ForgeApply · Job listing
Lead Engineer, Cyber Security
Trinity
See all 45 open roles at Trinity →
Tailor your resume for this Trinity job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Trinity's site. Free trial, no card required.
About this role
Position Summary
Trinity seeks an experienced Cybersecurity Engineer to join its Cybersecurity team. The successful candidate will serve as a technical architect and hands-on engineer, designing, implementing, hardening, and monitoring security controls across Trinity's multi-cloud infrastructure (Azure, AWS and GCP), applications, and endpoints. This role bridges security strategy with tactical execution, requiring both deep technical expertise and the ability to translate complex security requirements into operationally effective solutions. The Cybersecurity Engineer will partner with infrastructure, application development, incident response, and business teams to embed security into architecture, deployment pipelines, and operational processes.
Essential Functions
Cloud Security Architecture & Engineering • Design and implement security architectures for Azure and AWS environments following Zero Trust principles, including identity governance (Entra ID/IAM), network segmentation, private endpoints, NSGs, Security Groups, and Azure Firewall/AWS WAF configurations.
• Architect and deploy data protection controls (encryption at-rest and in-transit, key management, secrets rotation) across cloud services (VMs, App Service, AKS/EKS, databases, storage accounts, S3/ADLS).
• Conduct cloud infrastructure assessments, identify misconfigurations and compliance gaps, and develop remediation plans aligned with Azure/AWS Well-Architected security pillars.
• Define and enforce security baselines and cloud infrastructure hardening standards aligned with CIS Controls, NIST 800-53, and industry best practices.
Security Operations, Monitoring & Incident Response • Lead design and optimization of security monitoring and alerting (Splunk SIEM, SentinelOne EDR, Snyk, InsightVM and Appsec vulnerability management tools) to detect, investigate, and respond to security incidents in cloud and on-premises environments.
• Develop and maintain detection rules, correlation logic, and automated response playbooks for SOC-driven incident detection and response.
• Participate in threat hunting, security assessments, and penetration testing to proactively identify and validate security weaknesses.
• Lead or co-lead incident response investigations; document findings, root causes, and recommendations to prevent recurrence.
Application & Data Security • Define and enforce data classification, handling, and loss prevention (DLP) policies for regulated data (healthcare, pharmaceutical, client IP).
• Lead or oversee vulnerability assessments, secure code reviews, and penetration tests for critical applications.
• Support the DevSecOps lead with API security, authentication/authorization design, and secrets management for application tiers.
Compliance, Risk & Governance • Support CISO with compliance program execution: map security controls to regulatory requirements (SOC 2, ISO 27001, ISO 42001 roadmap, HIPAA, GDPR), manage audit evidence, and track remediation of findings.
• Develop and maintain security policies, procedures, and technical standards for cloud, endpoints, applications, and third-party integrations.
• Conduct risk assessments (cloud, third-party, SDLC, AI systems) and recommend risk mitigation strategies; document findings in risk registers.
• Support vendor risk management: evaluate security postures of cloud providers, SaaS vendors, and critical suppliers.
AI & Emerging Technology Security • Support the AI Governance Board with security assessment and controls design for AI/ML systems and model deployments (e.g., Azure AI Foundry, GPT-4/5 usage, responsible AI frameworks).
• Define guardrails, data minimization, and safety controls for generative AI applications.
• Lead or advise on secure AI architecture and monitoring to detect model drift, adversarial inputs, and unauthorized use.
Technical Leadership & Mentoring • Provide technical security guidance and mentoring to junior team members and cross-functional teams.
• Develop training materials, runbooks, and documentation for security procedures and tools.
• Lead or participate in security communities of practice and technology evaluations.
Position Requirements
Education: Bachelor's degree in Computer Science or related field Work Experience: • 5+ years of security engineering cloud security, or infrastructure security roles.
• 4+ years of hands-on experience designing and implementing security solutions in Azure and AWS environments (IaaS, PaaS, SaaS services).
• Demonstrated experience with cloud security frameworks (Azure Security Benchmark, AWS Well-Architected Security Pillar, CIS Controls).
• 3+ years of incident response, threat detection, or SOC operations experience.
• Solid understanding of identity and access management, encryption, network security, and secure SDLC.
Other Skills: Knowledge and/or working skills in the following areas: • Understanding of modern threats and exploits
• Ability to assist in designing correction plans, mitigations, and full remediation actions
• Ability to understand and communicate attack chains to management and key stakeholders
• Knowledge of WAFs and SD-WAN
• Experience with network monitoring and breach monitoring tools.
• Hands-on experience with AI/ML security, responsible AI governance, or model monitoring.
• Experience with zero-trust architecture design and implementation.
• Familiarity with container security (Kubernetes, Docker) and serverless security (Lambda, Azure Functions).
• Prior experience in SOC design, threat intelligence, or security architecture roles.
• Experience with third-party risk management or vendor security assessments.
• Cloud experience including Windows and Linux administration and/or engineering
• Experience and understanding of EDR platforms such as SentinelOne
• Show a solid knowledge of modern security frameworks, models and standards
• Experience writing scripts in Python, Powershell, Perl, Ruby, Bash, Grep/Sed/Awk
• Under
Salary insight
The midpoint of this range ($173k) is about 6% above the median disclosed salary for New York roles listed on ForgeApply ($163k across 10,123 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Trinity role before you apply.
Tailor my resume for this jobSimilar jobs
- Principal Engineer, Cybersecurity — Baxter · Skaneateles, NY
- Sr Engineer, Cybersecurity — T-Mobile · Bellevue, Washington | Chicago, Illinois | Frisco, Texas
- Cyber Security Engineering Lead — CACI · North Charleston, SC
- Senior Security Engineer, Cybersecurity — Fubotv · New York, NY
- Lead Cybersecurity Engineer — Visa · US - Foster City, CA
- Lead Cyber Security Engineer — MGM Resorts International · Home Office - US, NV | Home Office - US, NJ | Home Office - US, MI
- Cyber Product Security Engineer, Lead — Toyota · Plano, Texas
- Space Cybersecurity Engineering Lead — The Aerospace Corporation · Los Angeles AFB, CA
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)