Principal Information Security Engineer
Florida Crystals Corporation is a fully integrated cane sugar company. Florida Crystals regeneratively farms sugarcane and rice in South Florida, where it owns two sugar mills, a sugar refinery, a packaging and distribution center, Florida's only rice mill, a compost facility, and one of the largest renewable power plants of its kind in the U.S., which uses sugarcane fiber to generate eco-friendly energy that powers its sugar operations. Florida Crystals owns one of the largest Regenerative Organic Certified farms in the U.S. and its Florida Crystals products are the only ROC sugar grown and milled sugar in the country. Florida Crystals owns ASR Group International, Inc., a holding company that conducts operations through its subsidiaries. The ASR Group family of companies make up the world’s largest refiner and marketer of cane sugar. Florida Crystals is headquartered in West Palm Beach, Florida. Learn more at www.FloridaCrystalsCorp.com .
Overview
The Principal IT Security Engineer reports to the Sr. Manager of Information Security and serves as the technical lead for securing the company's enterprise IT environment across data centers, cloud platforms, corporate networks, endpoints, and business applications. The role emphasizes enterprise security engineering, network and identity architecture, and the protection of the systems and data that run the business, with awareness of how corporate IT interfaces with plant and OT environments where those boundaries intersect.
The primary focus is to design, implement, and operate security controls for complex, hybrid, and cloud-first environments, with a strong emphasis on Zero Trust, microsegmentation, secure connectivity, identity, and defense-in-depth. This role partners closely with infrastructure, cloud, application, and operations teams to advance the security architecture and drive execution of the 1-3 year enterprise security and segmentation roadmap.
Detailed Roles & Responsibilities
USA Remote or West Palm Beach, FL
We are an equal opportunity employer. We do not discriminate on the basis of race, color, creed, religion, gender, sexual orientation, gender identity, age, national origin, disability, veteran status or any other category protected under federal, state, or local law. All employment is decided on the basis of qualifications, merit, and business need.
Overview
The Principal IT Security Engineer reports to the Sr. Manager of Information Security and serves as the technical lead for securing the company's enterprise IT environment across data centers, cloud platforms, corporate networks, endpoints, and business applications. The role emphasizes enterprise security engineering, network and identity architecture, and the protection of the systems and data that run the business, with awareness of how corporate IT interfaces with plant and OT environments where those boundaries intersect.
The primary focus is to design, implement, and operate security controls for complex, hybrid, and cloud-first environments, with a strong emphasis on Zero Trust, microsegmentation, secure connectivity, identity, and defense-in-depth. This role partners closely with infrastructure, cloud, application, and operations teams to advance the security architecture and drive execution of the 1-3 year enterprise security and segmentation roadmap.
Detailed Roles & Responsibilities
- Design, implement, and operate enterprise security controls across endpoints, servers, business applications, data, cloud and on-prem infrastructure, mobile, and networking, including firewalls, IDS/IPS, secure remote access, VPN, ZTNA, and network access control.
- Lead the design and rollout of network microsegmentation and zone-based architectures using technologies such as identity-based segmentation, VLANs, next-generation firewalls, and policy-based controls across on-premises and cloud environments.
- Function as a Subject Matter Expert (SME) for security integrations and authentication elements, including firewall and network security, conditional access, VPN, Zero Trust network architecture, SSO federation, MFA, and email security solutions.
- Engineer and maintain secure connectivity between corporate IT and plant networks where those environments interconnect, applying least-privilege and defense-in-depth principles at the IT/OT boundary.
- Collaborate with network, infrastructure, cloud, and application teams to design and review security architectures for new and existing business systems, SaaS platforms, and infrastructure services.
- Implement and administer security tools and platforms across endpoints, servers, network, identity, and cloud environments, including EDR, SIEM/SOC integrations, vulnerability management, and secure remote access solutions.
- Perform security engineering and threat modeling for enterprise systems and integrations, identifying and mitigating risks introduced by new connectivity, vendors, and technologies.
- Develop, test, and maintain incident detection and response playbooks for enterprise security events, supporting the SOC and IT operations teams during investigations and recovery efforts.
- Drive vulnerability management for network, infrastructure, and platform components and coordinate safe remediation activities across production business systems.
- Contribute to and maintain security standards, reference architectures, and configuration baselines for data centers, cloud environments, corporate networks, and identity platforms.
- Create, manage, and update Standard Operating Procedures, and coordinate cross-team communications and activities that improve and sustain operational security functions.
- Provide mentorship and technical guidance to infrastructure, operations, and security team members on security best practices and secure design principles.
- Stay current on threats and trends affecting enterprise IT environments and evaluate new solutions that support segmentation, identity, visibility, and protection objectives.
- Implement, configure, and operate application allowlisting / default-deny Zero Trust endpoint tooling (e.g., ThreatLocker, AppLocker, Airlock, or equivalent), including policy design, ringfencing, exception governance, and integration with EDR and SIEM.
- Eight (8) or more years of hands-on experience as an Information Security Engineer or Network Security Engineer in enterprise environments.
- Significant experience designing and operating enterprise security controls such as firewalls, segmentation, VPN/ZTNA, NAC, EDR, and SIEM platforms at scale.
- Proven experience planning and executing network segmentation or microsegmentation programs, including firewall-based segmentation, SDN, or identity-based segmentation.
- Broad security experience in heterogeneous environments spanning diverse applications, systems, databases, SaaS solutions, and hybrid cloud and on-premises platforms.
- Working familiarity with manufacturing or plant environments and the IT/OT boundary is a plus.
- Demonstrated experience implementing and configuring application allowlisting / default-deny Zero Trust endpoint tooling (e.g., ThreatLocker, AppLocker, Airlock, or equivalent) in enterprise environments.
- Bachelor's degree in Information Systems, Computer Science, Engineering, or a related field, or equivalent experience.
- In lieu of a Bachelor's degree, eight (8) or more years of relevant professional experience will be considered.
- Relevant certifications preferred, including CISSP, CCNP Security, CCSP, or comparable enterprise security and network-focused certifications.
- Strong expertise in network security, routing and switching fundamentals, firewalls, secure remote access, and segmentation or microsegmentation technologies.
- Experience designing and implementing Zero Trust-aligned architectures, including identity-aware access controls and least-privilege network policies.
- Expert understanding of cloud and on-premises security, identity and access management, multi-factor authentication, SSO federation, and related security protocols.
- Strong expertise with cloud security and firewall technologies, and a working understanding of security architecture models and application security.
- Demonstrated knowledge of common adversary tactics, techniques, and procedures (TTPs) and relevant network defense and intelligence frameworks.
- Ability to collect, analyze, and interpret technical data from multiple tools, including firewalls, SIEM platforms, EDR solutions, and vulnerability scanners, and produce clear, actionable recommendations.
- Awareness of how corporate IT environments interface with plant and OT systems, sufficient to design safe connectivity and segmentation at that boundary.
- Ability to create clear, concise documentation for IT leadership, business stakeholders, and technical teams, including architecture and design documents for new and pre-existing solutions.
- Strong communication, collaboration, and leadership skills, with the ability to influence cross-functional teams and drive alignment on critical security decisions and policies.
USA Remote or West Palm Beach, FL
We are an equal opportunity employer. We do not discriminate on the basis of race, color, creed, religion, gender, sexual orientation, gender identity, age, national origin, disability, veteran status or any other category protected under federal, state, or local law. All employment is decided on the basis of qualifications, merit, and business need.
Recommended Jobs
Cyber Security Engineer
Posted 4 minutes ago
Senior Analyst, Information Security
Posted 27 minutes ago
Senior IT Security Analyst / Developer
Posted 28 minutes ago
Senior Security Engineer
Posted 28 minutes ago
Senior Cybersecurity Engineer
Posted 28 minutes ago

