Cybersecurity Engineer II
upbound · Plano, TX · United States · On-site
Posted Sep 8, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Description:
Cybersecurity Engineer II
Who We Are
At Upbound Group, we are committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’s customer-facing operating units include industry-leading brands such as Rent-A-Center, Acima and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company-branded retail units across the United States, Mexico, New York and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas.
Role Summary
We are seeking a hands-on Cybersecurity Engineer II to join our Security team. This role is responsible for the day-to-day engineering, administration, and support of core security platforms that protect our infrastructure, data, and users, including our privileged access management (PAM) platform and our Zscaler environment. The Cybersecurity Engineer will also drive Data Loss Prevention (DLP) initiatives, assist in IAM operations and support, help resolve security support tickets, and contribute to network security engineering activities across our hybrid environment.
This is an operationally focused engineering role, ideal for a security professional who enjoys owning platforms end to end: deploying, tuning, supporting, and continuously improving the controls that the business relies on every day. As part of an AI-native engineering organization, the Cybersecurity Engineer will be expected to embrace AI-driven ways of working, using GenAI tools, AI assistants, and agentic workflows to accelerate policy tuning, ticket resolution, investigation, and documentation, and to help identify opportunities to automate routine security engineering operations.
Key Responsibilities
Privileged Access Management (PAM)
Assist in managing the enterprise PAM platform (Delinea Secret Server), including secret and vault management, folder and permission structures, discovery rules, and platform upgrades and health monitoring.
Onboard privileged accounts across servers, databases, network devices, applications, and cloud services; enforce credential rotation, check-in/check-out workflows, and session recording and auditing.
Drive reduction of standing privilege through just-in-time elevation, least-privilege access policies, and periodic privileged access reviews in partnership with IAM and infrastructure teams.
Support integration of PAM with Active Directory, SIEM, and service account and secrets management workflows for both human and non-human identities.
Zscaler Deployment, Management, and Support
Deploy, manage, and support the Zscaler platform, including Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Client Connector across the enterprise.
Author and tune policies for URL filtering, SSL inspection, cloud app control (CASB), bandwidth control, and…