Jobs · Administrative · Colorado

Senior Security Engineer/Architect

Brownstein Hyatt Farber Schreck · Denver Metropolitan Area · 1 mo ago
On-siteAdministrative$170k–$200k/yrFull-time

About the Role

We have an immediate need for a Senior Security Engineer / Architect to join our Denver office. This is a high-visibility, high-trust position for a seasoned practitioner ready to operate as the firm's go-to technical expert across detection engineering, incident response, and security architecture. Working in close partnership with the CISO, you will shape the firm's technical roadmap, lead the engineering execution behind the security strategy, and influence how the firm uses its security investments. You will be the lead technical voice during incidents, mentor the rest of the team, and support the CISO in representing the firm's security capabilities to clients, regulators, auditors, and outside counsel. If you are energized by the prospect of serving as the principal architect and lead technical defender for an organization where confidentiality is non-negotiable, and you want a role where your judgment carries weight at the leadership table alongside the CISO, we would like to meet you.

Security Architecture and Strategy

  • Provide architectural oversight across the firm's security stack, ensuring that identity, endpoint, network, data, and cloud controls are designed and implemented coherently and in line with best practices.
  • Own the design, deployment, and continuous improvement of security controls and capabilities across Microsoft Entra ID, Conditional Access, Microsoft, Azure, and the broader Microsoft Defender suite (Endpoint, Identity, Cloud, Cloud Apps), driving appropriate utilization of the broader Microsoft security suite so that the firm consistently realizes the full value of its licensed protections and stays at the leading edge of Microsoft's evolving security platform.
  • Serve as the CISO's primary technical advisor on security design, investment, and risk decisions; partner on business case development and contribute to executive presentation of major initiatives.
  • Lead the technical evaluation of security technologies, including proof-of-concept design and vendor assessment, and develop recommendations that inform the CISO's decisions on the firm's security stack.
  • Partner with infrastructure, identity, and application teams to embed security into every project lifecycle, leading design reviews, threat modeling, and risk-based recommendations.

Detection and Response Engineering

  • Own the detection engineering lifecycle in the firm's enterprise SIEM platform: develop, tune, and retire analytics rules; build and refine workbooks; and curate connectors and data sources to ensure high-fidelity visibility across the environment.
  • Design and thoughtfully implement User and Entity Behavior Analytics (UEBA) capabilities, baselining normal activity for users, service accounts, and entities, and tuning anomaly detections to surface meaningful risk while minimizing analyst fatigue.
  • Set the strategy for SIEM log onboarding, parsers, filters, and ingestion pipelines; balance signal fidelity against cost, and align telemetry with detection priorities.
  • Build and curate advanced KQL libraries, hunting notebooks, and automations (Logic Apps, playbooks, SOAR-style workflows) that elevate the entire team's capability and accelerate triage, enrichment, and response.
  • Continuously benchmark detection coverage against current adversary tradecraft, with particular emphasis on threats targeting law firms and professional services organizations.

Threat Hunting and Threat Intelligence

  • Lead the firm's proactive, hypothesis-driven threat hunting program: define methodology, set cadence, and own outcomes across endpoints, identity, email, cloud workloads, and SaaS, leveraging Sentinel, Defender XDR Advanced Hunting, and other tools.
  • Serve as the firm's authority on adversary behavior relevant to legal services, translating industry, sector, and geopolitical threat intelligence into actionable detections, hunts, and architectural improvements.
  • Mature the firm's threat hunting program over time, ensuring documented hypotheses, tracked coverage gaps, and a durable feedback loop into detection engineering and architecture.

Incident Response and Resolution

  • Serve as the lead technical responder during significant security incidents, directing investigation, containment, eradication, and recovery activities under the CISO's overall incident leadership and in close partnership with IT leadership, outside counsel, and external IR partners as appropriate.
  • Lead deep-dive forensic analysis across Microsoft 365, Entra ID, Azure, endpoints, email, and network telemetry; reconstruct attacker activity; and produce clear, defensible findings suitable for executive, legal, and client audiences.
  • Author and maintain the firm's incident response playbooks; co-lead executive tabletop exercises and after-action reviews with the CISO; and ensure lessons learned become durable engineering and architectural improvements.

Identity, Access, and Data Protection

  • Lead the technical execution of the firm's identity security strategy, guiding architectural decisions across Entra ID, including Conditional Access, Privileged Identity Management, Identity Protection, and risk-based authentication, all aligned to a Zero Trust strategy.
  • Partner on the design and operation of data protection controls such as Microsoft Purview information protection, DLP, insider risk management, and eDiscovery considerations appropriate for a law firm environment.
  • Drive secure configuration baselines for Microsoft 365 and Azure workloads, including CIS, Microsoft Secure Score, and firm-specific hardening standards.

Program Leadership and Mentorship

  • Serve as the senior technical voice within the security team; mentor analysts and engineers, raise the bar on detection, hunting, and response, and contribute to hiring decisions for the function.
  • Support the CISO in client security reviews, third-party audits, and regulatory inquiries; act as the firm's primary technical voice during high-stakes external engagements.
  • Help shape the firm's security culture through clear, credible, and confident communication with non-technical audiences.

Qualifications

  • Ten or more years of progressive experience in information security, including substantial time as a senior individual contributor in security engineering, detection engineering, or threat analysis roles.
  • Relevant certifications are valued and, in some cases, may substitute for portions of the experience requirements. Strong candidates will typically hold one or more of the following: CISSP, GCIH, GCDA, GCFA, OSCP, and/or related Microsoft certifications such as SC-100/200/300 and AZ-500.
  • A documented track record of leading security architecture and detection engineering initiatives end-to-end with measurable improvements to an organization's security posture.
  • Deep, hands-on mastery of the Microsoft enterprise security stack, including Entra ID, Conditional Access, Microsoft 365, Azure, Microsoft Sentinel, and the Microsoft Defender suite.
  • Demonstrated experience setting detection engineering strategy in a modern SIEM, including authoring and tuning high-fidelity analytics rules, implementing and tuning UEBA, and managing log sources and ingestion economics at scale; advanced proficiency with KQL is required.
  • Proven experience serving as the lead technical responder or incident commander on significant security incidents, including investigations spanning cloud identity, email, endpoints, and SaaS.
  • Fluency with adversary tradecraft and frameworks including MITRE ATT&CK, the cyber kill chain, and Zero Trust architectural principles.
  • Recognized strength across core security architecture domains: identity, endpoint, network, email, data protection, and cloud security.
  • Scripting and automation depth in PowerShell and at least one general-purpose language (Python preferred) for detection, enrichment, response, and analytics workflows.
  • Sound judgment, discretion, and the ability to handle highly confidential client and firm information with care.
  • Exceptional written and verbal communication skills.

Compensation and Benefits

  • Medical, dental, and vision insurance
  • 401k with match and profit sharing
  • Vacation, sick, and personal time off
  • Salary range: $170,000 - $200,000 annually
  • Eligible for a discretionary bonus

Similar jobs

Senior Security Architect

Midcontinent Independent System Operator (MISO)Carmel, IN· 2 wk ago
Information Technology$155k–$180k/yrapply on rr.jobsyn.org

Senior Security Architect

Wolters KluwerNew York, NY· 1 mo ago
Information Technology$103k/yrapply on wk.wd3.myworkdayjobs.com