Sr. IT Security Engineer
Job Details
Swire Coca-Cola is a family-owned bottling company with a rich history spanning over two centuries. We are one of the largest bottlers of Coca-Cola in North America and distribute over 50 beverage brands and flavors, bringing joy to our customers daily. With 8,000+ driven employees, we deliver refreshment to over 30 million consumers across 13 states. Join us at Swire Coca-Cola and become part of a community of dedicated team members who strive for success together.
Why you’ll love working at Swire Coca-Cola
- Health coverage (3 medical options, dental and vision)
- 401(k) Retirement Plan with company match
- FREE virtual primary care, acute care, and physical therapy
- FREE Employee Assistance Program
- Company-paid (vacation, holidays, sick time, bereavement, jury duty, maternity/parental, disability leave, and volunteer time)
- Discounted & free product
- Tuition reimbursement
- Opportunities for career advancement
- Direct impact on community through various giving programs
What does the Sr. IT Security Engineer, Operations & Engineering do at Swire Coca-Cola?
A Senior IT Security Engineer in Operations & Engineering supports the design, implementation, and operation of enterprise cybersecurity technologies and services. They strengthen the organization's security posture through the deployment, administration, and optimization of security controls across on-premises, cloud, and hybrid environments. They serve as a technical leader within the Cybersecurity team, partnering closely with IT Infrastructure, Network Engineering, Cloud Operations, Application Development, and Security Operations teams to ensure security controls are effectively implemented and maintained. This role supports both operational security activities and strategic security initiatives, helping to reduce risk through automation, engineering excellence, and continuous improvement.
Responsibilities
- Security Engineering & Architecture: Design, implement, and maintain cybersecurity technologies across endpoint, network, cloud, and identity platforms. Evaluate, deploy, and optimize security tools and controls to improve the organization's security posture. Support the development and implementation of cybersecurity standards, architectures, and technical roadmaps. Partner with IT teams to ensure security controls are integrated into infrastructure and application designs.
- Security Operations & Incident Response: Support security monitoring, threat detection, and incident response activities. Investigate security alerts, identify root causes, and assist with containment and remediation efforts. Develop and maintain operational procedures, runbooks, and response documentation. Participate in incident response exercises and continuous improvement initiatives.
- Identity & Access Management (IAM): Implement and support IAM capabilities, including identity lifecycle management, authentication, authorization, and privileged access controls. Manage role-based access controls, multifactor authentication, conditional access, and identity governance processes. Support periodic access reviews, entitlement management, and segregation of duties initiatives. Partner with application and infrastructure teams to integrate IAM solutions and automate identity processes.
- Vulnerability & Security Risk Management: Support the vulnerability management program through assessment, prioritization, tracking, and remediation validation. Collaborate with system owners to remediate vulnerabilities and reduce cyber risk. Analyze security findings and recommend appropriate compensating controls or risk reduction measures. Track remediation progress and support risk reporting activities.
- Cloud & Infrastructure Security: Design and implement security controls for Microsoft Azure, Microsoft 365, and hybrid environments. Support cloud security monitoring, configuration reviews, and hardening efforts. Evaluate cloud architectures and services to ensure alignment with security requirements. Implement security best practices for infrastructure, applications, and data protection.
- Automation, Reporting & Continuous Improvement: Identify opportunities to automate security processes and improve operational efficiency. Develop metrics, dashboards, and reporting to support cybersecurity decision-making. Maintain technical documentation, standards, and operational procedures. Stay current on emerging threats, technologies, and industry best practices.
Requirements
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or related field
- 5-8 years of experience in cybersecurity engineering, security operations, or infrastructure security
- Experience managing and supporting enterprise security technologies, including EDR, SIEM, IAM, vulnerability management, and cloud security platforms
- Strong knowledge of Microsoft security technologies, including Microsoft Defender, Entra ID (Azure AD), Intune, and Azure security services
- Experience supporting incident response, vulnerability management, and security investigations
- Knowledge of cybersecurity frameworks and best practices such as NIST CSF, CIS Controls, and Zero Trust principles
- Experience scripting or automating security processes using PowerShell, Python, or similar technologies (preferred)
- Strong troubleshooting, analytical, and problem-solving skills
- Excellent communication and collaboration skills with both technical and non-technical stakeholders
- Industry certifications such as CISSP, GSEC, Security+, Azure Security Engineer (AZ-500), or similar (preferred)