In today’s dynamic environment, business leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership, using a hands-on approach to understand the specific needs of the organization and create tailored solutions to address key compliance risks.Our Cyber Security Advisory (CSA) services include building GRC/Cybersecurity programs from the ground up, framework readiness, design and maintenance of critical security domains, managed internal controls testing and monitoring, co-sourced/outsourced internal audit, segregation of duties and access risk review, policy and procedure development, enterprise risk management, and IT and cybersecurity risk assessment.Our work spans the full security lifecycle, from program strategy and risk advisory to compliance readiness and hands-on remediation. We serve startups, mid-market companies, and PE-backed portfolios at any stage of their security journey, across a wide range of industries and regulatory environments.The Cybersecurity Engineering Lead is a key delivery role within the practice. You will protect our clients' digital assets from ever-evolving cyber threats, be responsible for designing, implementing, and maintaining security solutions that safeguard sensitive data and infrastructure. You will work closely with senior practice leadership, mentor junior team members, and contribute across our cybersecurity engineering, GRC, and security strategy teams as engagement needs evolve. This is a role for someone who enjoys variety, takes ownership naturally, and wants to grow in a client-facing advisory environment.What You Have5+ years in cybersecurity or cloud security engineering, with hands-on experience across at least two major cloud providers (AWS, GCP, Azure).Expertise in zero-trust architecture, cloud networking, container security (Kubernetes, Docker), secrets management, vulnerability management, and data protection across multi-cloud environments.Understanding of compliance frameworks and cloud-native threat models.Relevant credentials such as AWS Certified Security – Specialty, Google Cloud Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate (AZ-500), or CISSP preferred.Who You AreYou take ownership of your work and your client relationships. You bring people along rather than waiting to be told what to do.You think about security in terms of business impact, not just technical controls.You are adaptable. You can move between an engineering, strategy, compliance, or technical architecture conversation without losing your footing.You are a natural collaborator. You work well across teams, and you make the people around you better.You are curious and motivated to keep growing. The security landscape moves fast, and you stay with it.You enjoy being part of something bigger, including recruiting, training, firm events, and building a practice that stands out in the market.What You'll DoThreat Detection & Response: Monitor and analyze security telemetry across platforms using Azure Sentinel, AWS GuardDuty/CloudTrail, and Google Cloud Logging. Investigate alerts, respond to incidents, and tune detection rules for multi-cloud environments.Identity and Access Management: Design and implement identity solutions across multi-cloud environments including Azure Entra ID / AWS IAM / GCP Identity and Access Management, Role-Based Access Control (RBAC), and Privileged Access Management (PAM). Enforce least-privilege principles and zero-trust identity frameworks.Security Posture & Compliance: Deploy and maintain cloud-native security tools—Microsoft Defender for Cloud, AWS Security Hub, and Google Cloud Security Command Center—to enforce security baselines, detect misconfigurations, and maintain regulatory compliance (SOC 2, ISO 27001, PCI-DSS, HIPAA).Cloud Infrastructure Security: Secure cloud networking, data encryption, and workload protection across Azure (NSGs, Application Gateways), AWS (Security Groups, NACLs, VPC), and GCP (VPCs, Cloud Armor, Firewall Rules) and CSPM Platforms. Implement encryption, DLP, and data residency controls.Automation & DevSecOps: Embed security controls into CI/CD pipelines using Infrastructure-as-Code (Terraform, CloudFormation, Deployment Manager) and scripting (Python, Bash, PowerShell). Automate compliance scanning and remediation across all three clouds.AI-Accelerated Internal Tooling & Innovation: Develop and enhance internal security tools and automation frameworks using AI platforms such as Claude, GitHub Copilot, and other LLM technologies. Leverage generative AI to accelerate code generation, security script development, threat analysis automation, and documentation, enabling faster iteration on security solutions and driving continuous innovation across the security program.About Riveron:At Riveron, we partner with clients—from global multinationals to high-growth private entities—to solve complex finance challenges, guided by our DELTA values: Drive, Excellence, Leadership, Teamwork, and Accountability. Our entrepreneurial culture thrives on collaboration, diverse perspectives, and delivering exceptional outcomes. We are committed to fostering growth, both for our clients and our people, through mentorship, integrity, and a client-centric approach. This inclusive environment offers flexibility, progressive benefits, and meaningful opportunities for impactful work that supports well-being in and out of the office. Want to stay connected with Riveron? Join our Talent Community to learn more about our growing firm and be considered for future opportunities.Check us out on social media: LinkedIn Glassdoor Instagram Facebook Riveron Consulting is an Equal Opportunity Employer and believes that we are stronger together through our diversity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability status, protected veteran status, sexual orientation, gender identity or any other characteristic protected by law.Full time roles are eligible for a full range of benefits including medical, dental, and vision insurance, 401(k) with company match, and PTO. A complete description of all available benefits can be found at Riveron's Benefits page at https://riveron.com/riveron-life/. Contract roles are not eligible for benefits.Fraud AlertPlease beware of fraudulent schemes or impersonations when going through the job application process. A Riveron employee will never recruit via text or extend unsolicited employment offers. Additionally, a Riveron employee will never ask you to exchange money or purchase anything as part of the recruiting process.Artificial intelligence (AI) tools are used to support the hiring process in screening, assessing, and/or selecting applicants for this position. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.