Job Summary
The Cybersecurity Engineer will help strengthen and modernize Security Engineering & Operations capabilities as part of a broader effort to mature the organization's cybersecurity posture. The role will focus on enhancing SIEM, EDR, and SOC capabilities, closing visibility gaps, and evolving security tools, processes, and operational practices. The engineer will support SIEM/SOAR integration, identity and endpoint security engineering, secure configuration baselines, cloud and enterprise security architecture, automation, and security operations enablement. The role requires a hands-on technical mindset, adaptability, strong documentation skills, and the ability to collaborate with IT operations, application teams, infrastructure teams, and SOC personnel.
Key Responsibilities
Design and implement security controls across identity, network, endpoint, and cloud environments.
Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.
Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.
Support enterprise security architecture development, including secure-by-design reviews with application and infrastructure teams.
Develop and tune risk-based detection use cases aligned with security operations priorities and threat exposure.
Engineer identity security controls, including IAM/PAM hardening, role-based access validation, and integration with monitoring solutions.
Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.
Build and maintain logging pipelines to provide visibility across endpoints, servers, network devices, identity platforms, and cloud services.
Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.
Partner with security operations teams to develop and tune detection rules, correlation logic, and enrichment processes.
Participate in incident investigations and root-cause analysis, with a focus on engineering solutions that prevent recurring issues.
Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.
Identify and implement high-impact security automation opportunities, including alert enrichment, ticket creation, and response workflow orchestration.
Evaluate security tool health, tuning opportunities, and integration gaps and provide recommendations for cybersecurity modernization.
Support AI-assisted capabilities designed to improve security operations and analyst effectiveness.
Collaborate with IT operations, infrastructure, endpoint management, and application teams to implement secure configurations and optimize security controls.
Participate in governance meetings and contribute to progress reporting and strategic planning.
Develop technical documentation, operational runbooks, and knowledge transfer materials.
Develop a SIEM/SOAR engineering plan and support integration of core security tools.
Deploy and tune risk-based detection use cases and document logging and visibility improvements across identity, network, endpoint, and cloud environments.
Support the development of incident response runbooks and cross-functional operational documentation.
Conduct baseline assessments of security tools and provide recommendations for future enhancements.
Maintain complete documentation for implemented security controls, configurations, and integrations.
Support technical evaluations, product assessments, procurement activities, and solution documentation as needed.
Required Qualifications
10+ years of experience in security engineering, security operations, or systems engineering with cybersecurity responsibilities.
Hands-on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar technologies.
Hands-on experience with SIEM engineering and detection engineering.
Experience with log onboarding, security monitoring, detection engineering, and security operations enablement.
Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and role-based access design.
Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.
Experience implementing secure configuration baselines using CIS, DISA STIG, or comparable frameworks.
Proficiency in scripting and security automation using PowerShell, Python, or similar languages.
Experience with SOAR platforms and security automation workflows.
Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.
Experience working within regulated environments and security compliance frameworks such as NIST CSF, RMF, CJIS, or similar standards.
Strong documentation, communication, problem-solving, and cross-functional collaboration skills.
Preferred Qualifications
Experience supporting large enterprise or public-sector environments.
Experience with vulnerability management tools and remediation workflow engineering.
Experience supporting hybrid security operations models involving internal teams and external service providers.
Experience with advanced security automation and orchestration architectures.
Experience with emerging AI-assisted security operations capabilities.
Certifications
Preferred certifications include CISSP, GSEC, GCIA, GCED, GCSA, AWS Security Specialty, or Azure Security certifications.