Skip to content

Open nowPosted 28 days ago

Lead Cybersecurity Engineer

First Student3 open roles

Where
CINCINNATI, OH - HEADQUARTERS
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Cybersecurity EngineerFirst Student · CINCINNATI, OH - HEADQUARTERS
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on First Student's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 28 days ago

The posting

The Lead Cybersecurity Engineer is a senior individual contributor on First Student’s Cybersecurity team, responsible for the day-to-day design, engineering, oversight, and operation of the controls that protect First Student’s cloud, endpoint, application, and identity environments. The role leads cybersecurity engineering projects, drives detection and response engineering, and serves as a senior technical resource for cybersecurity investigations and cross-functional partnership with I&O, Data, and Application teams.

This is a hands-on practitioner role. The individual is expected to lead engineering execution, mentor junior team members, and provide technical oversight and peer review of the team’s work product within cybersecurity.

Responsibilities

Identify and assess

  • Perform cybersecurity assessments and technical reviews for new platforms, cloud services, identity/authN/authZ changes, and externally-facing systems.
  • Lead offensive-informed technical assessments and translate findings into remediation plans.
  • Perform threat modeling for cloud and SDLC initiatives.

Securely build and protect

  • Engineer and lead operations of cybersecurity controls and cloud security posture management.
  • Author and code-review IaC for cloud governance components, including cloud policy management.
  • Provide SDLC cybersecurity engineering, including SAST and DAST program operation and secure code guidance for custom applications.
  • Provide oversight for identity and endpoint tooling and support enterprise secrets management.

Monitor, hunt, and detect

  • Own the technical integration of First Student systems and log sources into the managed MDR platform, and coordinate with the MDR provider on detection use cases, scenario-based workshops, and joint investigations.
  • Tune telemetry and sensor platforms to reduce false positives and improve detection fidelity.
  • Maintain existing and build new cybersecurity dashboards and telemetry that feed operational and leadership-facing reporting.

Respond, recover, and sustain

  • Serve as a senior technical lead for cybersecurity incidents, directing investigation, evidence collection, and containment across identity, endpoint, cloud, and email in coordination with I&O and MDR partners.
  • Maintain incident investigation templates, IR runbooks, and technical playbooks; drive lessons-learned and control improvements post-incident.
  • Support the incident management technical workflow and tabletop exercise execution.

Govern and manage risk

  • Contribute technical content to policies and standards (e.g., Vulnerability Management, cloud security, SDLC).
  • Interpret control requirements and translate them into enforceable technical controls.
  • Support leadership-facing reporting with technical evidence and narrative for internal reviews and external assessment cycles.
  • Contribute technical evidence to cyber risk acceptance packages.

Lead and coordinate

  • Provide technical oversight and peer review of the cybersecurity team’s work product.
  • Mentor cybersecurity analysts and junior engineers on cloud cybersecurity, investigations, and secure design; support individual growth plans in coordination with the Senior Director.
  • Lead cybersecurity engineering projects end to end, including planning, effort estimation, resource coordination, and delivery.
  • Liaise with cybersecurity vendors and managed service providers for issue resolution and operational escalation.

Desired qualifications

Education and certifications

  • BS/BA in IT, Computer Science, Engineering, or related field, or equivalent experience.
  • Industry certifications preferred: one or more of AWS Certified Security - Specialty, AWS Certified Solutions Architect - Associate/Professional, SANS/GIAC (GSEC, GCIH, GCSA, GCPN, GCIA), CISSP, CCSP, CRISC.

Knowledge and experience

  • 10+ years total experience in IT, with 5+ years of hands-on, demonstrated experience in one or more of cybersecurity engineering, cloud engineering, or DevOps.
  • Deep, hands-on AWS cybersecurity engineering: Organizations/Control Tower, SCPs and tag policies, IAM Identity Center, KMS key policy design, S3 hardening, Lambda runtime lifecycle, VPC segmentation and flow logging, CloudTrail/GuardDuty/Security Hub, Systems Manager, and cloud security posture management.
  • Working experience with managed MDR services, including onboarding and troubleshooting log sources, tuning detections in partnership with the provider, automating response, and participating in scenario-based workshops and joint IR execution.
  • EDR operations and incident response experience.
  • SDLC cybersecurity experience, including hands-on operation of SAST and DAST tooling, secure design review for cloud-native stacks, and remediation guidance for development teams.
  • Incident response experience on identity, cloud, and application-exposure incidents; ability to produce investigation reports suitable for leadership and legal review.
  • Working fluency in IaC review; proficiency in Python or PowerShell for automation, reporting, and control validation.
  • Strong understanding of NIST CSF 2.0, CIS Controls, and CIS AWS Foundations Benchmark; ability to translate framework requirements into enforceable, testable controls.
  • Familiarity with ITIL and Agile delivery practices.
  • Familiarity with the Microsoft 365 cybersecurity stack.

Personal attributes

  • Deep technical knowledge, strong analytical and problem-solving skills, and the ability to manage complex technical projects.
  • Strong written and oral communication skills; strong interpersonal skills.
  • Customer-focused mindset and attention to detail.
  • Operates independently and drives outcomes to closure. Comfortable defining technical requirements and holding partner teams accountable for implementation without direct execution authority.
  • Comfortable holding multiple technical domains simultaneously (cloud, detection, SDLC, IR) and prioritizing across them without daily direction.
  • Effective across organizational boundaries: I&O, Data, Applications, Legal, and external MDR/consulting partners.
  • High-integrity, ownership-first mindset. Proactive on risk reduction.

Compensation ranges from $130,000 - $155,000 depending on experience.

Language Requirement This role requires English proficiency. Federal, state, and local requirements, including U.S. Department of Transportation (DOT) regulations, require training, safety communications, company policies, employment documents, and other job-related communications be conducted in English.

First for a reason:

At First Student, we are a family of 60,000+ employees who take pride in safely transporting more than 5 million students and passengers to and from their destinations each day! Our family of brands include Transco, Total Transportation, Maggies Paratransit, and GVC II. Our employees are at the forefront of safety and innovation; they create and implement the most advanced training and technology the transportation industry has to offer.

In the state of Washington, all technician and driving positions, including but not limited to van drivers and any other position requiring employees to drive a company-owned vehicle, are considered safety-sensitive and are therefore subject to drug and alcohol testing, including cannabis.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. First is also committed to providing a drug-free workplace. First will consider for employment qualified applicants with criminal histories consistent with the requirements of the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Ordinance, and any other fair chance law. Philadelphia’s Fair Criminal Record Screening Standards Ordinance Poster is at this link or upon request https://www.phila.gov/media/20210423160847/Fair-Chance-Hiring-law-poster.pdf.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against First Student's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on First Student's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    First Student's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.