Logo for Aprio

Senior Cybersecurity Engineer

Role overview

Qualifications

  • 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring
  • Strong fundamentals in IAM, network segmentation, encryption/key management, and centralized logging/monitoring
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity
  • Excellent written and verbal communication; able to explain tradeoffs across Security, IT, and delivery audiences in plain language

Responsibilities

  • Own the operational health of one or two engineering domains (identity, network segmentation, cloud security baselines, etc.)
  • Lead cross-team initiatives that span Security, IT, Identity, Cloud Operations, and delivery teams
  • Design new control patterns and reference architectures; write decision records, runbooks, and standards
  • Pair with Mid and Associate engineers, run design reviews, and provide substantive code/config review

About the company

Aprio logo

Aprio

Accounting

Aprio is a premier CPA and business advisory firm that advises clients and associates on how to achieve what’s next. Aprio’s associates work as integrated teams across advisory, assurance, tax, outsourcing, staffing and private client services, bringing the best thinking and personal commitment to each client. Across practices, Aprio brings together proven expertise, deep understanding and strategic foresight for industries including Manufacturing and Distribution; Non-Profit and Education; Professional Services; Real Estate and Construction; Retail, Franchise and Hospitality; and Technology and Blockchain. Headquartered in Atlanta, Georgia, Aprio has grown to over 1,000+ team members. To serve clients wherever life or business may take them, Aprio’s teams speak more than 30 languages and work with clients in over 50 countries.

Company details

Company typeLarge
IndustryAccounting
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio's Information Technology team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Cybersecurity Engineer to join their dynamic team.
 
Aprio’s Cybersecurity Engineering team builds and operates the controls that make the firm defensible: identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Senior Cybersecurity Engineer is the senior individual contributor on that team — the engineer who takes a control domain from “documented” to “running cleanly in production,” sets the standard for how it’s done, and pulls the Mid and Associate engineers up with them. This is a hands-on engineering role that also leads cross-team initiatives.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.


What You'll Do:
  • You will own the operational health of one or two engineering domains, lead cross-team initiatives that touch multiple control areas, and design the patterns the rest of the team executes against.
  • You’re the engineer who can take a tool from “purchased” to “deployed, tuned, and instrumented,” the partner Cloud Ops and Identity call when they need a security pattern that actually works, and the senior who makes the Mid and Associate engineers better through pairing, code review, and clear standards.
  • You’ll also be a senior voice in architecture and decision conversations alongside the Principal Engineer and the Manager.

  • Key Responsibilities:
  • Domain ownership: Own the operational health of one or two engineering domains (identity, network/segmentation, cloud security baselines, monitoring/logging, encryption/key management, endpoint, vulnerability management, configuration management). Keep them measurably healthy and improving.
  • Cross-team initiatives: Lead initiatives that span Security, IT, Identity, Cloud Operations, and delivery teams — controlled rollouts, control set hardening, tool migrations. Land them without breaking production.
  • Architecture and standards: Design new control patterns and reference architectures. Write the decision records, runbooks, and standards the team executes against and the auditors review.
  • Controlled rollouts: Lead the end-to-end deployment of new control sets (e.g., bringing a new EDR online, hardening a new cloud account, standing up new logging pipelines) — pilot, measure, expand, document.
  • Mentorship: Pair with Mid and Associate engineers, run design reviews, give substantive code/config review, and grow the next tier. Quality of output from less senior engineers is part of your scope.
  • Operational partnership: Be the senior partner Cloud Ops, Identity, IT Service Management, GRC, and the SOC call when they need security engineering input. Solve problems with them, not at them.
  • Detection/response engineering support: Partner with Detection Engineering and the SOC on logging coverage, telemetry quality, and the engineering pieces of response (privileged access tooling, isolation capabilities, evidence capture).
  • Evidence and audit readiness: Produce control evidence and architecture documentation that holds up under audit and peer review. Keep your domains’ evidence map current.
  • Automation: Push toward repeatable, codified controls (IaC, policy-as-code, automated evidence collection) instead of one-off manual work.

  • What Success Looks Like:

    First 30–60 days: You can operate your priority domains safely on Aprio’s tooling, you’ve assessed current control posture, and you’ve published a prioritized remediation backlog for at least one domain.

    By 90 days: You’re leading at least one cross-team initiative, you’ve published or substantially revised at least one architecture pattern or decision record, and you’re an active mentor to the Mid and Associate engineers.

    By 6–12 months: Your domains have measurably improved control health (less drift, cleaner evidence, faster remediation, fewer escalations). At least one controlled rollout has landed cleanly. Less senior engineers on the team are visibly better because of how you work with them.


    Required Qualifications:
  • 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring.
  • Strong fundamentals in IAM, network segmentation, encryption / key management, and centralized logging / monitoring.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity.
  • Ability to produce clear architecture documentation, runbooks, and decision records that hold up under audit and peer review.
  • Excellent written and verbal communication; able to explain tradeoffs across Security, IT, and delivery audiences in plain language.
  • Comfortable mentoring less senior engineers and owning quality-of-output for one or more domains.

  • Preferred Qualifications
  • Regulated-environment experience (CMMC, NIST 800-171, NIST 800-53, FedRAMP-aligned, SOC 2, ISO 27001, HIPAA, PCI).
  • Infrastructure-as-code experience (Terraform, Bicep, Pulumi) and policy-as-code (Sentinel, OPA).
  • Security tooling integration experience (SIEM, EDR, vulnerability scanning, IAM, secrets management).
  • Industry certifications (one or more): CISSP, CCSP, GIAC (e.g., GCED, GPEN, GCWN), AZ-500, AWS Security Specialty.
  • Experience supporting a SOC’s detection/response engineering needs.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience
  • The application window is anticipated to close on July 27th and may be extended as needed.

    Why work for Aprio:
    Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.
     
     
    Perks/Benefits we offer for full-time team members:
    - Medical, Dental, and Vision Insurance on the first day of employment
    - Flexible Spending Account and Dependent Care Account
    - 401k with Profit Sharing
    - 9+ holidays and discretionary time off structure
    - Parental Leave – coverage for both primary and secondary caregivers
    - Tuition Assistance Program and CPA support program with cash incentive upon completion
    - Discretionary incentive compensation based on firm, group and individual performance
    - Incentive compensation related to origination of new client sales
    - Top rated wellness program
    - Flexible working environment including remote and hybrid options
     
     
    What’s in it for you:
    - Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.
    - An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.
    - A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.
    - Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.
    - Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.
    - Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.
     
     
    EQUAL OPPORTUNITY EMPLOYER
    Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.
     
    Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Cybersecurity Engineer Related jobs

    Other jobs at Aprio

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.