Skip to content

Open nowPosted 8 days ago

Senior Security Engineer

AGS LLC35 open roles

Where
Atlanta, GA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security EngineerAGS LLC · Atlanta, GA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on AGS LLC's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 8 days ago

The posting

Job Overview

The Senior Security Engineer is the senior technical implementer on the AGS security team, responsible for executing and maintaining the enterprise security control set in support of the security program strategy, roadmap, and standards set by the Senior IT Security Manager. The role provides senior engineering capability across Identity & Access Management, security monitoring and detection, and threat and vulnerability management, translating program requirements into working technical controls and documented procedures. This is a hands-on senior individual contributor role that assists in leading technical delivery and provides guidance and mentorship to other security engineers and analysts, without direct people management responsibility. The role partners closely with Infrastructure, Network, Enterprise Apps, Compliance, and Business Units to implement security by design and enable the business.

Responsibilities

  • Execute against the enterprise security program roadmap, control priorities, and risk treatment decisions set by the Senior IT Security Manager.
  • Assist in leading technical delivery of assigned security initiatives, including planning, sequencing, and hands-on implementation.
  • Implement and advance enterprise Identity & Access Management capability across hybrid on-premises and cloud environments, including authentication, authorization, and Conditional Access configuration.
  • Administer identity governance in partnership with Infrastructure: identity lifecycle (joiner/mover/leaver), MFA, self-service password reset, just-in-time administrative access, app registrations, and service principals.
  • Implement privileged access management capability, including privileged session controls and reduction of standing administrative rights.
  • Apply role-based access (RBAC/ABAC) and least privilege models across cloud and SaaS; expand SSO and federation coverage (SAML, OIDC) across enterprise and third-party applications.
  • Engineer, deploy, and expand the enterprise SIEM and log management platform, including log source onboarding, normalization, and retention configuration.
  • Develop and tune detection content, correlation rules, and alerting logic aligned to recognized adversary behavior frameworks; reduce noise while improving catch rate.
  • Build automated triage, enrichment, containment, and notification workflows for recurrent alert types.
  • Assist in leading the vulnerability and patch management program: operate scanning coverage, apply the risk-based prioritization model, and drive remediation to the service levels set by security leadership.
  • Integrate threat intelligence into vulnerability prioritization and asset risk scoring.
  • Coordinate remediation with IT operations and system owners; track SLA performance and report risk reduction.
  • Develop and maintain technical playbooks and runbooks in support of the enterprise incident response plan; participate in tabletop exercises and post-incident reviews.
  • Support crown jewel and critical asset identification, and recommend technical treatment options for review and approval by the Senior IT Security Manager.
  • Implement data classification and data protection controls, including labeling, encryption, and key management practices, in alignment with program standards.
  • Maintain enterprise security asset visibility and security tooling coverage across the estate.
  • Produce technical metrics and reporting in support of the KPIs and KRIs defined by security leadership (e.g., MFA coverage, privileged access reduction, endpoint agent coverage, MTTD/MTTR, patch SLA attainment, automation rate).
  • Use scripting and automation to codify controls and eliminate manual work.
  • Implement technical controls that align to the frameworks adopted by the security program (NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001) and to applicable gaming and privacy requirements; maintain auditable technical evidence.
  • Support internal and external audit, certification, and regulatory assessment activities with technical evidence and remediation execution.
  • Evaluate security products and services and provide technical input to vendor selection, consolidation, and ROI decisions made by security leadership.
  • Provide technical guidance and mentorship to security engineers and analysts; document technical procedures for the team to operate against.
  • Provide technical risk input to the Senior IT Security Manager to support business and executive communication.
  • Occasional travel throughout the United States.

Qualifications

  • Identity & Access Management: enterprise directory and cloud identity administration, Conditional Access, MFA, privileged access management, SSO and application integration, access review execution.
  • Security monitoring and detection engineering: SIEM and log management platform engineering, detection content development, query language proficiency, SOAR and playbook automation.
  • Threat and vulnerability management: enterprise scanning platforms, risk-based prioritization, patch orchestration, and SLA reporting.
  • Endpoint and email security platforms: EDR/XDR administration, policy tuning, baseline hardening, device compliance.
  • Data protection: classification and labeling, DLP concepts, encryption and key management.
  • Zero Trust Network Access patterns and Secure Service Edge (SSE) concepts, network segmentation fundamentals.
  • Incident response fundamentals, digital forensics basics, and threat hunting.
  • Scripting and automation; infrastructure-as-code or pipeline automation preferred.
  • Experience operating in hybrid environments combining on-premises infrastructure and cloud-based systems.
  • Proven ability to balance security requirements with user experience and business enablement.

Skills/Requirements

  • Bachelor's Degree in Computer Science, Information Security, Information Technology, or equivalent work experience.
  • At least 6 years of progressive experience implementing, configuring, and maintaining enterprise security solutions across hybrid (on-premises and cloud) environments.
  • Demonstrated hands-on delivery in at least two of the following domains: Identity & Access Management, SIEM and detection engineering, or threat and vulnerability management.
  • Experience producing and reporting security metrics for management review.
  • Experience documenting technical procedures and runbooks used by other engineers and analysts.
  • Experience implementing technical controls and procedures in accordance with industry frameworks (NIST, CIS, ISO 27001).
  • Familiarity with incident response, digital forensics, and vulnerability management processes.
  • Experience supporting external audit, certification, or regulatory assessment activities.
  • Ability to take direction on program priorities and independently deliver the technical execution.
  • Prior experience in a regulated industry with recurring external audit obligations (gaming, financial services, healthcare) preferred.
  • Relevant technical certifications required or strongly preferred: CISSP, CEH, CySA+, GIAC (GCIH/GCIA/GSEC), or equivalent.

Preferred Certification

  • Professional technical certifications such as CISSP, CEH, CySA+, GIAC (GCIH/GCIA/GCED/GSEC), OSCP, or equivalent. Platform-specific certifications are considered supplemental to demonstrated hands-on capability.

Note: All offers are contingent upon successful completion of a background check

*Posted positions are not open to third party recruiters and unsolicited resume submissions will be considered free referrals.

AGS is an equal opportunity employer

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against AGS LLC's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on AGS LLC's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    AGS LLC's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.