SonicJobs Logo
Left arrow iconBack to search

Sr Security Engineer I - IAM / Cloud Security

CSX
Posted 21 hours ago, valid for a month
Location

Jacksonville, FL, US

Salary

Competitive

Contract type

Full Time

Wellness Program

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Senior Security Engineer role focuses on providing expertise in Identity and Access Management (IAM) and cloud security, requiring a minimum of 5 years of relevant experience or 10 years with a high school diploma.
  • Responsibilities include designing and implementing security controls, developing AI-enabled tooling, and collaborating across various teams to enhance security measures.
  • The position requires strong knowledge in security automation, DevSecOps, and threat detection, along with hands-on experience in developing security solutions.
  • Preferred qualifications include certifications such as CISSP or cloud security certifications for major platforms like AWS or Azure.
  • The salary for this role is competitive and includes an annual bonus opportunity, alongside comprehensive benefits that support employee well-being.

Job Summary

The Senior Security Engineer provides senior-level technical expertise across Identity and Access Management (IAM) and cloud security, with advanced expertise in at least one domain and strong working knowledge of the other. The role designs, implements, automates, and continuously improves identity and cloud security controls; develops AI-enabled security tooling, including agentic workflows; contributes to complex engineering initiatives; and collaborates with architecture, platform, application, operations, risk, and compliance teams. The Engineer applies strong working knowledge of security automation, DevSecOps, artificial intelligence and machine learning, security analytics, threat detection and response, control validation, data protection, and responsible human oversight.

Core Specializations

Cloud Security - Provides senior-level engineering for secure cloud architecture and operations across one or more major cloud platforms. Designs preventive and detective controls for identity, workload, network, data, secrets, logging, posture management, and DevSecOps; automates policy enforcement; and uses AI-assisted analytics to identify misconfigurations, anomalous activity, attack paths, and control gaps.

Identity and Access Management (IAM) - Provides senior-level engineering for workforce, privileged, machine, and cloud identities. Designs and improves identity lifecycle management, authentication, authorization, federation, access governance, privileged access, and Zero Trust controls. Applies AI-assisted analytics to improve entitlement discovery, role engineering, access reviews, anomaly detection, and risk-based access decisions.

 

Primary Activities and Responsibilities

  • Contribute to the design, implementation, integration, and lifecycle management of enterprise IAM or cloud security capabilities.
  • Translate cybersecurity, architecture, operational risk, and compliance requirements into scalable security controls, standards, architectures, engineering patterns, and implementation road maps.
  • Engineer automation for provisioning, policy enforcement, evidence collection, configuration validation, remediation, and operational reporting.
  • Develop AI-enabled cybersecurity tooling and agentic security workflows for identity and cloud security use cases, including entitlement analysis, control configuration validation, security evidence collection, investigation, remediation recommendations, and explicitly approved security actions. Integrate models, security tools, APIs, identity context, cloud telemetry, and security policies while enforcing least privilege, bounded autonomy, human approval, audit logging, security testing, continuous monitoring, and safe-failure behavior.
  • Perform security engineering and assurance for AI-enabled cybersecurity capabilities and agentic security workflows by evaluating task effectiveness, accuracy, resilience, privacy, explainability, misuse risk, data quality, prompt injection, tool misuse, excessive agency, and operational impact. Implement human review, access control, security validation, auditability, monitoring, rollback, and containment safeguards.
  • Participate in security architecture reviews, threat modeling, security capability evaluations, security-focused proofs of concept, change controls, and production implementation of cybersecurity controls.
  • Investigate complex access, authentication, cloud, and AI-related security events; identify root causes and drive durable remediation.
  • Define metrics and control-health indicators that demonstrate risk reduction, control effectiveness, reliability, and user experience.
  • Share technical knowledge with colleagues and collaborate with leaders, vendors, auditors, and industry partners as appropriate.
  • Participate in on-call support and incident response when required.

 

Cloud Security Responsibilities

  • Design secure landing zones, identity boundaries, network controls, workload protections, key and secrets management, logging, and monitoring across major cloud platforms.
  • Implement cloud security posture management, workload protection, infrastructure-as-code scanning, policy-as-code, and automated remediation.
  • Integrate cloud security controls into CI/CD pipelines and collaborate with cloud, platform, DevOps, application development, data, and enterprise architecture teams to embed, validate, and operate cybersecurity requirements.
  • Apply AI-assisted analytics to cloud telemetry and exposure data to identify anomalous behavior, attack paths, misconfigurations, excessive permissions, and emerging threats.
  • Secure AI-enabled cybersecurity applications, agentic security workflows, and supporting cloud services, including workload and non-human identities, tool and API authorization, security data and model access, secrets, logging, monitoring, deployment pipelines, and containment controls.

 

Identity and Access Management (IAM) Responsibilities 

  • Design and improve identity governance, identity lifecycle, SSO, federation, MFA, passwordless authentication, PAM, RBAC, and ABAC capabilities.
  • Design and support directory services, identity repositories, synchronization, and authoritative identity data across hybrid environments.
  • Implement and maintain certificate-based identity and authentication controls for users, devices, applications, services, and workloads.
  • Manage the lifecycle of secrets, credentials, keys, certificates, service accounts, and other non-human identities, including issuance, storage, rotation, revocation, monitoring, and recovery.
  • Design and improve conditional, adaptive, and risk-based access controls using identity, device, location, behavior, workload, and contextual signals.
  • Engineer secure access for workforce, privileged, service, machine, application, API, and cloud identities across hybrid environments.
  • Automate joiner, mover, and leaver processes; access requests; approvals; certifications; segregation-of-duties checks; and entitlement remediation.
  • Use AI-assisted analytics for role mining, entitlement clustering, access-risk scoring, anomalous authentication detection, access-review prioritization, and policy recommendations.
  • Develop guardrails that prevent automated or AI-generated access decisions from bypassing approvals, least privilege, segregation of duties, auditability, or human oversight.

 

Minimum Qualifications

  • Bachelor's Degree/4-year Degree
  • 5 or more years of experience in formation Security with focus specifically on Security Architecture, Security Operations, Cryptography, Network Security or Security Forensics

 

Equivalent Minimum Qualifications

  • High School Diploma/GED
  • 10 or more years of experience in formation Security with focus specifically on Security Architecture, Security Operations, Cryptography, Network Security or Security Forensics

 

Preferred Qualifications

  • CISSP, CCSP, or equivalent senior-level security certification.
  • IAM-focused certification or advanced experience with identity governance, PAM, federation, Microsoft Entra ID, Active Directory, or comparable platforms.
  • Cloud security certification for Microsoft Azure, AWS, Google Cloud, or equivalent demonstrated expertise.
  • Hands-on experience developing, integrating, testing, and operating AI-enabled cybersecurity tooling or agentic security workflows using models, security APIs, retrieval or authorized enterprise security data sources, tool orchestration, evaluation methods, and security guardrails.
  • Experience governing AI-enabled security capabilities, including data protection, model and service access, validation, monitoring, human oversight, and risk management.

 

Knowledge and Skills

  • Advanced expertise in IAM or cloud security, strong working knowledge of the complementary domain, and demonstrated hands-on experience developing security automation or AI-enabled security tooling that applies identity and cloud controls.
  • Strong working knowledge of Zero Trust, least privilege, defense in depth, secure-by-design practices, threat modeling, and security architecture.
  • Strong working knowledge of a general-purpose programming or scripting language, APIs, secure software development practices, infrastructure as code, configuration management, CI/CD, DevSecOps, testing, version control, and security automation sufficient to build and maintain production-quality cybersecurity tooling and control integrations.
  • Strong working knowledge of security telemetry, identity data, cloud logs, graphs, and analytics platforms sufficient to produce actionable risk insights.
  • Strong working knowledge of AI and machine learning concepts and hands-on ability to develop secure AI-enabled cybersecurity tooling and agentic security workflows that implement or improve security controls. Required capabilities include model and security API integration, retrieval and grounding with authorized security data, prompt and agent security, tool authorization, identity propagation, data protection, evaluation, observability, human-in-the-loop controls, and mitigation of prompt injection, data leakage, hallucination, excessive agency, and unsafe actions.
  • Ability to contribute effectively to complex projects, collaborate across teams, share knowledge with peers, communicate technical information to varied audiences, and produce clear technical documentation.
  • Ability to operate effectively in a fast-paced environment, maintain confidentiality, and support incident response or on-call needs.

CSX is passionate about building a workforce that reflects the values and behaviors of ONE CSX. We are nationally recognized for our commitment to diversity and engagement, as well as our support for veterans and reservists. 
CSX, based in Jacksonville, Florida, is a premier transportation company. It provides rail, intermodal and rail-to-truck transload services and solutions to customers across a broad array of markets, including energy, industrial, construction, agricultural, and consumer products. For nearly 200 years, CSX has played a critical role in the nation's economic expansion and industrial development. Its network connects every major metropolitan area in the eastern United States, where nearly two-thirds of the nation's population resides. It also links more than 230 short-line railroads and more than 70 ocean, river and lake ports with major population centers and farming towns alike. More information about CSX Corporation and its subsidiaries is available at www.csx.com. Connect with us on Facebook  X  LinkedIn  Instagram   YouTube

Closing Statement

At CSX, two of our six Guiding Principles are Valuing and Developing Employees as well as Operating Safely. We are committed to offering our team members the most competitive compensation and benefits package available, unlimited opportunities for development and growth throughout an exciting and rewarding career, and the safest work environment possible.
CSX is an Equal Opportunity Employer Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Click here to view the EEO is Law poster. 
CSX Transportation and its subsidiaries are not seeking outside assistance or accepting unsolicited resumes from staffing agencies or search firms for employment or contractor opportunities. Any resumes submitted by an outside vendor to any employee at CSX via e-mail, Internet, or directly to hiring managers without a valid written search agreement in place with the Talent Acquisition / HR department will be deemed the sole property of CSX. No placement fee will be paid in the event a candidate is hired as a result of the referral, or through other means.
This role offers an annual salary range based on experience and qualifications. In addition to base salary we provide an annual bonus opportunity. 
At CSX, we prioritize valuing and developing employees, as well as operating safely. We are committed to offering our team members competitive compensation, a comprehensive benefits package, and unlimited growth opportunities. Our benefits support financial, physical, emotional, and social well-being, with health plans, wellness programs, and customizable coverage options. Learn more about our benefits here. 



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.