We are seeking an experienced and adaptable
Cybersecurity Engineer to support and mature
Csquare's security program. This role is hands-on and multidisciplinary, requiring close collaboration across engineering, infrastructure, and operations teams. The successful candidate will strengthen detection capabilities, optimize security platforms, and respond to incidents that span hybrid, multi-tenant, and cloud-adjacent environments.
This position offers significant influence over how security is engineered and operated within a colocation model, where uptime, customer trust, regulatory compliance, and operational discipline are paramount. The role is well-suited to an engineer who values depth, ownership, and practical security outcomes.
Key ResponsibilitiesSecurity Engineering & Platform Management- Own the configuration, tuning, and lifecycle management of security platforms supporting corporate IT and data center operations, including SIEM, XDR/EDR, MDR, vulnerability management, and the Microsoft Defender ecosystem.
- Engineer efficient, purposeful security telemetry pipelines focused on actionable signals rather than raw log volume.
- Integrate alerts and telemetry across identity systems, endpoints, network infrastructure, virtualization platforms, and cloud services to enable cohesive visibility.
- Customize and harden security tools to reflect operational realities of colocation environments, including shared infrastructure, management networks, and customer demarcation boundaries.
- Partner with key stakeholders across the company to ensure security controls are customized for our environment.
Detection Engineering- Design, implement, and maintain high-confidence detection logic across corporate and data center environments.
- Treat detections as code-versioned, reviewed, validated, and continuously improved
- Evaluate detection coverage with a focus on threats relevant to the business (e.g., compromised admin access, management plane abuse, insider risk, and lateral movement).
Incident Response- Participate in end-to-end incident response activities, including triage, investigation, containment, remediation, and post-incident analysis.
- Investigate identity compromise, phishing, endpoint alerts, anomalous network activity, and suspicious behavior within management or control environments.
- Perform root-cause analysis and drive durable corrective actions to reduce recurrence and operational risk.
Automation & Process Improvement- Collaborate with infrastructure, network, and operations teams to automate repetitive security and response tasks.
- Improve response workflows to balance security rigor with business needs and evolving threats.
- Reduce alert fatigue and operational noise through improved tuning, enrichment, and prioritization.
Security Posture & Internal Assessments- Support internal security assessments, tabletop exercises, and incident simulations aligned to colocation and data center threat scenarios.
- Assist with validation of controls supporting customer assurance requirements and industry frameworks (e.g., SOC 1/2, ISO 27001).
- Contribute to continuous improvement initiatives related to system hardening, visibility, and detection capabilities.
QualificationsCore Technical Knowledge- Strong understanding of fundamental computing and security concepts, including:
- Networking (TCP/IP, DNS, routing, switching)
- Windows and Linux operating systems
- Identity and privileged access management
- Demonstrated ability to develop meaningful detection logic using query languages, event correlation, and behavioral analysis.
- Experience working with platforms such as SIEM, EDR/XDR, SOAR, Defender, MDR, and network security tooling, with an emphasis on engineering, tuning, and optimization.
Experience- Prior hands-on experience in cybersecurity engineering, security operations, incident response, or threat detection.
- Comfort leading technical investigations involving critical infrastructure or administrative access.
- Experience with scripting and automation (e.g., PowerShell, Python, Bash) and integrating tools via APIs is highly desirable.
Professional Attributes- Operational Mindset: Understands the balance between strong security controls, reliability, and customer service commitments.
- Adaptability: Comfortable operating across corporate IT, data center operations, and evolving threat scenarios.
- Analytical Curiosity: Consistently seeks root cause and systemic improvements rather than surface-level fixes.
- Ownership: Proactively identifies and resolves security gaps, particularly those affecting shared or critical infrastructure.
- Clear Communicator: Communicates security risk and findings clearly to leadership and non-security stakeholders.
- Collaborative: Works effectively with IT, network, facilities, compliance, and external partners without siloed thinking.