Cybersecurity Engineer III

Location:
5501 Headquarters Dr, Plano, Texas, 75024, United States of America

Who We Are

At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company's customer-facing operating units include industry-leading brands such as Rent-A-Center, Acima and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company-branded retail units across the United States, Mexico, New York and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas.

Role Summary

The Cybersecurity Engineer designs, builds, and operates enterprise security capabilities across Zero Trust, data security, identity and access management, network security, and privileged access management. This role blends architectural thinking, standards, reference patterns, and design reviews, with hands-on engineering execution: implementation, configuration, automation, and tuning. The Cybersecurity Engineer partners with Enterprise Architecture, Security Engineering, IT, Platform Engineering, Cloud Operations, Privacy, and Risk/Compliance to ensure security controls are both well-designed and reliably deployed across the enterprise.

This role is suited to an experienced security professional who wants to work across both the design and delivery of enterprise security capability: someone comfortable defining a standard and then personally building, configuring, and operating the control that meets it.

As part of an AI-native engineering organization, the Cybersecurity Engineer is expected to build AI engineering skillsets alongside core security engineering: using GenAI tools, AI assistants, and agentic workflows to accelerate policy tuning, investigation, automation, and documentation, and to help design and engineer the AI security controls (guardrails, access scoping, and audit logging) needed as GenAI and agentic tooling are adopted across the enterprise.

Key Responsibilities

  • Design and engineer Zero Trust architecture, including network segmentation, conditional access, device trust, and secure remote access, and lead hands-on implementation across environments.
  • Assist in architectural and implementation functions for data security controls, including DLP and DSPM platforms, data classification, encryption, and key management, ensuring protections are deployed and operating effectively, not just designed on paper.
  • Partner with the IAM team to design, build, and maintain enterprise IAM capabilities, including SSO, MFA, and lifecycle automation, alongside Privileged Access Management (PAM) architecture and hands-on administration.
  • Design and implement network security architecture, including segmentation models, secure connectivity, firewall and proxy policy, and Zero Trust network access (ZTNA).
  • Contribute to enterprise security architecture standards, reference designs, security reference architectures and patterns, ensuring they are practical to implement and reflected in real deployed configurations.
  • Participate in architecture and design reviews for major initiatives, validating that Zero Trust, data security, IAM/PAM, and network security requirements are met.
  • Support target-state security roadmap and reference architecture domains and controls, such as Zero Trust maturity, IAM/PAM modernization, and data security posture improvement, and help translate them into engineering backlogs.
  • Contribute to security governance processes, including exception handling, risk acceptance support, and documentation of architectural and engineering decisions.
  • Partner with Security Engineering, IT, and Platform teams to ensure designs are operationally supportable, automatable, and measurable.
  • Evaluate and help select vendors and tools for Zero Trust, DLP/DSPM, IAM/PAM, and network security, including proof-of-concept execution.
  • Map security architecture and engineering controls to compliance frameworks (NIST CSF, NIST 800-53, SOC 2, ISO 27001, PCI DSS), supporting auditability.
  • Maintain clear technical and architecture documentation, and communicate standards and engineering decisions to stakeholders through presentations, docs, and working sessions.
  • Use AI-driven tooling, including GenAI assistants, agentic workflows, and automation scripts, to accelerate day-to-day security engineering work such as policy tuning, investigation, remediation, reporting, and documentation across Zero Trust, IAM/PAM, data security, and network security.
  • Help implement baseline AI security controls for enterprise GenAI and agentic tooling, including model and data access scoping, tool and permission allow-listing, human-in-the-loop approval on consequential actions, and audit coverage of agent and tool activity.
  • Identify opportunities to automate routine security engineering operations using scripting and AI-assisted tooling, and help build the automation and skillsets that let the broader team adopt them.

Required Qualifications

  • 5 to 7 years of experience in information security engineering, security architecture, or related technical roles.
  • Hands-on engineering experience designing and implementing Zero Trust architecture (network segmentation, conditional access, ZTNA, secure remote access).
  • Hands-on experience with data security engineering, including DLP and DSPM platforms, data classification, and encryption/key management.
  • Strong IAM engineering experience (SSO, MFA, lifecycle automation) and direct experience implementing and administering Privileged Access Management (PAM) solutions.
  • Network security engineering experience, including segmentation, firewall/proxy policy, and secure connectivity.
  • Familiarity with cloud concepts and shared responsibility (AWS, Azure, and/or GCP) and how security guardrails are implemented in cloud environments.
  • Ability to both design security architecture and personally engineer and implement the resulting controls.
  • Strong documentation and communication skills (comfortable writing standards and presenting to stakeholders).
  • Understanding of common security frameworks and control concepts (e.g., NIST CSF, NIST 800-53, CIS Controls, OWASP, PCI/DSS).
  • Experience using AI-assisted engineering tools, such as GenAI copilots, agentic workflows, and scripting automation, to accelerate day-to-day security engineering work, along with willingness to build these skillsets further on the job.
  • Self-accountability is a must.

Preferred Qualifications

  • Familiarity with SABSA or other enterprise security architecture methodologies.
  • Direct experience with PAM platforms (e.g., CyberArk, Delinea, BeyondTrust).
  • Direct experience with DLP/DSPM platforms (e.g., Microsoft Purview, Zscaler DLP/DSPM, Varonis, Securiti).
  • Direct experience with Zero Trust/ZTNA platforms (e.g., Zscaler, Palo Alto Prisma Access, Netskope).
  • Exposure to enterprise architecture concepts (capability models, target-state roadmaps, architecture review boards).
  • Familiarity with GRC processes (risk exceptions, control mapping, audit support), without being purely a compliance role.
  • Experience with security architecture modeling or diagramming (e.g., C4, ArchiMate, Visio/Lucidchart).
  • Experience designing or implementing AI security controls, such as GenAI/agent guardrails, prompt injection mitigation, and model or data access scoping, for enterprise environments.
  • Experience using AI-assisted automation, such as GenAI copilots or LLM-based scripting assistants, to improve security engineering throughput (policy tuning, investigation, reporting, or documentation).
  • Scripting or automation experience (PowerShell, Python) for security engineering and reporting tasks.
  • Certifications (nice to have, not required): CISSP, CCSP, Security+, SABSA Foundation, Delinea certification, AZ-500, AWS Security Specialty.

Work Location

Ability to work in the Plano, Texas office.  Onsite Monday through Friday.

Employment Eligibility

To be eligible for this opportunity, you must be authorized to work in the U.S. Upbound Group does not offer employment-based immigration sponsorship for this role, including OPT or CPT.