Cybersecurity Engineer
American Tower Global · Cary, NC, United States
About The Role
The Team
We are seeking a Cybersecurity Engineer to join American Tower’s Information Security organization. The Information Security team is responsible for protecting the confidentiality, integrity, and availability of American Tower’s data and systems across core platforms, global networks, cloud-connected environments, and distributed users. As a Cybersecurity Engineer, you will play a hands-on role in supporting and improving enterprise network security, cloud security, and secure access controls through administering enterprise-grade firewalls, cloud security tools, and Zero Trust Network Access (ZTNA) solutions. This role is intended for a security professional who can independently complete assigned technical work, support operational improvements, and collaborate with infrastructure and application engineers as well as cross-organizational technical resources on policy, segmentation, connectivity, and modernization initiatives. You will work closely with other cybersecurity engineers, infrastructure teams, cloud teams, network operations, and business stakeholders to help improve firewall and secure access policies, troubleshoot hybrid and cloud connectivity, implement secure configurations, and continuously strengthen American Tower’s security posture against evolving threats.
What You Can Offer Us
- Support enterprise network and cloud security controls across Palo Alto Next-Generation Firewall (NGFW), secure access, and cloud security platforms.
- Administer and enforce Palo Alto NGFW policies, security profiles, and rule-based hygiene.
- Configure and troubleshoot Azure and Amazon Web Services (AWS) network security, including routing, segmentation, Virtual Private Network (VPN), Web Application Firewall (WAF), private access, and hybrid connectivity.
- Implement and support secure access solutions, such as Zscaler, for secure internet, private application, and identity-aware access.
- Configure Cloud Security Posture Management (CSPM)/Cloud-Native Application Protection Platform (CNAPP) integrations, including troubleshooting, visibility validation, posture tuning, vulnerability findings, and remediation workflows.
- Collaborate with technical teams to validate connectivity, segmentation, least privilege access, and secure cloud configuration patterns.
- Investigate security events, access issues, routing anomalies, and performance concerns using logs and security telemetry.
- Review network designs, validate firewall and routing requirements, and recommend secure implementation approaches.
- Maintain runbooks, configuration baselines, implementation standards, and operational documentation.
- Identify and remediate misconfigurations, policy gaps, overly permissive access, routing issues, and cloud security risks.
- Improve security operations through policy hygiene, access reviews, reporting, automation support, metrics, and process improvements.
- Perform other duties as assigned.
What You Need to Succeed
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent experience required.
- 3+ years of cybersecurity operations or engineering experience with a focus on network security in hybrid environments, including at least 1 year managing firewalls, security groups, Access Control Lists (ACLs), and network segmentation controls required.
- Hands-on experience implementing, administering, and troubleshooting enterprise-grade firewalls, layer-7 load balancers, WAFs, and ZTNA solutions required.
- Working knowledge of zero trust and privileged access architectures, including traffic forwarding, identity-aware access controls, policy enforcement, secure application connectivity, and least-privilege access models across cloud, hybrid, and remote user environments.
- Experience using log analysis, security monitoring platforms, Security Information and Event Management (SIEM), and Microsoft Security Suite tools such as Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID, or related platforms to detect, investigate, and respond to threats.
- Understanding of identity and access management principles as they relate to Zscaler application access, user authentication, authorization, privileged access, and least privilege access models.
- Experience with network security concepts across cloud and hybrid environments, particularly within Azure and AWS.
- Familiarity with supporting Wiz platform across various cloud environments, including cloud account onboarding, security posture reviews, vulnerability and misconfiguration detection, attack path analysis, workload visibility, and remediation workflows that improve cloud security resilience.
- Experience with automation, scripting, or query languages such as PowerShell, Python, Ansible, or Kusto Query Language (KQL) is a plus.
- Good judgment, a sense of urgency, and a commitment to high standards of ethics, regulatory compliance, customer service, and business integrity.
- Strong written and verbal communication skills, including the ability to document technical procedures, explain security risks, and collaborate effectively with technical and non-technical stakeholders.
- Strong organizational skills, with the ability to manage multiple priorities and deliver results in a fast-paced environment.
- Approximately 5% travel may be required to support the position’s responsibilities.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
