Lennar logo

Staff Security Engineer

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Senior-level
Remote
On-site
Benefits
Health Insurance
Dental Insurance
Vision Insurance

Job Description

Summary of Position:

The Staff Security Engineer is the senior technical owner of the security capabilities the Enterprise Security Office runs: network security, data security, endpoint security, edge and web application protection, application security, security operations and SIEM, and vulnerability and posture management. The role sets engineering direction across all of these domains and keeps hands-on ownership of cloud security for IaaS, PaaS, and SaaS environments.

This is an individual contributor role with technical leadership responsibility and no direct reports. The Staff Security Engineer works with security engineers, architects, infrastructure teams, and application development teams so that controls in every domain are designed, deployed, and configured correctly, and mentors senior and junior engineers on the team.

Principal Duties and Responsibilities:

Technical Leadership Across Domains:

  • Own the technical direction of the team's security domains: cloud security, network security, data security, endpoint security, edge and web application firewall, application security, security operations and SIEM, and vulnerability and posture management.
  • Set the engineering standard for how products in each domain are designed, deployed, documented, and reviewed, including the design, decision, and change records the team keeps for every product it runs.
  • Review and approve significant architecture and configuration changes to security products in any domain.
  • Act as the escalation point for the team's hardest technical problems, including issues that cross more than one domain or more than one engineering team.
  • Mentor senior and junior security engineers and security operations staff, and build depth in domains where only one engineer currently has it.
  • State and defend the team's technical position with Enterprise Architecture, Infrastructure, application teams, and leadership.

Domain Engineering and Operations:

  • Cloud Security: Own the cloud security strategy and its implementation across public cloud (IaaS, PaaS) and SaaS platforms, and lead the design, implementation, and management of:
  • Core controls for IaaS, PaaS, and SaaS services, including identity, network segmentation, logging, and key and secret management
    • Cloud Security Posture Management (CSPM)
    • Cloud-Native Application Protection Platforms (CNAPP)
    • Cloud Access Security Broker (CASB) and Security Service Edge (SSE)
    • Cloud workload, container, and Kubernetes protection
  • Network Security: Guide the design and operation of next-generation firewalls, remote access VPN, and cloud-native firewall controls covering traffic entering and leaving the network.
  • Data Security: Guide the controls that prevent data loss through browsers, email, and removable media, including enterprise browser isolation, email security, and data classification and labeling.
  • Endpoint Security: Guide endpoint detection and response, application control, and server protection across laptops, desktops, and servers.
  • Edge and WAF: Guide web application firewall coverage and rule tuning for public-facing applications, including false-positive reduction with application owners.
  • Application Security: Guide static and dynamic testing, dependency and secret scanning, and pipeline controls for cloud-native development and delivery platforms (DevOps, CI/CD), with remediation workflows run alongside development teams before and after code ships.
  • Security Operations and SIEM: Contribute detection logic, log source onboarding, and automated response playbooks, support triage of complex or cross-domain alerts, and make sure cloud telemetry reaches the SIEM in a usable form.
  • Vulnerability and Posture Management: Guide vulnerability scanning and posture assessment across endpoints, servers, and cloud, and drive prioritized remediation with infrastructure and application owners.

Program and Cross-Team Responsibilities:

  • Contribute to the Cybersecurity Program and to the Security Engineering and Architecture roadmaps.
  • Meet legal, compliance, and regulatory requirements that apply to security controls in any domain, including cloud.
  • Provide input to Lennar's Risk Management, Compliance, and Incident Response teams for every domain the team owns.
  • Lead vendor and product evaluations, including requirements definition, proof of concept, risk assessment, procurement support, and selection recommendations.
  • Evaluate new and emerging services and technologies and recommend where they fit the existing control set.
  • Drive remediation of findings from internal and external security audits.
  • Participate as an active member of the Security Incident Response Team, including post-incident review.
  • Keep communication working between Security Engineering and Architecture, Enterprise Architecture, Infrastructure, and the operating business units.

Education and Experience Requirements:

  • Education: Bachelor's degree required in Computer Science, Cybersecurity, Engineering, or related field. Master's degree preferred.
  • Experience:
    • 8+ years of security engineering experience, including 5+ years designing, implementing, and running security technologies in a mid to large-scale enterprise environment.
    • 5+ years securing IaaS, PaaS, and SaaS resources in public cloud environments (AWS, Microsoft Azure, Oracle OCI), including cloud network solutions and cloud-native application security testing.
    • Hands-on depth in at least 4 of the following: network security, data security, endpoint security, edge and WAF, application security, security operations and SIEM, vulnerability and posture management.
    • 3+ years with DevSecOps components, including a strong understanding of DevOps and the software development lifecycle, static and dynamic application testing, and application vulnerability discovery, assessment, and remediation support.
    • Experience securing SaaS delivery platforms (Microsoft 365, Salesforce, Box.com) with CASB, CSPM, and similar technologies.
    • Experience as the senior technical owner of an enterprise security platform through a full lifecycle, including deployment, upgrade, and migration or replacement.
  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Azure Security Engineer Associate, AWS Certified Security-Specialty, GIAC Cloud Security Automation (GCSA), Certificate of Cloud Security Knowledge (CCSK), or similar advanced security certifications preferred.

Additional Skills, Knowledge, and Experience:

  • Expert knowledge of cloud identity and access controls, including federation between on-premises identities and cloud platforms.
  • Expert knowledge of network security fundamentals on-premises and in cloud, including segmentation, VNET and VPC design, web application firewalls, firewall-as-a-service, and remote access.
  • Working knowledge of endpoint detection and response, application control, and server protection at enterprise scale.
  • Working knowledge of data loss prevention across email, browser, and endpoint, and of data classification and labeling.

Life at Lennar

At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone’s Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar’s policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.

Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedInhttps://www.linkedin.com/company/lennar/> for the latest job opportunities.

Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Staff Security Engineer Jobs at Lennar

What is the work location for this position at Lennar?
This job at Lennar is located in Irving, Texas, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Lennar?
Employer has not shared pay details for this role.
What employment applies to this position at Lennar?
Lennar lists this role as a Full-time position.
What experience level is required for this role at Lennar?
Lennar is looking for a candidate with "Senior-level" experience level.
What benefits are offered by Lennar for this role?
Lennar offers following benefits: Health Insurance, Dental Insurance, Vision Insurance, Family/Dependent Health, Paid Holidays, Paid Vacation, Paid Sick Leave, Parental and Family Leave, 401k Matching/Retirement Savings, Tuition/Education Assistance, and Health & Wellness Programs for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Lennar?
You can apply for this role at Lennar either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.