Brown and Caldwell Logo

Brown and Caldwell

Senior Cyber Security Engineer

Posted 28 Days Ago
Hybrid
Walnut Creek, CA, USA
129K-212K Annually
Senior level
Hybrid
Walnut Creek, CA, USA
129K-212K Annually
Senior level
Designs, automates, and supports complex cybersecurity solutions across cloud and infrastructure environments. Responsibilities include security alert monitoring, incident and vulnerability management, security architecture, SIEM tuning, access reviews, compliance with frameworks such as SOC 2 and CMMC, risk assessments, third-party security reviews, scripting, and secure technology guidance. The role also mentors team members and partners with technical and business stakeholders to improve security posture.
The summary above was generated by AI

The Senior Cyber Security Engineer protects the company's systems and information by designing, building, and supporting complex security solutions while driving the organization's compliance posture against applicable industry frameworks and client requirements. This role tackles ambiguous, high-impact security problems that lack predefined solutions and provides pragmatic, risk-based guidance for new technology initiatives with minimal oversight from the manager. Drawing on deep expertise across security tools, techniques, and processes, the Senior CSE monitors and responds to security alerts, manages incidents, and identifies and remediates vulnerabilities across the environment. The Senior CSE partners with technical teams and business stakeholders to focus on the highest priority risks while enabling the business to deliver client solutions securely. This position focuses on safeguarding valuable information through the establishment, enforcement, and managing of security standards.

Responsibilities

  • Work with BC employees to provide support on complex issues, address security questions, and address concerns/threats.
  • Identify opportunities to improve processes and tasks via automation or efficiency.
  • Perform complex scripting and script debugging for automating security tasks.
  • Anticipate security challenges and implement preventative measures.
  • Make critical decisions balancing risks and opportunities to impact positively the company's overall security.
  • Flexibility to adapt and execute various additional assignments based on evolving need

Additional Focus Areas

Security Engineering & Architecture

  • Design, build, and automate security solutions and tooling to detect, prevent, and manage threats across the environment.
  • Shape the security architecture of cloud and infrastructure environments.
  • Guide new technology initiatives with a security-first lens, providing pragmatic, risk-based recommendations that enable the business rather than block it.
  • Build and tune SIEM ingests, use cases, and alerting to sharpen detection capabilities.

Detection, Response & Access

  • Investigate and respond to alerts, incidents, and vulnerabilities, turning insight into action using established tools and playbooks.
  • Champion zero-trust and least-privilege access through regular access reviews.

Compliance & Risk

  • Drive compliance and control maturity against applicable industry frameworks and contractual security requirements (e.g., SOC2, CMMC), including control implementation, audit preparation, and remediation tracking.
  • Assess risk across supplier and third-party relationships, and support Legal with eDiscovery and preservation requests as needed.

Collaboration & Mentorship

  • Partner closely with technical and business teams to deliver secure, high-quality capabilities, prioritizing the risks that matter most.
  • Keep a pulse on emerging threats and technologies and help shape how the team responds to them.
  • Provide mentorship, guidance, and knowledge-sharing to help less experienced team members develop their skills and grow within their roles.

Skills and Competencies

  • Strong comprehension and demonstratable skills in information and data security principles and practices.
  • Data-driven decision-making ability, with strong analytical and problem-solving skills.
  • Excellent communication skills to effectively provide relevant technical guidance to a broad set of stakeholders and mentor employees.
  • Proven skills in application security, software development security, authentication security, SEIM, automation, incident management, vulnerability management, compliance, and security solution implementation.
  • Strong Microsoft/Azure security skills, including automation.

Experience

  • Typically, a minimum of 8 years of relevant cyber security experience.
  • Experience with incident and vulnerability management and security guidance.

Preferred Experience

  • Relevant governance/compliance certifications (e.g., CISSP, CISA, CRISC, CGRC) preferred.
  • 6+ years of direct cyber security experience, including hands-on compliance or audit-support work.
  • Working knowledge across many of the following domains, with deeper hands-on expertise in at least three or four: identity & access management; communications & network; asset; operations; software development; application; SIEM and detection engineering; automation/scripting; and assessment/compliance/audit support.
  • Working knowledge of AI-specific security considerations (e.g., securing AI/ML systems and evaluating AI-assisted tools for security use), and comfort using AI tools to improve security operations.

Education

  • A relevant degree in computer science, cybersecurity, information systems, or related field or equivalent experience is required.
  • Relevant certifications (CISSP, Security+, etc).

Learn more about our work:

Climate Change and Resilience - Brown and Caldwell

Data Center Water - Brown and Caldwell

Emerging Contaminants and PFAS - Brown and Caldwell

Digital Solutions - Brown and Caldwell

News - Brown and Caldwell

Projects - Brown and Caldwell

Industrial Water - Brown and Caldwell


Salary Range: The anticipated starting pay range for this position is based on the employee’s primary work location and may be more or less depending upon skills, experience, and education.  These ranges may be modified in the future.  

Location A: $129,000 - $177,000
Location B: $142,000 - $194,000
Location C: $155,000 - $212,000

You can view which BC location applies to you here. If you have any questions, please speak with your Recruiter. 

Benefits and Other Compensation:  We provide a comprehensive benefits package that promotes employee health, performance, and success which includes medical, dental, vision, short and long-term disability, life insurance, an employee assistance program, paid time off and parental leave, paid holidays, 401(k) retirement savings plan with employer match, performance-based bonus eligibility, employee referral bonuses, tuition reimbursement, pet insurance and long-term care insurance. Click here to see our full list of benefits. 

About Brown and Caldwell  

Headquartered in Walnut Creek, California, Brown and Caldwell is a full-service environmental engineering and construction services firm with 50 offices and over 2,100 professionals across North America and the Pacific. For more than 75 years, we have created leading-edge environmental solutions for municipalities, private industry, and government agencies. We strive to be the company of choice—to our clients, who benefit from our passion for delivering exceptional quality, and to our employees, present and future, who share our commitment to client service, collaboration, and innovation. Join us, and you will find a home where you can do your best work, reach new levels of expertise, and enjoy exceptional development opportunities. For more information, visit www.brownandcaldwell.com 

This position is subject to a pre-employment background check and a pre-employment drug test.  

Notice to Third Party Agencies: Brown and Caldwell does not accept unsolicited resumes from recruiters or employment agencies. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement and approved engagement request with Brown and Caldwell, Brown and Caldwell reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency.   

Brown and Caldwell is proud to be an EEO/AAP Employer. Brown and Caldwell encourages protected veterans, individuals with disabilities, and applicants from all backgrounds to apply. Brown and Caldwell ensures nondiscrimination in all programs and activities in accordance with Title VI of the Civil Rights Act.


Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
HQ

Brown and Caldwell Walnut Creek, California, USA Office

201 N Civic Dr, Walnut Creek, California, United States, 94596

Brown and Caldwell San Francisco, California, USA Office

San Francisco, United States

Similar Jobs

3 Days Ago
In-Office
131K-194K Annually
Senior level
131K-194K Annually
Senior level
Fintech • Payments
Applies security best practices to optimize systems, analyzes and resolves security challenges, drives cross-functional security initiatives, and collaborates with engineers to improve security processes and overall organizational security posture.
15 Days Ago
In-Office or Remote
United States
Senior level
Senior level
Healthtech
Leads exposure management and vulnerability management across cloud, hybrid, SaaS, applications, APIs, certificates, domains, and shadow IT. Identifies, validates, prioritizes, and reports vulnerabilities, misconfigurations, leaked data, and other cybersecurity risks. Designs and implements security solutions, supports remediation and penetration testing, integrates threat intelligence, advises on security architecture, and mentors team members. Requires advanced cybersecurity expertise, cross-functional collaboration, and knowledge of security frameworks and technologies.
Top Skills: Cloud SecurityEndpoint ProtectionHitrustIdentity And Access Management (Iam)Nist 800-53Security Information And Event Management (Siem)
One Month Ago
In-Office
Senior level
Senior level
Energy
Serve as the cybersecurity SME for the generation fleet: lead segmented architecture deployments and vulnerability remediation, develop fleet-wide standards, oversee compliance audits, lead incident root-cause analysis, build dashboards/metrics, and represent cybersecurity on capital projects and plant upgrades.
Top Skills: Control Systems EngineeringFirewallsIcs/Ot SecurityIndustrial NetworksJavaScriptNatNerc CipNetwork SegmentationPowershellPythonRoutingSwitchingTcp/IpVlans

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account