIs, identity context, cloud telemetry, and security policies with least privilege, human approval, audit logging, testing, monitoring, rollback, and containment safeguards.
- Design secure cloud landing zones, identity boundaries, network controls, workload protections, key and secrets management, logging, monitoring, posture management, workload protection, infrastructure-as-code scanning, and policy-as-code.
- Design and improve identity governance, lifecycle management, SSO, federation, MFA, passwordless authentication, PAM, RBAC, ABAC, directory services, certificates, secrets, service accounts, and adaptive access controls.
- Investigate complex access, authentication, cloud, and AI-related security events and drive durable remediation.
- Participate in security architecture reviews, threat modeling, proofs of concept, change controls, production implementations, on-call support, and incident response.
- Define metrics and control-health indicators and share technical knowledge with colleagues, leaders, vendors, auditors, and industry partners.
Requirements
- Bachelor's degree or four-year degree and at least five years of information security experience focused on security architecture, security operations, cryptography, network security, or security forensics.
- Alternatively, a high school diploma/GED and at least ten years of relevant information security experience.
- Advanced expertise in IAM or cloud security and strong working knowledge of the complementary domain.
- Hands-on experience developing security automation or AI-enabled cybersecurity tooling and agentic security workflows.
- Working knowledge of Zero Trust, least privilege, defense in depth, secure-by-design practices, threat modeling, and security architecture.
- Working knowledge of a general-purpose programming or scripting language, APIs, secure software development, infrastructure as code, configuration management, CI/CD, DevSecOps, testing, version control, and security automation.
- Experience with model and security API integration, retrieval and grounding using authorized security data, prompt and agent security, tool authorization, identity propagation, data protection, evaluation, observability, human-in-the-loop controls, and mitigation of prompt injection, data leakage, hallucination, excessive agency, and unsafe actions.
- Ability to collaborate across teams, communicate technical information to varied audiences, produce clear documentation, maintain confidentiality, and support incident response or on-call needs.
- Preferred qualifications include CISSP, CCSP, IAM-focused, or cloud security certifications; experience with Microsoft Entra ID, Active Directory, PAM, federation, Azure, AWS, or Google Cloud; and experience governing AI-enabled security capabilities.