Skip to main content

Hillpointe

Cybersecurity Engineer

  • Confirmed live in the last 24 hours
  • No salary listed
  • Mid level
  • On-site · Winter Park, FL
  • 4+ yrs exp
  • Added today

About this role

WHY HILLPOINTE? Hillpointe is a fully integrated real estate development and investment management firm focused on developing market-rate workforce housing across the Sun Belt. Ranked at the top of NMHC's list of Builders and Developers, our team ensures best-in-class execution.

Built on its long and proven track record of real estate development, the firm’s investment approach is centered around its in-house general contracting expertise, enabling direct control of cost and delivery timeframe. For each project, Hillpointe directly controls land acquisition, land development, construction, procurement of building materials, asset management, and capital markets. This is more than just a job - it's a career-defining opportunity! At Hillpointe, you'll be part of a dynamic, innovative team that has tangible impacts on day-to-day operations and contributes directly to overall success.

Cybersecurity Engineer


The Cybersecurity Engineer owns the day-to-day security operations of the organization's fully cloud-based technology environment. This is the company's dedicated security role, and it operates with a high degree of independence: the incumbent drafts and sets the approved operational security agenda, oversees external MDR, drives vulnerability and access remediation with system owners, and carries the organization through external audit. Because the scope is broad by design, the role is structured to scale through leverage — directing managed security service providers and specialist vendors for around-the-clock monitoring and surge capacity, while retaining ownership of strategy, configuration, escalation, and outcomes in-house.

The successful candidate is equally comfortable investigating an alert at the console and explaining residual risk to business leadership. This is a high-visibility role with a direct line to decisions about how the organization protects its data, its residents' information, and its capital.

Key Responsibilities

Threat Detection & Incident Response

  • Own detection and response across cloud identity, endpoint, email, and cloud infrastructure, including triage, containment, eradication, and recovery
  • Serve as primary incident responder and incident commander for security events, coordinating internal stakeholders, managed service providers, and outside counsel or forensics as required
  • Maintain and exercise the incident response plan, including tabletop exercises and post-incident reviews that produce tracked corrective actions
  • Develop and tune detection rules, alert logic, and automated response playbooks to reduce mean time to detect and mean time to respond
  • Build and maintain runbooks for recurring incident types so that response is repeatable and not dependent on a single individual


Security Monitoring, SIEM & Reporting

  • Administer the security information and event management (SIEM) platform, including data source onboarding, log ingestion health, normalization, and retention configuration
  • Manage ingestion cost and data tiering to keep monitoring coverage aligned with budget
  • Build and maintain dashboards, analytics rules, and workbooks that provide operational visibility into the security posture of the cloud environment
  • Produce recurring security reporting for IT leadership and executive stakeholders, translating technical findings into business risk and clear recommendations
  • Define and track security metrics — detection coverage, alert volume and disposition, patch and remediation timeliness, phishing susceptibility, and audit readiness


Vulnerability & Configuration Management

  • Run the vulnerability management lifecycle across endpoints, servers, cloud workloads, and third-party platforms: discovery, assessment, risk-based prioritization, remediation tracking, and verification
  • Partner with system and application owners to drive remediation to closure, escalating where service-level targets are at risk
  • Assess and harden security configuration baselines against recognized benchmarks, and monitor for configuration drift
  • Coordinate external penetration testing and vulnerability assessments, and manage the resulting findings through to resolution
  • Maintain the risk register and formal exception process for accepted risks, with documented compensating controls and review dates


Identity & Privileged Access Governance

  • Administer privileged identity and privileged access management, including just-in-time elevation, approval workflows, activation justification, and time-bound role assignment
  • Conduct recurring privileged access reviews and audits, validating that standing administrative access is eliminated or justified and that every elevation is attributable
  • Own access review and recertification cycles across the cloud tenant and integrated business platforms, coordinating with business owners as reviewers
  • Review and strengthen conditional access, multifactor authentication, and device compliance policies, including break-glass account controls and their periodic testing
  • Monitor for identity-based threats — token theft, consent phishing, risky sign-ins, legacy authentication, and over-permissioned service principals and application registrations


Cloud & DevOps Security

  • Provide security oversight of the organization's cloud productivity tenant and cloud infrastructure platform, including tenant-level security configuration and posture management
  • Embed security into development and automation pipelines: secrets management, dependency and container scanning, infrastructure-as-code review, and pipeline identity and permission hygiene
  • Review and advise on cloud architecture changes, network segmentation, and secure-by-default configuration before deployment rather than after
  • Administer cloud-delivered secure access and secure web gateway capabilities for private application access, internet egress filtering, and conditional network controls
  • Govern third-party application consent, API permissions, and integration security across the cloud tenant


Data Protection, Compliance & eDiscovery

  • Serve as the primary owner for the annual SOC 2 audit: control mapping, evidence collection, gap remediation, auditor liaison, and management of the readiness timeline
  • Maintain the security control framework and supporting policy set, keeping documentation current and demonstrably operating
  • Administer the data governance and compliance platform, including data loss prevention policies, sensitivity labeling, retention, and insider risk controls
  • Conduct eDiscovery searches, legal holds, exports, and collection activities in support of legal, human resources, and compliance requests, maintaining defensible chain of custody
  • Support security questionnaires, investor and lender due-diligence requests, and cyber insurance renewals with accurate control attestations
  • Track applicable regulatory and contractual obligations relating to personal information and advise the business on required controls


Security Awareness & Human Risk

  • Own the security awareness program end to end: content selection, campaign calendar, assignment, completion tracking, and effectiveness measurement
  • Design and administer simulated phishing campaigns, including scenario selection, difficulty progression, targeting, and results analysis
  • Deliver targeted follow-up training and coaching for repeat-susceptible users, favoring constructive reinforcement over punitive measures
  • Provide role-specific training for higher-risk functions such as finance, accounting, and executive support, with emphasis on payment fraud and business email compromise
  • Contribute security content to new-hire onboarding in partnership with Human Resources and Training


Vendor & Managed Service Oversight

  • Manage outsourced security functions and managed security service providers, including scope definition, service-level expectations, escalation paths, and performance review
  • Validate provider work rather than accepting it at face value: review alert dispositions, challenge false-negative and false-positive patterns, and audit coverage gaps
  • Evaluate, pilot, and recommend security tooling, with attention to consolidation and total cost of ownership rather than point-solution accumulation
  • Own security vendor relationships, contract renewals, and license true-ups in coordination with IT leadership
  • Conduct third-party and vendor security risk assessments for new platforms prior to adoption

Qualifications

Required:

  • 4+ years of hands-on experience in cybersecurity operations, security engineering, or a security-focused systems administration role, in a predominantly cloud environment
  • Demonstrated experience with security monitoring and SIEM platforms, including detection tuning and investigation of real alerts through to disposition
  • Practical experience with endpoint detection and response and cloud-native security tooling across identity, endpoint, email, and cloud workloads
  • Working knowledge of cloud identity security, including conditional access, multifactor authentication, and privileged access management concepts
  • Experience running a vulnerability management program, including prioritization and driving remediation through other teams
  • Direct participation in a recognized audit or compliance program such as SOC 2, ISO 27001, or NIST Cybersecurity Framework, including evidence collection
  • Ability to lead an incident calmly under pressure and to document what happened clearly afterward
  • Strong written communication: policies, runbooks, findings, and executive-level summaries
  • Sound judgment about what to escalate and what to handle independently, with the discretion the role requires


Preferred:

  • Experience administering a cloud data governance and compliance platform, including data loss prevention and eDiscovery
  • Experience integrating security controls into CI/CD pipelines and infrastructure-as-code workflows
  • Experience managing or holding a managed security service provider accountable to service levels
  • Scripting or automation capability for reporting, evidence collection, and repetitive response tasks
  • Experience administering a security awareness and simulated phishing platform
  • Familiarity with secure access service edge or zero-trust network access technologies
  • Exposure to real estate, construction, property management, or another multi-site operating environment
  • Relevant certifications such as CISSP, CISM, GIAC, CCSP, or vendor-specific cloud security certifications; certification is valued but does not substitute for demonstrated hands-on capability

Work Environment:

  • This is a fully cloud-based environment. Incumbents primarily work in an office setting with occasional travel between office locations required. The role requires availability outside standard business hours for security incidents, and as the primary on-call escalation. Occasional extended hours may be needed to support audit deadlines, remediation windows, or critical incidents.

Written by Hillpointe. Original job post

Skills mentioned

  • CI/CD
  • DevOps
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Hillpointe

Industry
Real Estate & Construction
View all jobs at Hillpointe

Preparing likely interview questions for this role…