Senior Cyber Security Engineer (M365 specific)

Garmin•Published 2 hours ago•First seen 2 hours ago
Overview We are seeking a full-time Senior Cyber Security Engineer at Garmin's U.S. headquarters in the Greater Kansas City area. In this role, you will be responsible for developing security roadmaps, standards, and control strategies that protect enterprise collaboration, communication, identity, endpoint, and data environments. This position partners across Cyber Security, IT platform teams, and business stakeholders to strengthen protection, detection, and response capabilities in alignment with Garmin’s broader security architecture and risk-management objectives. This is a build-and-operationalize role focused on translating security direction into practical, scalable, and supportable capabilities. The individual develops security standards, guides implementation priorities, and works closely with partner teams responsible for platform administration, identity services, endpoint management, security operations, architecture, and data governance. The role may also support broader endpoint security initiatives as needed, while maintaining a primary focus on M365 and modern-workplace security. Essential Functions Serve as a trusted advisor to other cybersecurity teams and to Garmin business segments on multiple domains in cybersecurity Mentor and develop a team of highly skilled security professionals, promoting knowledge transfer, skill development, and a culture of continuous learning and improvement Proactively evaluate and design improvements to tool integrations and workflows, developing advanced automation and scripts and optimizing the use of security tool APIs Lead planning for project components, provide reliable progress reporting, and ensure cross-team alignment on schedules, risks, and deliverables Design and develop complex, integrated solutions to meet business requirements and enhance the performance of Garmin’s security systems Contribute to the team roadmap and priorities Collaborate with cross-functional teams to identify automation opportunities that increase efficiency and reduce manual processes Participate in the evaluation and adoption of emerging security technologies to improve threat detection, prevention, and response Advise leadership on strategic technology investments to advance cybersecurity engineering capabilities Creates opportunities to share knowledge, skills, and abilities with other team members to further their professional development through training, mentoring, and hands-on assistance as appropriate Drive the roadmap, standards, and control strategy for modern-workplace security, translating security architecture into practical, scalable capabilities. Define secure configuration baselines, control expectations, reporting measures, and delivery priorities that improve program maturity and reduce risk. Design and guide implementation of security capabilities for email, collaboration, productivity, identity, endpoint, and enterprise content platforms. Establish data-protection, access-governance, external-collaboration, and AI-enabled productivity security requirements in partnership with platform, data privacy, and security teams. Partner with identity, endpoint, and platform teams to align access controls, application governance, and device-security expectations with enterprise security standards. Ensure relevant security telemetry, detection use cases, and response processes support monitoring, investigation, incident response, and continuous improvement. Contribute subject-matter expertise to incident response, investigation, containment, and remediation activities involving modern-workplace security threats. Assess security posture over time, prioritize remediation opportunities, evaluate capability enhancements, and define resilience expectations with responsible platform teams. Use automation, repeatable processes, and control validation to improve operational efficiency, consistency, and long-term sustainability of security capabilities. Serve as a trusted advisor across Cyber Security, IT platform teams, Data Privacy, and business stakeholders to coordinate scope, ownership, and execution of the modern-workplace security roadmap. Other Responsibilities Demonstrate broad understanding of Garmin’s business model, including Engineering, Operations, Finance, Sales, and Marketing. Stay informed on advancements in modern-workplace security, identity, information protection, endpoint security, and the evolving AI threat landscape, and advise leadership on strategic investments to advance capabilities. Adhere to SOX, PCI, TISAX, and other regulatory requirements as applicable to Garmin’s business environments. Demonstrate professional maturity through giving and receiving constructive feedback; collaborate effectively and resolve conflict. Facilitate team discussions and meetings and mentor less-experienced engineers on M365 and endpoint security best practices. Perform other duties as necessary Basic Qualifications Bachelor's Degree in Computer Science, Information Technology, Management Information Systems, Business or another relevant field AND a minimum of 5 years of relevant experience Leads clear, concise, and influential communication across teams and stakeholders Fosters collaboration, demonstrating leadership in team dynamics and maintaining a positive, solution-oriented approach Serves as a go-to problem solver for complex or ambiguous challenges, consistently delivering effective solutions and guiding others through problem-solving approaches Effectively prioritizes complex workloads and ensures timely follow-up on commitments Produces comprehensive, high-quality documentation and promotes best practices for organization and clarity Experience leading complex security engineering initiatives and mentoring team members on best practices in security operations and automation Strong understanding of core information technology services such as networking, storage, databases, and web-based services Demonstrated experience designing, implementing, and operationalizing security controls for enterprise collaboration, productivity, identity, endpoint, and data-protection environments. Experience with email, collaboration, and productivity-platform threat protection capabilities in an enterprise environment. Experience with information protection, data loss prevention, retention, compliance, or related data-governance capabilities. Working knowledge of identity-security concepts, including risk-based access, application governance, and lifecycle controls. Strong understanding of modern-workplace threat scenarios and the security telemetry needed to support monitoring, detection, investigation, and response. Experience partnering with security operations teams on detection engineering, incident response, and continuous improvement. Ability to evaluate security capabilities, tooling, and investments against coverage, integration, operational effort, user impact, and cost. Experience using automation or scripting to support security operations, control validation, and process efficiency. Demonstrated strong and effective verbal, written, and interpersonal communication skills; team-oriented with a positive attitude and proven problem-solving ability. Desired Qualifications Cybersecurity certifications such as CISSP, CCSP, or SC-100 (Microsoft Cybersecurity Architect). Microsoft security certifications such as SC-200 (Security Operations Analyst), SC-300 (Identity & Access Administrator), or SC-400 (Information Protection Administrator). Experience securing Microsoft Copilot or comparable enterprise AI deployments. Experience with Defender for Cloud Apps, DSPM for AI, or comparable CASB / data-security tooling. Garmin International is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, veteran's status, age or disability. This position is eligible for Garmin's benefit program. Details can be found here: Garmin Benefits