Cybersecurity Engineer II
Cybersecurity Engineer II
Who We Are
At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’s customer-facing operating units include industry-leading brands such as Rent-A-Center, Acima and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company-branded retail units across the United States, Mexico, New York and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas.
Role Summary
We are seeking a hands-on Cybersecurity Engineer II to join our Security team. This role is responsible for the day-to-day engineering, administration, and support of core security platforms that protect our infrastructure, data, and users, including our privileged access management (PAM) platform and our Zscaler environment. The Cybersecurity Engineer will also drive Data Loss Prevention (DLP) initiatives, assist in IAM operations and support, help resolve security support tickets, and contribute to network security engineering activities across our hybrid environment.
This is an operationally focused engineering role, ideal for a security professional who enjoys owning platforms end to end: deploying, tuning, supporting, and continuously improving the controls that the business relies on every day. As part of an AI-native engineering organization, the Cybersecurity Engineer will be expected to embrace AI-driven ways of working, using GenAI tools, AI assistants, and agentic workflows to accelerate policy tuning, ticket resolution, investigation, and documentation, and to help identify opportunities to automate routine security engineering operations.
Key Responsibilities
Privileged Access Management (PAM)
- Assist in managing the enterprise PAM platform (Delinea Secret Server), including secret and vault management, folder and permission structures, discovery rules, and platform upgrades and health monitoring.
- Onboard privileged accounts across servers, databases, network devices, applications, and cloud services; enforce credential rotation, check-in/check-out workflows, and session recording and auditing.
- Drive reduction of standing privilege through just-in-time elevation, least-privilege access policies, and periodic privileged access reviews in partnership with IAM and infrastructure teams.
- Support integration of PAM with Active Directory, SIEM, and service account and secrets management workflows for both human and non-human identities.
Zscaler Deployment, Management, and Support
- Deploy, manage, and support the Zscaler platform, including Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Client Connector across the enterprise.
- Author and tune policies for URL filtering, SSL inspection, cloud app control (CASB), bandwidth control, and firewall rules within ZIA; build and maintain ZPA application segments, access policies, and app connectors to enable Zero Trust Network Access (ZTNA).
- Manage Zscaler client rollouts, agent health, traffic forwarding (tunnels, PAC files, GRE/IPSec), and location/sub-location configuration; troubleshoot user connectivity, latency, and access issues.
- Monitor Zscaler dashboards and logs, integrate telemetry with the SIEM, and partner with network and helpdesk teams to resolve escalations and continuously improve the user experience.
Data Security
- Deploy, operate, and tune DLP controls across endpoint, network, email, web, and cloud channels using Microsoft Purview and Zscaler DLP to prevent exfiltration of sensitive consumer data such as PII and SPI.
- Extend DLP coverage to AI platforms, including controls that detect and block sensitive data from being submitted to GenAI tools, external LLMs, and AI assistants, in alignment with enterprise AI acceptable use policies.
- Author and maintain DLP policies, data classification rules, and detection logic, including custom dictionaries and exact data matching (EDM); manage false-positive tuning with business stakeholders.
- Triage and investigate DLP alerts and incidents, document findings, and coordinate remediation and user education with HR, Legal, and Compliance as appropriate.
- Support Data Security Posture Management (DSPM) capabilities to discover, classify, and continuously monitor sensitive data across cloud storage, databases, SaaS platforms, and unstructured repositories.
- Assist in remediating data exposure risks surfaced through DSPM, including over-permissioned data stores, shadow data, stale sensitive data, and excessive access paths.
- Partner with Data, Privacy, and Compliance teams on data classification, retention, and minimization efforts, and validate data store security posture before data is exposed to AI platforms and workflows.
Identity and Access Management (Microsoft Entra ID)
- Provide day-to-day IAM support and maintenance for Microsoft Entra ID, including user and group lifecycle administration, enterprise application and app registration management, and directory hygiene.
- Administer and tune Conditional Access policies, multi-factor authentication (MFA), and device compliance requirements to enforce least-privilege, risk-based access.
- Support single sign-on (SSO) integrations (SAML, OAuth 2.0/OIDC, SCIM provisioning) for enterprise and SaaS applications, and troubleshoot authentication and access issues.
- Assist with Entra ID Governance activities, including access reviews, entitlement management, and Privileged Identity Management (PIM) for just-in-time role elevation.
Security Support and Ticket Management
- Assist with security support tickets and service requests within defined SLAs, including access issues, policy exceptions, allowlist/blocklist changes, certificate issues, and security tool troubleshooting.
- Serve as an escalation point for the helpdesk on security platform issues; document root causes, maintain runbooks and knowledge base articles, and identify recurring issues for permanent fixes or automation.
- Support audit and compliance requests with evidence collection, access reviews, and control documentation.
Network Security
- Support network security engineering activities including firewall rule reviews and changes, network segmentation, IDS/IPS, VPN, and egress filtering across on-premises and cloud environments.
- Participate in vulnerability remediation efforts for network and security infrastructure, including patching, hardening, and configuration baseline enforcement.
- Assist with security monitoring and incident response activities, including investigating alerts from network and security tooling and executing containment actions when required.
Required Qualifications
- 3-5 years of hands-on experience in cybersecurity engineering, security operations, or a related security infrastructure role.
- Hands-on experience administering a PAM platform (Delinea Secret Server strongly preferred; CyberArk, BeyondTrust, or equivalent considered), including privileged account onboarding, credential rotation, and session management.
- Hands-on experience deploying, managing, and supporting Zscaler (ZIA and/or ZPA), including policy administration, traffic forwarding, client connector management, and troubleshooting.
- Experience operating DLP controls across one or more channels (endpoint, network, email, web, or cloud) using Microsoft Purview, Zscaler DLP, or equivalent, including policy authoring, alert triage, and false-positive tuning. Exposure to DSPM platform and operations.
- Working knowledge of network security fundamentals: TCP/IP, DNS, proxies, firewalls, VPN, network segmentation, and TLS/SSL inspection.
- Experience working in a ticket-driven environment (ServiceNow, Jira, or equivalent) with a strong customer-service orientation and demonstrated ability to meet SLAs.
- Hands-on experience supporting and maintaining Microsoft Entra ID (Azure AD), including Conditional Access, MFA, SSO integrations, and user/group administration, along with familiarity with Active Directory and least-privilege principles.
- Strong troubleshooting, documentation, and communication skills; able to explain security requirements and issues to technical and non-technical audiences.
Preferred Qualifications
- Experience using AI tools (GenAI assistants, LLM-based copilots, or agentic workflows) as part of daily engineering and operational workflows, such as accelerating investigations, policy tuning, scripting, and documentation.
- Experience with Zero Trust architecture concepts (NIST SP 800-207) and ZTNA implementations.
- Experience with SIEM platforms (Rapid7, Microsoft Sentinel, or equivalent) and log integration from security tools.
- Exposure to cloud security in AWS, Azure, or GCP, including cloud-native IAM and security posture management.
- Scripting or automation experience (PowerShell, Python) for administrative and reporting tasks.
- Experience in regulated consumer finance, payments, or retail environments, with working knowledge of PCI DSS, GLBA, or SOX control expectations.
- Relevant certifications: Zscaler ZDTA, Zscaler ZTCA, CompTIA Security+, CompTIA CySA+, Delinea certifications, CISSP (or progress toward), or equivalent.
Work Location
Ability to work in the Plano, Texas Monday through Friday, with travel between locations as necessary based on transformation and governance activities.
Sponsorship
Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time.
Equal Opportunity Employer
Upbound Group is an equal opportunity employer committed to ensuring all employment decisions are made on a non-discriminatory basis in accordance with applicable federal, state, and local laws.