{"id":1512010,"url":"https://alion.io/job/first-student-lead-cybersecurity-engineer","title":"Lead Cybersecurity Engineer","company":{"id":1861742,"name":"First Student","domain":"firststudentinc.com","url":"https://alion.io/company/firststudentinc-com","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Cincinnati, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":130000,"max":155000,"currency":"USD","period":"year","gross":null,"usd_annual":155000},"salary_estimate":null,"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"Amazon S3","optional":false},{"name":"AWS","optional":false},{"name":"AWS Lambda","optional":false},{"name":"IAM","optional":false},{"name":"Incident Management","optional":false},{"name":"ITIL","optional":false},{"name":"NIST CSF","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-09-01T00:00:00Z","employer_posted_date":"2026-09-01","last_verified_at":"2026-10-04T02:21:09Z","board_verified":true,"closed_at":null,"days_open":33,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":33},"description":"The Lead Cybersecurity Engineer is a senior individual contributor on First Student’s Cybersecurity team, responsible for the day-to-day design, engineering, oversight, and operation of the controls that protect First Student’s cloud, endpoint, application, and identity environments. The role leads cybersecurity engineering projects, drives detection and response engineering, and serves as a senior technical resource for cybersecurity investigations and cross-functional partnership with I&O, Data, and Application teams.\nThis is a hands-on practitioner role. The individual is expected to lead engineering execution, mentor junior team members, and provide technical oversight and peer review of the team’s work product within cybersecurity.\nResponsibilities\nIdentify and assess\nPerform cybersecurity assessments and technical reviews for new platforms, cloud services, identity/authN/authZ changes, and externally-facing systems.\nLead offensive-informed technical assessments and translate findings into remediation plans.\nPerform threat modeling for cloud and SDLC initiatives.\nSecurely build and protect\nEngineer and lead operations of cybersecurity controls and cloud security posture management.\nAuthor and code-review IaC for cloud governance components, including cloud policy management.\nProvide SDLC cybersecurity engineering, including SAST and DAST program operation and secure code guidance for custom applications.\nProvide oversight for identity and endpoint tooling and support enterprise secrets management.\nMonitor, hunt, and detect\nOwn the technical integration of First Student systems and log sources into the managed MDR platform, and coordinate with the MDR provider on detection use cases, scenario-based workshops, and joint investigations.\nTune telemetry and sensor platforms to reduce false positives and improve detection fidelity.\nMaintain existing and build new cybersecurity dashboards and telemetry that feed operational and leadership-facing reporting.\nRespond, recover, and sustain\nServe as a senior technical lead for cybersecurity incidents, directing investigation, evidence collection, and containment across identity, endpoint, cloud, and email in coordination with I&O and MDR partners.\nMaintain incident investigation templates, IR runbooks, and technical playbooks; drive lessons-learned and control improvements post-incident.\nSupport the incident management technical workflow and tabletop exercise execution.\nGovern and manage risk\nContribute technical content to policies and standards (e.g., Vulnerability Management, cloud security, SDLC).\nInterpret control requirements and translate them into enforceable technical controls.\nSupport leadership-facing reporting with technical evidence and narrative for internal reviews and external assessment cycles.\nContribute technical evidence to cyber risk acceptance packages.\nLead and coordinate\nProvide technical oversight and peer review of the cybersecurity team’s work product.\nMentor cybersecurity analysts and junior engineers on cloud cybersecurity, investigations, and secure design; support individual growth plans in coordination with the Senior Director.\nLead cybersecurity engineering projects end to end, including planning, effort estimation, resource coordination, and delivery.\nLiaise with cybersecurity vendors and managed service providers for issue resolution and operational escalation.\nDesired qualifications\nEducation and certifications\nBS/BA in IT, Computer Science, Engineering, or related field, or equivalent experience.\nIndustry certifications preferred: one or more of AWS Certified Security - Specialty, AWS Certified Solutions Architect - Associate/Professional, SANS/GIAC (GSEC, GCIH, GCSA, GCPN, GCIA), CISSP, CCSP, CRISC.\nKnowledge and experience\n10+ years total experience in IT, with 5+ years of hands-on, demonstrated experience in one or more of cybersecurity engineering, cloud engineering, or DevOps.\nDeep, hands-on AWS cybersecurity engineering: Organizations/Control Tower, SCPs and tag policies, IAM Identity Center, KMS key policy design, S3 hardening, Lambda runtime lifecycle, VPC segmentation and flow logging, CloudTrail/GuardDuty/Security Hub, Systems Manager, and cloud security posture management.\nWorking experience with managed MDR services, including onboarding and troubleshooting log sources, tuning detections in partnership with the provider, automating response, and participating in scenario-based workshops and joint IR execution.\nEDR operations and incident response experience.\nSDLC cybersecurity experience, including hands-on operation of SAST and DAST tooling, secure design review for cloud-native stacks, and remediation guidance for development teams.\nIncident response experience on identity, cloud, and application-exposure incidents; ability to produce investigation reports suitable for leadership and legal review.\nWorking fluency in IaC review; proficiency in Python or PowerShell for automation, reporting, and control validation.\nStrong understanding of NIST CSF 2.0, CIS Controls, and CIS AWS Foundations Benchmark; ability to translate framework requirements into enforceable, testable controls.\nFamiliarity with ITIL and Agile delivery practices.\nFamiliarity with the Microsoft 365 cybersecurity stack.\nPersonal attributes\nDeep technical knowledge, strong analytical and problem-solving skills, and the ability to manage complex technical projects.\nStrong written and oral communication skills; strong interpersonal skills.\nCustomer-focused mindset and attention to detail.\nOperates independently and drives outcomes to closure. Comfortable defining technical requirements and holding partner teams accountable for implementation without direct execution authority.\nComfortable holding multiple technical domains simultaneously (cloud, detection, SDLC, IR) and prioritizing across them without daily direction.\nEffective across organizational boundaries: I&O, Data, Applications, Legal, and external MDR/consulting partners.\nHigh-integrity, ownership-first mindset. Proactive on risk reduction.\nCompensation ranges from $130,000 - $155,000 depending on experience.\nLanguage Requirement\nThis role requires English proficiency. Federal, state, and local requirements, including U.S. Department of Transportation (DOT) regulations, require training, safety communications, company policies, employment documents, and other job-related communications be conducted in English.\n\nFirst for a reason:\nAt First Student, we are a family of 60,000+ employees who take pride in safely transporting more than 5 million students and passengers to and from their destinations each day! Our family of brands include Transco, Total Transportation, Maggies Paratransit, and GVC II. Our employees are at the forefront of safety and innovation; they create and implement the most advanced training and technology the transportation industry has to offer.\nIn the state of Washington, all technician and driving positions, including but not limited to van drivers and any other position requiring employees to drive a company-owned vehicle, are considered safety-sensitive and are therefore subject to drug and alcohol testing, including cannabis.\nAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. First is also committed to providing a drug-free workplace. First will consider for employment qualified applicants with criminal histories consistent with the requirements of the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Ordinance, and any other fair chance law. Philadelphia’s Fair Criminal Record Screening Standards Ordinance Poster is at this link or upon request https://www.phila.gov/media/20210423160847/Fair-Chance-Hiring-law-poster.pdf.","description_format":"text","description_chars":7861,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Public Transport","EV Charging"],"lifecycle":[{"event":"open","at":"2026-09-30T08:14:34Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"green card filings: 1","filings_12m":0,"filings_prev_12m":2,"green_card_filings_12m":1,"median_offered_wage_usd":117500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)","US Department of Labor: PERM disclosure data (green cards)"],"filings_for_role_12m":0}],"liveness":{"score":17,"band":"cold","label":"Long shot","p_open":1,"p_active":0.489,"p_room":0.35,"age_days":32,"expected_fill_days":9,"reasons":["conf:28","urgency","win:tail","comp:brand"],"computed_at":"2026-10-03T05:45:00Z"},"pay":{"stated_usd_annual":155000,"is_top_pay":false},"html_url":"https://alion.io/job/first-student-lead-cybersecurity-engineer","json_url":"https://alion.io/job/first-student-lead-cybersecurity-engineer.json","meta":{"generated_at":"2026-10-04T03:08:53Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4781,"day_limit":5000,"remaining_today":219,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}