- Salary
- $115k – $145k
- Location
- Corporate Headquarters, United States of America
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Master
- Visa
- Not sponsored
- Closing date
- Today
- Source
- Workday
Description
Location: Cleveland, OH
Cleveland-Cliffs is currently seeking a Senior Cybersecurity Engineer - Security Architecture & Automation to help strengthen and scale our cybersecurity program through security architecture, incident response, threat hunting, and automation. Supporting one of North America's largest steel producers, this role focuses on designing resilient security solutions, automating response capabilities, and partnering across infrastructure, operations, OT, and cybersecurity teams to protect critical business systems while enabling reliable production.
Summary of Responsibilities
- Lead security architecture reviews of new systems, applications, cloud/SaaS services, third-party integrations, and OT/ICS requests, assuming initial access will happen and designing for segmentation, least privilege, zero-trust principles, and resilient recovery that holds up under both attacks and ordinary failures, then turn recurring patterns into engineering standards other teams and vendors design to
- Design and build security automation, including automated triage, enrichment, and response using SOAR, scripting, or AI-assisted workflows, so detection and response keep pace with attackers who move in minutes. This is where most of your week lives
- Right-size recommendations to real business risk, availability first, working with the business to land on solutions that are repeatable and supportable, and tie each one, including how identities actually get compromised (MFA bypass, help desk/voice social engineering, session and token theft) and how attackers abuse integrations, APIs, and AI tools, to the specific attack it stops
- Take periodic turns in a mature, shared on-call rotation across the cybersecurity team, leading incident response and threat hunting when events occur, and feed every incident back into architecture and automation
- Partner with our OT, vulnerability management/GRC, DevSecOps, AI security, and infrastructure teams, including certificate management, post-quantum cryptography readiness, and architecture at the IT/OT boundary, and share what you learn to help others grow
- Scope and participate in penetration tests, automated pen testing, and purple-team exercises, then turn what you learn and current threat intelligence into design and detection improvements
Minimum Qualifications
- 5+ years in cybersecurity, including hands-on incident response and experience in threat hunting or detection engineering
- Experience with SIEM-based detection and hands-on experience automating security work, including scripting (Python/PowerShell), APIs, SOAR, or AI-assisted workflows
- Working knowledge of network security, identity, data protection, endpoint, remote access, encryption, cloud, resilience (redundancy, failover, recovery), and vulnerability management
- Familiarity with penetration testing and purple-team methodology, and frameworks such as MITRE ATT&CK, NIST CSF, or CIS Controls
- Clear communication with both technical and non-technical audiences
- Understanding of the Purdue Model or IEC 62443 as OT/ICS security frameworks, since you'll be reviewing a steady stream of OT-related requests
- Bachelor's degree in a related field, or equivalent experience
- Must be able to work full-time onsite
- The ability to work closely with infrastructure, operations, engineering, and cybersecurity teams, making in-person collaboration an important part of success
- Applicants must be legally authorized to work in the United States
- Other duties as assigned
Preferred Qualifications
- Exposure to identity (IAM) or PAM, with room to grow into these areas
- Hands-on exposure to PLCs or other OT/ICS field devices
- Industry certifications (e.g., CISSP, GIAC, OSCP, CySA+)
- undefined
The salary range for this role is $115,000 to $145,000. An employee’s pay within the salary range will be based on numerous factors including, but not limited to, relevant education, qualifications, experience, skills, geographic location and business or organizational needs.
Cleveland-Cliffs is a leading North America-based steel producer with focus on value-added sheet products, particularly for the automotive industry. The Company is vertically integrated from the mining of iron ore, production of pellets and direct reduced iron, and processing of ferrous scrap through primary steelmaking and downstream finishing, stamping, tooling, and tubing. We offer an excellent total compensation package, including competitive pay with variable compensation opportunity, health insurance, retirement plan, education assistance, paid time off, and more.
Cleveland-Cliffs Inc. is committed to working with and providing reasonable accommodation to individuals with disabilities. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the employment process, please send an e-mail to [email protected] or call 1-(312) 899-3097 and let us know the nature of your request and your contact information. Do not email your application materials to this email address. Application materials sent to this email address will not be considered.
Cleveland-Cliffs Inc. is an equal opportunity employer – M/F/Veteran/Disability. We are a drug-free workplace and conduct pre-employment screening as a condition of employment.