Lead Security Engineer
About the job
This role is 4 days onsite (Monday - Thursday) at one of the below locations:
- Austin, TX 78729
- Boca Raton, FL 33496
Overview:
As a Lead Security Engineer, you are an integral team member of our Information Security Engineering team, helping protect how our workforce, customers, and business partners access our environment. The role of Lead Security Engineer is to design, build, and maintain the identity, access, and endpoint security solutions that protect the organization while enabling the business. Working closely with fellow team members, including other Security Engineers, Network, Infrastructure, and Application teams, this role translates security requirements into technical solutions and helps guide the broader organization on security best practices. This role also mentors and teaches junior Security Engineers. The Lead Security Engineer works across the organization to ensure that systems, identities, and endpoints remain secure.
This role provides guidance and oversight on identity and access management, privileged access, conditional access and multi-factor authentication, and endpoint detection and response for multiple enterprise applications. This role is a thought leader for the Information Security Engineering team, especially in areas such as identity governance and endpoint security, to deliver secure, reliable solutions in a cost-effective manner. You'll partner with Security, Network, Infrastructure, and Application teams to translate security requirements into technical solutions and guide best practices across the organization.
Primary Responsibilities:
- Work closely with multiple departments in the organization, focusing on company-wide initiatives as well as being the SME on identity, access management, and endpoint security. Own the design, configuration, and maintenance of SSO/federation, conditional access, and privileged access management solutions. Report to leadership on relevant statistics for area of expertise. Lead and guide offshore resources.
- Design, configure, and troubleshoot SAML/SSO integrations for a large and growing portfolio of B2B customers, vendors, and internal applications (e.g., Microsoft Entra ID, Okta, ADFS, Ping, SecureAuth, Auth0), including certificate and signing-key rotation.
- Build and tune Conditional Access Policies (e.g., geo-fencing, anonymous proxy/Tor/botnet blocking, MFA enforcement) and lead passwordless/Passkey rollouts for privileged account populations.
- Drive Privileged Access Management (PAM) operations and migrations (e.g., CyberArk Privilege Cloud), onboard service accounts and secrets, and integrate PAM with cloud key vaults and automation platforms.
- Oversee all aspects of area of expertise inside Information Security Engineering, including establishing metrics, applying industry best practices, and developing new tools and processes to ensure goals are met. Lead endpoint detection and response, identity governance, and security tooling initiatives, coordinating resources internally and externally.
- Lead migrations from legacy AV/EDR tools to modern XDR platforms (e.g., Microsoft Defender suite), including automated response tuning and phishing simulation/security awareness programs.
- Manage Active Directory/Entra ID hygiene, including service account ownership reviews, RBAC/access-role cleanup, security group governance, and privileged role alerting.
- Coordinate NSG, firewall, and WAF rule changes with the Network team to support secure application and integration architectures.
- Lead and mentor team members, as well as manage outside contract resources.
- Provide technical leadership and mentorship to other security engineers, review designs, and help prioritize and estimate the team's engineering backlog.
- Lead processes and create additional documentation and runbooks to optimize security operations.
- Build and maintain Information Security Engineering documentation and runbooks (e.g., in Confluence) so processes are repeatable and auditable.
- Manage SSO/certificate lifecycle for monitoring and observability tooling integrations (e.g., Splunk, Dynatrace, Zabbix).
- Work independently with multiple teams, including Network and Infrastructure, as well as on multiple projects.
Education and Experience:
- Bachelor's degree or equivalent experience in Computer Science, Information Security, or related field
- 6+ years of experience in identity and access management, security engineering, and enterprise IT infrastructure
- CISSP, CISM, or equivalent security certification preferred
- Technical Competencies & Information Systems: Identity providers (e.g., Microsoft Entra ID, Okta), privileged access management platforms (e.g., CyberArk), endpoint detection & response tools (e.g., Microsoft Defender), Active Directory, SQL
- Skills & Abilities:
- 7 to 10+ years of security engineering, identity & access management, or infrastructure security experience
- Strong leadership and mentoring qualities
- Oversee all aspects of identity, access, and endpoint security including establishing metrics, applying industry best practices, and developing new tools and processes to ensure security goals are met
- Act as key point of contact for identity and endpoint security matters, providing security engineering services, and coordinating resources internally and externally
- Lead and mentor other Security Engineers
- Lead and review security configurations, scripts, plans, and procedures
- Good knowledge of SDLC processes
- Good knowledge of Agile methodology
- Very good communication skills and able to lead others
- Must have experience administering SSO/SAML federation and Conditional Access policies.
- Experience working with privileged access management tooling (e.g., CyberArk)
- Experience with endpoint detection & response tools (e.g., Microsoft Defender)
- Understanding of Active Directory administration and identity governance
- Basic knowledge of network security constructs (e.g., NSGs, firewalls, WAF)
- Familiarity with automation tooling (e.g., Ansible) for provisioning and secret management
- Ability to write SQL
- Able to work independently across multiple teams
- Must have experience using security and IT tools like JIRA and Confluence
- Must have experience working with onsite offshore teams
- Excellent English written and verbal communication skills
- Should be able to lead security team members Onsite and Offshore.
- Partner with multiple teams and provide high-quality security engineering services.
- Should be able to work individually as well as in a team.
- Experience with automation for identity and access provisioning
- Experience with certificate and vulnerability management platforms
- Experience with security monitoring/observability platforms (e.g., Splunk, Dynatrace).
About The ODP Group: The ODP Group, through its business entities ODP Business Solutions and Office Depot, is a leading provider of products, services, and technology solutions through an integrated business-to-business (B2B) distribution platform and omnichannel presence, which includes world-class supply chain and distribution operations, dedicated sales professionals, online presence, and a network of Office Depot and OfficeMax retail stores.
Commitment to Safety: We are committed to maintaining a safe and healthy work environment for our Coworkers and our customers. All Coworkers are expected to support our operational safety culture by working safely and addressing potential hazards or concerns.
Disclaimer: The above statements are intended to describe the general nature and level of work being performed by Coworkers assigned to this classification and are not intended to be a complete list of all responsibilities, duties and skills required of Coworkers so classified. Other duties may be assigned.
Pay, Benefits & Work Schedule: The company offers competitive salaries, a benefits package, which includes a 401(k) and more, along with plenty of opportunities to move and grow within our organization! You may be eligible to participate in an incentive program, paid in accordance with the Incentive Plan terms and conditions.
Equal Employment Opportunity: The company is committed to providing equal employment opportunities in all employment practices. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, citizenship status, marital status, age, disability, protected veteran status, sexual orientation or any other characteristic protected by law.
We will consider for employment qualified applicants with arrest and conviction records pursuant to the City & County of San Francisco Fair Chance Ordinance.
Application Deadline: The job posting will remain open for a minimum of 3 days and will expire once the position has been filled.