Senior Security Engineer
TX, US, 0
As an NRG employee, we encourage you to take charge of your career and development journey. We invite you to explore exciting opportunities across our businesses. You’ll find that our dynamic work environment provides variety and challenge. Your growth is key to our ongoing success—take the lead in shaping your career development, goals and future!
Senior Security Engineer
About the Role
The Security Engineer is a strategic, architecture-focused role responsible for defining, governing, and advancing security across our modern platforms, cloud ecosystems, AI and agent-driven capabilities, integrations, and digital experiences.
This role drives the secure foundations that enable the organization to scale Power Platform, Dynamics 365 F&O, cloud-native solutions, cross-domain MCP capabilities, API ecosystems, and enterprise AI/LLM agents with confidence.
The Security Engineer acts as a critical partner across Architecture, Engineering, Cloud, Cyber Security, and Data & AI to ensure that every platform, agent, automation, and application is designed with the right guardrails, governance, controls, and operational readiness to keep the business safe while accelerating transformation.
Key Responsibilities
Security Architecture & Design
• Define and maintain security architecture standards for Power Platform, Dataverse, Dynamics 365 F&O, Azure, AWS, GCP, custom applications, and enterprise integrations.
• Apply Zero Trust and least-privilege principles to identity, access, API, MCP, connector, and automation patterns.
• Lead threat modeling and secure design reviews for applications, integrations, AI systems, and agent-based orchestration.
• Establish secure patterns for workload isolation, identity propagation, capability routing, and service segmentation.
• Govern APIM zero-trust enforcement across Power Apps, digital applications, orchestrator agents, API consumers, and MCP domain services.
• Define secure patterns for deterministic vs AI-driven capability invocation, ensuring uniform authorization and policy enforcement.
Data Protection & Encryption
• Define standards for encrypting data in transit and at rest across Azure, AWS, GCP, Dataverse, Dynamics 365 F&O, and AI pipelines.
• Drive data classification, PII/PHI protection, masking, tokenization, and synthetic data usage standards.
• Ensure secure handling, auditability, and retention of financial and SOX-relevant data.
• Govern secure data pathways for MCP orchestration and Power Platform integration flows.
AI, Agent & Automation Security
• Lead security risk assessments for LLMs, copilots, MCP domain agents, orchestrators, and AI-driven automation.
• Implement controls that prevent prompt injection, data leakage, unauthorized outputs, and unsafe system actions.
• Define safe tool/action boundaries for agents including permission scoping, output validation, and complete traceability of agent decisions.
• Establish secure RAG retrieval and document governance patterns including sanitization, access filtering, encryption, and contextual authorization.
• Ensure alignment with Responsible AI, AI governance policies, evaluation and red-teaming standards, and behavioral monitoring requirements.
• Govern security for solution-aware orchestration agents within Power Apps, including safe routing to domain MCPs and strict context boundaries.
• Ensure integrity of AI and agent telemetry, including structured risk-event logging, behavior traces, and auditable evaluation histories.
• Implement agent governance controls including agent quarantine, risk-event containment, and unsafe behavior mitigation.
Platform & Application Security
• Define secure design patterns for Dataverse environment separation, role-based access, and field-level protection.
• Oversee security architecture for Dynamics 365 F&O, including role design, segregation of duties, and SOX-aligned access governance.
• Define MCP/API security patterns covering token enforcement, schema validation, throttling, identity propagation, and request boundary controls.
• Establish secure connector patterns for Power Platform including authentication flows, certificate handling, and data boundary enforcement.
• Ensure application security controls align to OWASP Top 10 and modern threat prevention requirements.
Cloud Security Architecture (Azure + AWS + GCP)
• Define cloud security patterns for Azure, AWS and including workload isolation and identity-based access boundaries.
• Establish logging and telemetry requirements for cloud workloads, AI systems, and agent-driven interactions.
• Ensure cloud and platform designs align with Cyber Security, Cloud Architecture, and Data & AI governance frameworks.
• Support secure authentication patterns including Amazon Cognito for digital identity and user access.
Digital & Web Application Security
• Define authentication, authorization, session management, and API protection for digital-facing applications.
• Partner with the team that owns F5 WAF to ensure policies and configurations meet application and threat-prevention requirements.
• Validate secure request handling, input validation, and cross-domain protections across web workloads.
Governance, Compliance & SOX
• Ensure alignment with enterprise cybersecurity standards, cloud governance, Data & AI governance, and SOX ITGC controls.
• Support access certification, segregation of duties, change management evidence, audit documentation, and control testing.
• Participate in architecture reviews, penetration testing, risk assessments, and remediation planning.
• Develop reusable security standards, reference architectures, guardrails, and implementation guidelines.
• Govern secure Dynamics 365 F&O API interaction patterns including identity propagation, token management, and financial transaction protections.
• Ensure consistent enforcement of enterprise AI guardrails and governance controls across copilots, MCP agents, and automation workflows.
Required Skills & Experience
Minimum Requirements
• Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or a related field, or equivalent work experience.
• 8–10+ years of experience in security engineering, application/platform security, or cloud security in a mission-critical enterprise environment.
• Hands-on experience with Azure, AWS and GCP security architecture, including identity, access, workload security, and cloud governance alignment.
• Experience designing and implementing security controls across API ecosystems, application architectures, and integration patterns.
• Demonstrated experience securing AI/LLM systems, agent-based workflows, and automation platforms (including MCP domain agents and orchestrator agents).
• Experience with enterprise authentication and identity platforms, including Amazon Cognito.
• Strong knowledge of encryption standards, data protection, and secure data handling for regulated and SOX-sensitive environments.
• Applied knowledge of cybersecurity frameworks, including Zero Trust, OWASP Top 10, and secure SDLC practices.
• Experience supporting governance and compliance requirements, including SOX ITGC controls, segregation of duties, and audit evidence.
Preferred Experience
• Power Platform and Dataverse security architecture.
• Dynamics 365 F&O security model and SOX-aligned access controls.
• MCP/API security patterns and agent-oriented architecture.
• Familiarity with F5 WAF threat analysis and policy behavior.
• Certifications such as Azure Security Engineer, AWS Security Specialty, CISSP, CCSP, or CISA.
NRG Energy is committed to a drug and alcohol-free workplace. To the extent permitted by law and any applicable collective bargaining agreement, employees are subject to periodic random drug testing, and post-accident and reasonable suspicion drug and alcohol testing. EOE AA M/F/Vet/Disability. Level, Title and/or Salary may be adjusted based on the applicant's experience or skills.
Official description on file with Talent.
We support the use of AI tools to help you prepare for your interview (e.g., practicing responses, researching the role, or refining your resume). However, during interviews and assessments, we expect responses to reflect your own thinking, experience, and communication. Use of AI to generate or read answers in real time, complete assessments, or misrepresent your qualifications is not permitted and may impact your candidacy.