Cybersecurity Engineer II

Upbound Group - Plano, TX

Hiring: Cybersecurity Engineer II Company: Upbound Group Location: Plano, TX Job Posted Time: 2026-09-10 12:09:58 Employment Type: Hybrid Target Skills & Keywords : AWS, Azure, Azure AD, Cloud Storage, CyberArk, DNS, GCP, IAM, Jira, LLM, OAuth2, OIDC, PCI DSS, PowerShell, Python, SAML, SIEM, SSL, SaaS, ServiceNow, TCP/IP, TLS, User Experience, VPN, Vault, Zero Trust About the job Experience: •3-5 years of hands-on experience in cybersecurity engineering, security operations, or a related security infrastructure role. •5 years of hands-on experience in cybersecurity engineering, security operations, or a related security infrastructure role. Required Skills: •Privileged Access Management (PAM) •Assist in managing the enterprise PAM platform (Delinea Secret Server), including secret and vault management, folder and permission structures, discovery rules, and platform upgrades and health monitoring. •Onboard privileged accounts across servers, databases, network devices, applications, and cloud services; enforce credential rotation, check-in/check-out workflows, and session recording and auditing. •Drive reduction of standing privilege through just-in-time elevation, least-privilege access policies, and periodic privileged access reviews in partnership with IAM and infrastructure teams. •Support integration of PAM with Active Directory, SIEM, and service account and secrets management workflows for both human and non-human identities. •Zscaler Deployment, Management, and Support •Deploy, manage, and support the Zscaler platform, including Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Client Connector across the enterprise. •Author and tune policies for URL filtering, SSL inspection, cloud app control (CASB), bandwidth control, and firewall rules within ZIA; build and maintain ZPA application segments, access policies, and app connectors to enable Zero Trust Network Access (ZTNA). Qualifications: •Hands-on experience administering a PAM platform (Delinea Secret Server strongly preferred; CyberArk, BeyondTrust, or equivalent considered), including privileged account onboarding, credential rotation, and session management. •Hands-on experience deploying, managing, and supporting Zscaler (ZIA and/or ZPA), including policy administration, traffic forwarding, client connector management, and troubleshooting. •Solid functional working knowledge of network security fundamentals: TCP/IP, DNS, proxies, firewalls, VPN, network segmentation, and TLS/SSL inspection. •Hands-on experience supporting and maintaining Microsoft Entra ID (Azure AD), including Conditional Access, MFA, SSO integrations, and user/group administration, along with familiarity with Active Directory and least-privilege principles. •Strong troubleshooting, documentation, and communication skills; able to explain security requirements and issues to technical and non-technical audiences. •Exposure to cloud security in AWS, Azure, or GCP, including cloud-native IAM and security posture management. •Scripting or automation experience (PowerShell, Python) for administrative and reporting tasks. •Relevant certifications: Zscaler ZDTA, Zscaler ZTCA, CompTIA Security+, CompTIA CySA+, Delinea certifications, CISSP (or progress toward), or equivalent. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!