Prepin
Log in
CBIZ

engineering opportunity

Security Engineer

The Security Detection Engineer is responsible for designing, deploying, and maintaining security detections across various platforms to identify suspicious activity. They also lead incident response efforts, perform root-cause analysis, and utilize automation to improve security controls and operational efficiency.

Seven Hills, Ohio, United StateshybridFULL_TIME

Posted

About the role

What will you do at CBIZ?

#LI-CR2 #LI-Hybrid

RESPONSIBILITIES

The Security Detection Engineer is a senior, hands-on technical role responsible

for building, tuning, validating, and operating security detections across CBIZ

environments. Detection engineering is the core of the role: translating threat

intelligence, adversary behavior, incident findings, and business risk into

dependable analytics that identify suspicious activity with useful context. The

engineer also investigates incidents, improves supporting controls, and uses

automation to increase speed, consistency, and coverage. This is not a passive

monitoring or ticket-routing role; the engineer owns detection problems from

use-case design and telemetry validation through deployment, triage support,

measurement, and continuous improvement.

Essential Functions and Primary Duties

Detection Engineering and Threat Analytics

* Design, test, deploy, document, and maintain detection content across SIEM,

XDR, NDR, identity, email, endpoint, network, cloud, and application security

platforms.

* Turn threat intelligence, adversary tactics and techniques, incident

findings, and business risk into prioritized detection use cases; develop

behavioral, correlation, threshold, anomaly, and indicator-based analytics.

* Map detection coverage to recognized adversary behaviors and maintain clear

traceability among threats, telemetry, analytics, response actions, and

control owners.

* Validate detections through structured testing, historical-log review, attack

simulation, purple-team exercises, and post-incident analysis; tune for

meaningful signal while reducing false positives and duplicates.

* Own the detection lifecycle, including intake, prioritization, peer review,

testing, release, version control, performance review, exception handling,

and retirement.

* Monitor detection health, data freshness, rule execution, alert quality, and

coverage gaps; drive corrective action when controls or telemetry degrade.

Telemetry, Logging, and Detection Architecture

* Partner with cloud, identity, endpoint, network, infrastructure, and

application teams to onboard, normalize, and retain security-relevant

telemetry.

* Assess log quality and availability, including timestamps, identity context,

event fidelity, field mapping, parsing, retention, and ingestion health

required for reliable investigations and detections.

* Document data dependencies and recovery procedures for critical detections,

and contribute to detection architecture, data-source strategy, and use-case

roadmaps across hybrid and multi-cloud environments

Security Operations, Incident Response, and Engineering

* Investigate and respond to alerts and incidents across SIEM, XDR, NDR,

identity, email, endpoint, network, and cloud platforms; lead work from

triage and scoping through containment, eradication, recovery, validation,

and lessons learned.

* Perform root-cause analysis, reconstruct activity across data sources,

preserve relevant evidence, validate remediation, and convert incidents, near

misses, and control failures into improved detections, playbooks, and

preventive controls.

* Configure, harden, maintain, and troubleshoot security controls across

Microsoft Azure, Azure Virtual Desktop, AWS, and Microsoft 365 security and

compliance platforms, including identity protection, Conditional Access,

email defense, endpoint security, DLP, cloud workload protection, and tenant

baselines.

* Support certificate-based authentication, encryption, and PKI dependencies;

coordinate remediation and control changes with technology owners and confirm

intended security outcomes.

* Participate in an on-call rotation and after-hours response as needed.

Automation, Documentation, and Collaboration

* Use PowerShell, Python, Bash, APIs, SOAR workflows, and other automation

methods to enrich alerts, test controls, improve data quality, orchestrate

response, and reduce repetitive work.

* Build reusable queries, scripts, integrations, dashboards, investigation

guidance, runbooks, playbooks, SOPs, and knowledge articles that improve

operational consistency.

* Evaluate AI-enabled security capabilities responsibly to improve detection

development and investigation efficiency while retaining appropriate human

review and control.

* Partner with Security Operations, GRC, IT, Cloud, Networking, Systems,

Endpoint, application owners, threat intelligence, vulnerability management,

and red/purple teams; provide technical guidance and peer review when

appropriate.

Preferred Qualifications

  • * 3-5 years of experience in information security, security operations,
  • detection engineering, incident response, threat hunting, or security
  • engineering.
  • * Proven hands-on experience creating and tuning detections in an enterprise
  • SIEM, XDR, or comparable security analytics platform.
  • * Strong ability to analyze authentication, endpoint, network, email, cloud,
  • and application telemetry and translate findings into durable detection
  • logic.
  • * Hands-on experience with security investigations, incident response, log
  • analysis, root-cause analysis, and remediation validation.
  • * Working knowledge of adversary behavior, common attack techniques, detection
  • lifecycle practices, and methods for validating detection coverage.
  • * Experience securing Azure and/or AWS environments and operating Microsoft 365
  • security capabilities; experience supporting or securing Azure Virtual
  • Desktop is required.
  • * Working knowledge of PKI, certificate-based authentication, encryption,
  • enterprise logging architectures, networking, identity and access, endpoint
  • security, and malware fundamentals.
  • * Strong PowerShell skills and experience with Linux command-line
  • administration, logs, and services; ability to work independently, exercise
  • sound judgment, and drive complex work to completion.
  • * Advanced skill with SIEM query languages, detection-as-code, source control,
  • testing frameworks, SOAR, APIs, and automated response.
  • * Experience with threat hunting, attack simulation, purple teaming, adversary
  • emulation, breach-and-attack simulation, or measuring detection coverage and
  • quality.
  • * Experience with AI-assisted security analytics and responsible use of AI in
  • detection and response workflows.
  • * Relevant certifications such as Security+, GIAC, Microsoft security
  • certifications, ISC2 CC or CISSP, or comparable credentials.
  • * Experience in a large enterprise SOC, hybrid or multi-cloud environment, or
  • large-scale security transformation.
  • QUALIFICATIONS

Minimum Qualifications

  • Required
  • * College Degree or equivalent required
  • * 1 year related experience
  • * Proficient use of applicable technology
  • * Ability to follow technical instructions and guidelines
  • * Ability to document daily activities and system functions
  • * Able to work in team environment
  • * Demonstrated ability to communicate verbally and in writing throughout all
  • levels of organization both internally and externally
  • * Ability to travel as required by business and on-call availability
  • * Able to lift up to 50 lbs
  • CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to
  • middle-market businesses nationwide. With industry knowledge and expertise in
  • accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers
  • actionable insights to help clients anticipate what is next and discover new
  • ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major
  • markets coast to coast.
  • CBIZ strives to be our team members' employer of choice by creating an
  • environment where team members are appreciated, recognized for their
  • contributions, and provided with opportunities to grow, both personally and
  • professionally, throughout their careers.
  • Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of
  • accounting services in the United States. CBIZ CPAs is an independent CPA firm
  • that provides audit, review and attest services, while CBIZ provides business
  • consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs
  • operates under its previous name, Mayer Hoffman McCann P.C.

Which skills does this role require?

Threat IntelligencePythonBashCloud SecurityNetwork SecurityEndpoint SecurityAutomationLog AnalysisSecurity EngineerNDRSOARIdentity and Access ManagementPurple TeamingAPIAzure Virtual DesktopDLPSecurity+GIACCISSPProduct Strategy

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.