Назад
Company hidden
12 дней назад

Cybersecurity Engineer II (PAM/Zscaler)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Engineer II (PAM/Zscaler): Operating and improving privileged access management, Zscaler, DLP, Microsoft Entra ID, and network security controls across a hybrid infrastructure with an accent on data protection, identity security, and Zero Trust access. Focus on onboarding privileged accounts, tuning security policies, investigating DLP alerts, supporting access operations, and resolving complex platform and connectivity issues.

Location: Plano, Texas or Draper, Utah office, Monday through Friday, with travel between locations as necessary. Applicants must be authorized to work for any employer in the United States; visa sponsorship is not available.

Company

hirify.global provides technology-driven financial solutions through consumer-facing brands including Rent-A-Center, Acima, and Brigit across store-based and digital retail channels.

What you will do

  • Administer the Delinea Secret Server PAM platform, onboard privileged accounts, manage credential rotation and session recording, and reduce standing privilege through just-in-time access.
  • Deploy, manage, and support Zscaler Internet Access, Zscaler Private Access, and Client Connector, including policy administration, traffic forwarding, application segmentation, and troubleshooting.
  • Operate DLP controls across endpoint, network, email, web, and cloud channels using Microsoft Purview and Zscaler DLP.
  • Extend data protection controls to GenAI tools, external LLMs, and AI assistants; investigate DLP incidents and support DSPM remediation.
  • Maintain Microsoft Entra ID, Conditional Access, MFA, SSO integrations, access reviews, entitlement management, and Privileged Identity Management.
  • Support security tickets, network security engineering, vulnerability remediation, audit evidence collection, monitoring, and incident response.

Requirements

  • 3–5 years of hands-on experience in cybersecurity engineering, security operations, or related security infrastructure.
  • Hands-on PAM administration, preferably with Delinea Secret Server, including privileged account onboarding, credential rotation, and session management.
  • Experience deploying and supporting Zscaler ZIA and/or ZPA, DLP controls, policy authoring, alert triage, and false-positive tuning.
  • Working knowledge of TCP/IP, DNS, proxies, firewalls, VPN, network segmentation, and TLS/SSL inspection.
  • Experience supporting Microsoft Entra ID, Conditional Access, MFA, SSO integrations, Active Directory, and least-privilege principles.
  • Strong troubleshooting, documentation, communication, customer-service, and SLA-management skills.

Nice to have

  • Experience using GenAI assistants, LLM-based copilots, or agentic workflows for investigations, policy tuning, scripting, or documentation.
  • Zero Trust and ZTNA experience, including familiarity with NIST SP 800-207.
  • Experience with SIEM platforms such as Rapid7 or Microsoft Sentinel and cloud security in AWS, Azure, or GCP.
  • PowerShell or Python scripting experience and background in regulated consumer finance, payments, or retail environments.
  • Relevant security certifications, including Zscaler, CompTIA, Delinea, or CISSP.

Culture & Benefits

  • Office-based work in Plano or Draper from Monday through Friday.
  • Travel between the two office locations may be required for transformation and governance activities.
  • Work within an AI-native engineering organization using AI-driven workflows to improve security operations.
  • Collaborate with IAM, infrastructure, network, helpdesk, Data, Privacy, Compliance, HR, and Legal teams.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →