Talent.com
Lead Cybersecurity Engineer
Lead Cybersecurity EngineerDutch Bros. • Tempe, AZ, United States
Lead Cybersecurity Engineer

Lead Cybersecurity Engineer

Dutch Bros. • Tempe, AZ, United States
5 days ago
Job type
  • Full-time
Job description

It's fun to work in a company where people truly believe in what they are doing. At Dutch Bros Coffee, we are more than just a coffee company. We are a fun-loving, mind-blowing company that makes a difference one cup at a time.

Position Overview :

We're looking for a Lead Cybersecurity Engineer to drive the design, implementation, and automation of advanced security controls across our enterprise. This role will help shape our Zero Trust and Secure Service Edge (SSE) strategy, partner closely with software and infrastructure teams, and ensure our technology environment remains resilient, scalable, and secure.

The ideal candidate combines deep hands-on technical expertise with strong problem-solving skills and a passion for continuous improvement. You'll work at the intersection of security engineering, cloud architecture, and automation to help us stay ahead of evolving threats.

  • Design, implement, and maintain enterprise-grade security solutions aligned with Zero Trust and SSE principles.
  • Lead development and automation of security controls using Python, REST APIs, and modern DevOps pipelines (CI / CD, IaC, SOAR).
  • Engineer integrations between security platforms, infrastructure, and applications to improve visibility, detection, and response capabilities.
  • Collaborate with cross-functional teams (infrastructure, software, IAM, DevOps) to embed security into architecture and development workflows.
  • Manage and optimize SIEM, EDR, Vulnerability Management, and DLP platforms.
  • Support configuration and governance of IAM and PIM platforms (Entra ID, Okta, CyberArk, Auth0).
  • Provide technical leadership in evaluating, deploying, and tuning Zero Trust and SSE platforms (Cloudflare, Cisco, Microsoft, Palo Alto Networks).
  • Drive continuous improvement in automation, detection engineering, and response playbooks.
  • Contribute to compliance initiatives (PCI DSS, SOX, NIST, CIS 18) through engineering, documentation, and evidence collection.
  • Research and prototype the use of Large Language Models (LLMs) and prompt engineering for cybersecurity automation and analysis.
  • Mentor junior engineers and contribute to security standards, processes, and technical documentation.

Job Qualifications :

  • 6+ years of hands-on experience in security engineering roles
  • 1+ year of hands-on experience in software engineering.
  • Strong understanding of security principles, software development, IAM, networking, and application security.
  • Extensive hands-on experience with :
  • Zero Trust methodologies and SSE platforms (Cloudflare, Cisco, Microsoft, Palo Alto Networks)

  • Python, REST APIs, and data formats (JSON, CSV, XML)
  • Security automation (SOAR, CI / CD, IaC)
  • Azure and AWS environments
  • IAM / PIM solutions (Entra ID, CyberArk, Okta, Auth0
  • Linux and Windows administration
  • SIEM platforms (Microsoft Sentinel, Splunk, Rapid7)
  • Vulnerability Management platforms (Qualys, Rapid7, Tenable)
  • Experience with :
  • DevOps methodologies and principles

  • Next-Generation Firewalls (Palo Alto, Fortinet, Sophos, Checkpoint)
  • Compliance frameworks (PCI DSS, SOX, NIST, CIS 18)
  • EDR platforms (Microsoft, CrowdStrike, SentinelOne)
  • DLP solutions (Microsoft Purview, Symantec, Trellix)
  • Large Language Models (LLMs) and prompt engineering concepts
  • Strong problem-solving, communication, and documentation skills.
  • Proven ability to collaborate with cross-functional technical teams.
  • Certifications

  • Preferred / Highly Desired :
  • CISSP, CCSP, OSCP

  • AWS Certified Solutions Architect - Associate
  • AWS Certified Security - Specialty
  • Microsoft Certified : Azure Security Engineer Associate
  • CCNA
  • HashiCorp Certified : Terraform Associate
  • Location Requirement :

    This role is located in Tempe, Arizona. This position is required to be in office 4 days per week (Mon-Thurs); Fridays are optional remote work days.

    Key Result Areas (KRAs) :

    Secure Access Service Edge (SASE) Implementation & Optimization

    Objective : Establish a unified, cloud-delivered security and networking architecture to protect users, devices, and applications across our HQ and Shops :

  • Design and deploy SASE components (SWG, CASB, ZTNA, SD-WAN) achieving ≥ 95% policy enforcement consistency across locations and devices.
  • Migrate ≥ 80% of remote user traffic through SASE. Deprecate VPN models
  • Achieve centralized policy visibility and reporting for all edge traffic through a single management console (e.g., Cloudflare, Palo Alto, Cisco).
  • Microsoft Security Ecosystem Integration

    Objective : Maximize protection and ROI from the Microsoft 365 E5 and Entra security stack :

  • Achieve ≥ 90% coverage of Conditional Access and PIM enforcement across Entra
  • Deploy Microsoft Defender suite (Endpoint, Cloud Apps, Identity) to ≥ 95% of eligible assets.
  • Integrate Sentinel SIEM with all major data sources (SASE, EDR, IAM, vulnerability management) for unified threat detection.
  • Reduce mean time to detect (MTTD) and respond (MTTR) to incidents by ≥ 30% through automation and correlation within Sentinel.
  • Security Automation and AI-driven Operations

    Objective : Leverage AI and automation to streamline detection, response, and compliance workflows :

  • Automate ≥ 60% of repetitive SOC tasks using SOAR, AI models, and scripted playbooks (Python, Logic Apps).
  • Deploy LLM-based enrichment and triage for security alerts, reducing ops review time by ≥ 40%.
  • Integrate automated patch validation and remediation workflows using IaC and CI / CD pipelines.
  • Implement anomaly detection models for user and entity behavior, improving proactive risk identification accuracy by ≥ 25%.
  • Zero Trust Maturity Advancement

    Objective : Achieve a measurable increase in Zero Trust maturity across identity, device, application, and data layers :

  • Engineer data pipelines to aggregate authentication, device posture, and access logs from Entra ID, SASE, and EDR into centralized telemetry (e.g., Sentinel, Splunk).
  • Develop automation scripts to continuously validate compliance of users and devices with Zero Trust policies (MFA, device health, network segmentation).
  • Create dashboards and analytics to measure Zero Trust posture (policy coverage, noncompliance rates, anomalous access trends).
  • Integrate validation outcomes into CI / CD or SOAR workflows for real-time remediation and reporting.
  • Skills :

  • Change Management
  • Budgetary Responsibility
  • Business Plan Development
  • Collaborative
  • Communication
  • Critical Problem Solving
  • Delegation
  • Physical Requirements :

  • In-Office Environment : Must be able to work in a busy, crowded, and loud office with frequent distractions and interruptions
  • Must be able to collaborate in-person with occasional impromptu in-person meetings

  • Office Conditions : Adaptability to typical office conditions, which may include exposure to air conditioning, heating, artificial lighting, and varying noise levels
  • Mobility : Ability to sit, stand, reach, twist, stretch, and work at a desk for long stretches. Must be able to occasionally move or lift office items up to 25 pounds
  • Hearing Requirements : Hearing must be sufficient or correctable to ensure clear understanding of spoken information, including participating in virtual meetings and phone calls. Use of hearing aids or other assistive devices is acceptable if needed.
  • Reading and Writing Proficiency : Ability to read and write in English is essential for processing documents, drafting reports, and following up on necessary actions. Proficiency in written communication is required to handle job-related tasks effectively.
  • Vision Requirements : Vision must be adequate or correctable to perform essential job duties, such as reading documents on a computer screen and using other visual tools. Use of corrective lenses or other measures to meet visual requirements is expected if needed.
  • Technology Proficiency : Must be proficient in operating a computer and other office productivity tools such as printers, scanners, and collaboration software.
  • Effective Communication : Must possess strong verbal and written communication skills to interact effectively with team members, clients, and other stakeholders via email, video conferencing, and other in office communication tools.
  • Compensation : DOE

    If you like wild growth and working in a unique and fun environment, surrounded by positive community, you'll enjoy your career with us!

    Create a job alert for this search

    Cybersecurity Engineer • Tempe, AZ, United States

    Related jobs
    Offensive Cybersecurity Engineer (Web and Cloud)

    Offensive Cybersecurity Engineer (Web and Cloud)

    Viasat • Tempe, AZ, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 17 days ago • Promoted
    Offensive Cybersecurity Engineer (Web and Cloud)

    Offensive Cybersecurity Engineer (Web and Cloud)

    ViaSat • Tempe, AZ, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 11 days ago • Promoted
    Senior Lead, Cyber Security Engineer (CyberArk)

    Senior Lead, Cyber Security Engineer (CyberArk)

    Northern Trust • Tempe, AZ, United States
    Full-time
    Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative f...Show more
    Last updated: 17 days ago • Promoted
    Insider Risk Engineer - Cyber

    Insider Risk Engineer - Cyber

    Western Alliance Bank • Phoenix, AZ, United States
    Full-time
    As a Insider Risk Engineer - Cyber you'll work both independently and as part of a cohesive team to manage and provide ownership of innovative threat detection, security audit, and logging solution...Show more
    Last updated: 17 days ago • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    Ports America Shared Services, Inc. • Tempe, AZ, United States
    Full-time
    In the maritime industry, where colossal ships dock, and millions of tons of cargo are moved with precision, it takes teams of dedicated individuals to keep global trade in motion.Working in this d...Show more
    Last updated: 17 days ago • Promoted
    Cybersecurity Engineer

    Cybersecurity Engineer

    Maricopa Community College district • Tempe, AZ, United States
    Full-time +1
    District Support Services Cntr.Summer Hours : Monday - Thursday, 7am-6pm.The Maricopa County Community College District is one of the largest community college systems in the nation.Home to 10 indiv...Show more
    Last updated: 9 days ago • Promoted
    Cybersecurity Saviynt engineer

    Cybersecurity Saviynt engineer

    Syntricate Technologies • Scottsdale, AZ, United States
    Full-time
    Must have 3-5 years minimum Saviynt experience • Must have strong experience working on Linux servers • Collate functional and technical requirements related to Identity Governance • Work with partner...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cybersecurity Engineer II

    Senior Cybersecurity Engineer II

    American Express • Phoenix, AZ, United States
    Full-time
    At American Express, our culture is built on a 175-year history of innovation, shared values and Leadership Behaviors, and an unwavering commitment to back our customers, communities, and colleague...Show more
    Last updated: 9 days ago • Promoted
    Director of Cybersecurity Architecture

    Director of Cybersecurity Architecture

    Verra Mobility • Phoenix, AZ, United States
    Full-time
    Verra Mobility is a global leader in smart mobility.We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with ...Show more
    Last updated: 13 days ago • Promoted
    Insider Risk Engineer - Cyber

    Insider Risk Engineer - Cyber

    Software Resources • Phoenix, AZ, United States
    Permanent
    Software Resources has an immediate, direct hire job opportunity for an Insider Risk Engineer - Cyber with a major corporation in Phoenix, AZ. User Entity Behavior Analytics (UEBA).Must be able to i...Show more
    Last updated: 5 days ago • Promoted
    Manager, OT Cybersecurity

    Manager, OT Cybersecurity

    KPMG • Phoenix, AZ, United States
    Full-time
    KPMG Advisory practice is currently our fastest growing practice.We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this ever-changing market envi...Show more
    Last updated: 30+ days ago • Promoted
    Remote vCISO - Strategic Cybersecurity Leader for Clients

    Remote vCISO - Strategic Cybersecurity Leader for Clients

    Lumifi Cyber • Scottsdale, AZ, United States
    Remote
    Full-time
    A cybersecurity consulting firm is seeking a Virtual Chief Information Security Officer (vCISO) to provide strategic leadership and manage cybersecurity programs for clients.The ideal candidate wil...Show more
    Last updated: 1 hour ago • Promoted • New!
    Lead Cybersecurity Engineer; HP NonStop Systems

    Lead Cybersecurity Engineer; HP NonStop Systems

    Capital One • Phoenix, AZ, United States
    Full-time +1
    Lead Cybersecurity Engineer; HP NonStop Systems.In this key technical Lead Cybersecurity role, you'll be responsible for the overall security architecture, design, and configuration of the PULSE HP...Show more
    Last updated: 6 days ago • Promoted
    Senior Cybersecurity Engineer (Networking)

    Senior Cybersecurity Engineer (Networking)

    Amentum • Phoenix, AZ, United States
    Full-time
    Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in scien...Show more
    Last updated: 17 days ago • Promoted
    Cybersecurity Engineer (SOAR) [JOB ID 20251117]

    Cybersecurity Engineer (SOAR) [JOB ID 20251117]

    Phoenix Cyber • Phoenix, AZ, US
    Full-time
    Quick Apply
    Phoenix Cyber is looking for Cybersecurity Engineers to join our client delivery team.This is a remote, work-from-home position with the possibility of minimal travel within the continent...Show more
    Last updated: 11 days ago
    Cybersecurity Eng II - Engineer II

    Cybersecurity Eng II - Engineer II

    Inficare • Phoenix, AZ, United States
    Full-time
    Role : Cybersecurity Eng II - Engineer II.Skills : Java, Spring, Python, React / React JS, Node / Node JS, Postgres / Postgresql, Postman, Docker, AWS, GCP, Regression, Performance Testing, Functional Test...Show more
    Last updated: 14 days ago • Promoted
    Cybersecurity Engineer

    Cybersecurity Engineer

    Maricopa Community College District • Tempe, AZ, United States
    Full-time +1
    District Support Services Cntr.Summer Hours : Monday - Thursday, 7am-6pm.The Maricopa County Community College District is one of the largest community college systems in the nation.Home to 10 indiv...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    Humana • Phoenix, AZ, United States
    Full-time
    Become a part of our caring community and help us put health first.The Senior CyberSecurity Engineer develops and tests information security tools, applications, and system solutions deployed in Hu...Show more
    Last updated: 4 days ago • Promoted