CSX Corporation

Sr Security Engineer I - IAM / Cloud Security

CSX Corporation
Apply
8 days ago
Jacksonville, FL, USASenior

Responsibilities

  • Design, implement, integrate, and manage enterprise IAM and cloud security capabilities.
  • Translate cybersecurity, architecture, operational risk, and compliance requirements into scalable controls, standards, architectures, engineering patterns, and implementation road maps.
  • Automate provisioning, policy enforcement, evidence collection, configuration validation, remediation, reporting, and security control integrations.
  • Develop and secure AI-enabled cybersecurity tooling and agentic workflows for identity and cloud security use cases.
  • Integrate models, security tools, APIs, identity context, cloud telemetry, and security policies with least privilege, human approval, audit logging, testing, monitoring, rollback, and containment safeguards.
  • Design secure cloud landing zones, identity boundaries, network controls, workload protections, key and secrets management, logging, monitoring, posture management, workload protection, infrastructure-as-code scanning, and policy-as-code.
  • Design and improve identity governance, lifecycle management, SSO, federation, MFA, passwordless authentication, PAM, RBAC, ABAC, directory services, certificates, secrets, service accounts, and adaptive access controls.
  • Investigate complex access, authentication, cloud, and AI-related security events and drive durable remediation.
  • Participate in security architecture reviews, threat modeling, proofs of concept, change controls, production implementations, on-call support, and incident response.
  • Define metrics and control-health indicators and share technical knowledge with colleagues, leaders, vendors, auditors, and industry partners.

Requirements

  • Bachelor's degree or four-year degree and at least five years of information security experience focused on security architecture, security operations, cryptography, network security, or security forensics.
  • Alternatively, a high school diploma/GED and at least ten years of relevant information security experience.
  • Advanced expertise in IAM or cloud security and strong working knowledge of the complementary domain.
  • Hands-on experience developing security automation or AI-enabled cybersecurity tooling and agentic security workflows.
  • Working knowledge of Zero Trust, least privilege, defense in depth, secure-by-design practices, threat modeling, and security architecture.
  • Working knowledge of a general-purpose programming or scripting language, APIs, secure software development, infrastructure as code, configuration management, CI/CD, DevSecOps, testing, version control, and security automation.
  • Experience with model and security API integration, retrieval and grounding using authorized security data, prompt and agent security, tool authorization, identity propagation, data protection, evaluation, observability, human-in-the-loop controls, and mitigation of prompt injection, data leakage, hallucination, excessive agency, and unsafe actions.
  • Ability to collaborate across teams, communicate technical information to varied audiences, produce clear documentation, maintain confidentiality, and support incident response or on-call needs.
  • Preferred qualifications include CISSP, CCSP, IAM-focused, or cloud security certifications; experience with Microsoft Entra ID, Active Directory, PAM, federation, Azure, AWS, or Google Cloud; and experience governing AI-enabled security capabilities.

Tech Stack

AWSAzureGoogle Cloud

Categories

CSX Corporation

About CSX Corporation

10,000+ employees
Contact me