Hiring.Camp

Cyber Security Engineer(Cloud/SaaS)

Crescentenergyco

·

Today

Location
Houston, TX, United States of America
Type
Full-time
Department
Engineering
Experience
4+ years
Source
Workday

Description

Crescent is a differentiated U.S. energy company committed to delivering value through a disciplined, returns-driven growth through acquisition strategy and consistent return of capital. Our long-life, balanced portfolio combines significant cash flow from stable production with a deep, high-quality development inventory. Crescent is a top three producer in the Eagle Ford basin and a scaled operator in each of the Permian and Uinta basins. Crescent’s leadership is an experienced team of investment, financial and industry professionals that combines proven investment and operating expertise. For more than a decade, Crescent and our predecessors have executed on a consistent strategy focused on cash flow, risk management and returns. Through disciplined and accretive investments, we have successfully tripled the size of our company since going public in December 2021 while maintaining a strong balance sheet.


The Cybersecurity Engineer (Cloud/SaaS) is responsible for securing and governing cloud platforms, SaaS applications, APIs, AI-driven automation, and enterprise technologies across the organization. This role is critical to protecting the company’s digital assets by strengthening controls around SaaS integrations, machine-driven workflows, centralized logging, and cloud telemetry, while improving the organization’s ability to detect, investigate, and respond to cyber threats across the enterprise.

This position will lead and support the design, implementation, and continuous improvement of cloud and SaaS security controls, centralized logging capabilities, telemetry integrations, detection engineering, and incident response support processes. The ideal candidate brings hands-on experience with cloud and SaaS security, SIEM and SOC integrations, logging architecture, and security monitoring, along with the ability to partner across cybersecurity, infrastructure, applications, data, and business teams to improve enterprise resilience. This role will also help define and implement security best practices for agentic AI solutions, automation pipelines, and non-human workflows to ensure these technologies are deployed with appropriate guardrails, visibility, and governance. This individual will play an important role in advancing the company’s cybersecurity posture and supporting its journey toward becoming a secure, technology-enabled, and operationally resilient enterprise.

Key Responsibilities:

Cloud & SaaS Security

Secure and govern AI-driven automation, agentic workflows, SaaS platforms, and cloud-connected business processes across the enterprise.

Protect SaaS integrations, APIs, automation pipelines, service-to-service connections, and cloud-connected operational workflows from misuse, misconfiguration, excessive privilege, and unauthorized access.

Partner with application, infrastructure, and data teams to ensure cloud and SaaS platforms are deployed with appropriate security controls, monitoring, and governance across the enterprise.

Support the development and enforcement of security standards for cloud services, SaaS applications, machine identities, and AI-enabled workflows.

Centralized Logging, Visibility & Telemetry Enablement

Enable, maintain, and continuously improve centralized logging across cloud platforms, SaaS applications, enterprise services, and security tooling.

Ensure log integrity, retention, security, and availability are maintained in line with enterprise policy, compliance requirements, and operational needs.

Validate logging coverage across critical cloud, SaaS, and enterprise systems and identify gaps that may reduce detection or investigative effectiveness.

Collaborate with platform and infrastructure teams to onboard new systems and services into centralized logging pipelines.

SIEM, Detection Engineering & SOC Integration

Integrate cloud and SaaS telemetry with managed SOC providers, SIEM platforms, and approved security monitoring solutions.

Tune detection rules, monitoring logic, and alerting thresholds to improve visibility into SaaS activity, suspicious access behavior, API misuse, AI usage patterns, and anomalous activity across the enterprise.

Support SOC operations through alert triage, investigation, escalation, and response coordination.

Work with internal cybersecurity stakeholders and external monitoring partners to improve alert fidelity, reduce false positives, and strengthen response effectiveness.

Security Monitoring, Investigation & Response

Monitor cloud and SaaS environments to identify anomalous behavior, suspicious activity, policy violations, and indicators of compromise.

Support detection, investigation, and response efforts involving SaaS applications, APIs, cloud platforms, automation pipelines, and non-human identities.

Assist in incident response activities by gathering evidence, validating event scope, supporting containment actions, and coordinating with technical teams on remediation.

Partner with infrastructure and application teams during investigations involving cloud-connected systems and remote access pathways.

Document findings, lessons learned, and recommended control improvements following investigations or security events.

Continuous Improvement & Operational Cyber Resilience

Continuously enhance automation, detection, and response capabilities across the enterprise through process improvement, tooling optimization, and workflow standardization.

Identify opportunities to automate repetitive security tasks, improve telemetry quality, and increase visibility without disrupting business operations, production support, or operational uptime.

Support roadmap initiatives related to SaaS security, cloud monitoring, detection maturity, and AI governance.

Contribute to the development of standards, procedures, and repeatable controls that improve long-term cyber resilience across the enterprise.

Qualifications & Experience:

Education:

Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or a related field preferred.

Equivalent practical experience will be considered.

Relevant certifications such as CCSP, CISSP, GIAC, Azure/AWS security certifications, or other cloud and security operations certifications are a strong plus.

Experience:

4+ years of experience in cybersecurity, cloud security, SaaS security, security operations, or related security engineering roles.

Hands-on experience securing SaaS platforms, APIs, integrations, and cloud-connected workflows in enterprise environments.

Experience with centralized logging, SIEM integration, security monitoring, and detection engineering.

Experience supporting SOC operations, alert investigation, and incident response processes.

Familiarity with AI-driven automation, agentic workflows, service accounts, and machine identities is strongly preferred.

Experience supporting control validation, security policy enforcement, and audit activities in regulated environments is preferred.

Upstream oil and gas experience is strongly preferred.

Skills & Competencies:

Strong understanding of cloud security, SaaS security, API security, logging architecture, and telemetry management.

Ability to secure and govern AI-driven automation, agentic workflows, and machine-based activity in enterprise environments.

Working knowledge of SIEM platforms, managed SOC operating models, alert tuning, and incident response support practices.

Strong analytical and troubleshooting skills with the ability to investigate anomalous behavior and improve detection effectiveness.

Ability to balance security rigor with operational practicality in a fast-paced enterprise environment.

Strong collaboration skills with the ability to work across cybersecurity, infrastructure, applications, data, and business teams.

Clear communication skills with the ability to explain risks, findings, and technical issues to both technical and non-technical stakeholders.


Crescent Energy is an equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, gender/pregnancy, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status or any other legally protected status. Crescent Energy is also committed to compliance with all fair employment practices regarding citizenship and immigration status. If you require accommodation to complete the application process, please let us know by contacting [email protected].

Skills

AWSAzureCybersecuritySIEMSOCRisk ManagementComplianceCISSP