The posting
The Security Engineer II implements and operates the security controls that protect the organization's technology environment. The role works across the security products the Enterprise Security Office runs, with the heaviest day-to-day work in cloud and network environments.
This is a hands-on role. The Security Engineer II builds what senior and staff engineers design, handles day-to-day configuration, tuning, and troubleshooting of assigned security products, works requests from IT and business teams, and takes part in an on-call rotation. The role is a place to build depth across the security toolset with senior engineers close by.
Principal Duties and Responsibilities:
Engineering and Implementation:
- Implement and maintain security controls across cloud and on-premises environments, including identity and access configuration, network segmentation, firewall and platform policy, logging, and key and secret management.
- Build and configure what senior and staff engineers design, then test and validate the change before it reaches production.
- Support deployments, upgrades, and migrations of security platforms, including version updates, failover testing, license renewals, and configuration backups.
- Onboard log sources into the SIEM and confirm they keep reporting.
- Write small scripts to automate repetitive configuration, validation, and reporting work.
- Review system and resource configurations against the organization's security baselines and report drift to the owner.
Operations and Support:
- Handle day-to-day configuration, tuning, and troubleshooting of assigned security products.
- Respond to security service requests and tickets within the team's service levels.
- Triage alerts and findings, separate false positives from real issues, and work with system owners through remediation.
- Troubleshoot problems that involve a security control, working with infrastructure and application teams to separate a policy issue from a routing or application issue.
- Participate in a rotating on-call schedule for security platform issues and security incidents, including nights, weekends, and holidays.
- Support the Security Incident Response Team during investigations with log retrieval, evidence collection, and containment actions under the direction of a senior engineer or incident commander.
- Escalate early when a problem is outside the scope of the role or carries risk beyond a routine change.
Collaboration and Documentation:
- Follow change management: document the change, test it, and get approval before it goes to production.
- Write and update product documentation, including configuration notes, runbooks, access instructions, and change records.
- Explain a control or a finding to a system owner who does not work in security, and say what the owner needs to do next.
- Take part in design and peer reviews, and bring questions and observations from day-to-day operations.
- Support security reviews of new services and tools before they are approved for use.
Education and Experience Requirements:
- Education: Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field, or equivalent practical experience.
- Experience:
- 1 - 3 years of experience in security engineering, network engineering, systems administration, or security operations.
- 1+ years of hands-on work in a public cloud environment (AWS, Microsoft Azure, Oracle OCI), including core identity, network, and logging services.
- 1+ years supporting enterprise firewalls or remote access VPN preferred.
- Working knowledge of TCP/IP, DNS, routing, NAT, VPN, and TLS, and the ability to trace a connection through them.
- Experience with at least one scripting language (Python, PowerShell, Bash) for automation and reporting.
- Exposure to enterprise security platforms in a production environment, such as SIEM, endpoint protection, vulnerability scanning, or firewall management.
Additional Skills, Knowledge, and Experience:
- Working knowledge of cloud identity and access controls, including federation between on-premises identities and cloud platforms.
- Working knowledge of network security fundamentals, including segmentation, VNET and VPC design, firewall policy design, remote access, and TLS inspection.
- Ability to read logs, packet captures, and configuration files and reach a conclusion that holds up to review.
- Ability to document work clearly, including configuration notes, network and data flow diagrams (Visio, Lucid), and change records.
- Familiarity with security standards, frameworks, and baselines (NIST, CIS, ISO), including CIS benchmarks for operating systems and cloud services.
- Ability to explain a control or a finding to a system owner who does not work in security, and to say what the owner needs to do next.
- Ability to manage several open tickets and small projects at once and give an accurate status on each.
- Comfortable asking for help early and escalating rather than guessing on production systems.
Personal Attributes:
- Team Player: Ability to work collaboratively with senior engineers, IT teams, and other stakeholders to reach shared goals.
- Ownership: Follows an issue to closure, including the documentation and the follow-up with the requester.
- Coachability: Takes feedback on designs and changes, and asks for review before making a change with broad impact.
- Communication: Effective written and verbal communication, with a strong commitment to customer service.
- Detail-Oriented: Strong attention to detail, particularly in firewall policy, cloud permissions, and anything with production impact.
- Adaptability: Ability to balance planned project work against tickets and incidents in a fast-paced environment.
Additional Requirements:
- On-Call: Participation in a rotating on-call schedule, including nights, weekends, and holidays, and availability for scheduled after-hours change windows.
- Continuous Learning: Commitment to staying current with industry trends and to building skills through hands-on work and training.
- Travel: Willingness to travel occasionally to support security deployments or upgrades at remote locations.
This role is for an engineer with a few years of experience who wants hands-on work from the first week: configuration changes, tuning, findings, and the tickets and incidents that come with running security products for a large organization. If you are passionate about cybersecurity and eager to grow in a fast-paced, collaborative environment, we encourage you to apply.
Physical Requirements:
This is primarily a sedentary office position which requires the incumbent to have the ability to operate computer equipment, speak, hear, bend, stoop, reach, lift, and move and carry up to 25 lbs. Finger dexterity is necessary. 10-20% of travel is required.
This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.
Life at Lennar
At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone’s Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar’s policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.
Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedIn<https://www.linkedin.com/company/lennar/> for the latest job opportunities.
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.



