CSX Corporation

Security Engineer II - Security Operations Center (SOC)

CSX Corporation$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Engineering, or related field.
  • 3+ years of cybersecurity experience.
  • 2 years in a SOC, incident response, or security engineering role.
  • Experience investigating security incidents in enterprise environments.
  • Familiarity with Microsoft security technologies and cloud security solutions.

Responsibilities

  • Monitor alerts and events from various security platforms.
  • Investigate and respond to cybersecurity incidents.
  • Analyze security events across multiple domains.
  • Perform incident management tasks including triage and recovery.
  • Participate in major incident responses and crisis management activities.
  • Conduct proactive threat hunting and research emerging threats.
  • Develop detection use cases aligned with industry frameworks.

Benefits

  • Comprehensive health plans and wellness programs.
  • Customizable coverage options for individual needs.
  • Opportunities for career growth and development.
  • Annual bonus opportunity based on performance.
  • Commitment to operating safely and prioritizing employee value.
Full Job Description
Job Description

Job Summary

The Security Engineer II - Security Operations Center (SOC) is responsible for monitoring, detecting, analyzing, investigating, and responding to cybersecurity threats impacting CSX systems, networks, applications, and data. This role serves as a technical contributor within the Security Operations Center and collaborates with infrastructure, engineering, application, and business teams to protect critical railroad operations and corporate assets.

The Security Engineer II leverages advanced security technologies, threat intelligence, automation, and incident response methodologies to identify and mitigate security risks while supporting continuous improvement of CSX's cybersecurity posture.

Primary Responsibilities

Security Monitoring and Incident Response
  • Monitor security alerts and events generated by SIEM, EDR, email security, cloud security, and network security platforms.
  • Investigate and respond to cybersecurity incidents including malware, phishing, ransomware, unauthorized access, data loss, insider threats, and advanced persistent threats.
  • Conduct analysis of endpoint, network, cloud, identity, and application security events.
  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.
  • Participate in major incident response activities and cyber crisis management efforts.


Threat Detection and Threat Hunting

  • Conduct proactive threat hunting activities across enterprise environments.
  • Research emerging threats, adversary tactics, and attack techniques using threat intelligence sources.
  • Develop and tune detection use cases aligned with the MITRE ATT&CK framework.
  • Analyze indicators of compromise and indicators of attack.
  • Recommend improvements to detection capabilities and monitoring coverage.


Security Engineering and Operations

  • Administer and support security technologies, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Entra ID, Azure security services, email security platforms, vulnerability management solutions, and network security monitoring tools.
  • Develop and maintain security monitoring rules, analytics, dashboards, and alerting mechanisms.
  • Support the implementation, integration, testing, and operationalization of new security technologies.


Automation and Process Improvement

  • Develop and maintain security automation workflows and incident response playbooks.
  • Leverage Power Automate, Logic Apps, SOAR technologies, scripting, and AI-enabled solutions to improve operational efficiency.
  • Identify opportunities to reduce manual effort, improve alert quality, and shorten response times.
  • Contribute to SOC process optimization and continuous improvement initiatives.


Compliance and Reporting

  • Support cybersecurity compliance activities related to SOX, applicable FRA and CISA requirements, internal policies, and security standards.
  • Create accurate technical reports, executive summaries, metrics, and incident documentation.
  • Maintain evidence and records required for audits, investigations, and regulatory reporting.


Collaboration and Knowledge Sharing

  • Partner with infrastructure, cloud, network, identity, application, legal, and business teams to resolve security findings and incidents.
  • Participate in cybersecurity tabletop exercises, simulations, and readiness activities.
  • Provide mentoring and technical guidance to junior analysts and engineers.
  • Contribute to SOC procedures, runbooks, knowledge articles, and response documentation.


Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 3 or more years of cybersecurity experience.
  • 2 years of experience in a Security Operations Center, incident response, security engineering, or a related security role.
  • Experience investigating security incidents across enterprise environments.
  • Experience with Microsoft security technologies and cloud security solutions


Equivalent Minimum Qualifications
  • High School Diploma/GED
  • 8 or more years of cybersecurity experience, a Security Operations Center, incident response, security engineering, or a related security role.


Preferred Qualifications

5 or more years of cybersecurity experience.

One or more of the following certifications is preferred:
  • CISSP
  • GIAC certifications such as GCIH, GCIA, or GCFA
  • Microsoft security certifications, including SC-200 or SC-100
  • CompTIA Security+ or CySA+
  • Experience in the following is preferred:
    • Railroad, transportation, critical infrastructure, or industrial environments.
    • MITRE ATT&CK-based detection engineering and threat hunting programs.
    • Security orchestration, automation, and response platforms.
    • Vulnerability management and cloud security operations.


Knowledge and Skills
  • Security Information and Event Management platforms and security analytics.
  • Endpoint Detection and Response technologies.
  • Microsoft Sentinel, Microsoft Defender XDR, Azure, and Microsoft Entra ID security.
  • Threat hunting, threat intelligence analysis, and incident response.
  • Working knowledge of Windows and Linux operating systems.
  • Networking concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, and firewalls.
  • Security automation and scripting; PowerShell, Python, and KQL are preferred.
  • Digital forensics and evidence-handling fundamentals.
  • Ability to work independently or collaboratively
  • Technical agility and strong analytical skills


Job Requirements

This position may participate in an on-call rotation and provide support during cybersecurity incidents impacting CSX operations, systems, or critical business functions.

This role offers an annual salary range based on experience and qualifications. In addition to base salary we provide an annual bonus opportunity.

At CSX, we prioritize valuing and developing employees, as well as operating safely. We are committed to offering our team members competitive compensation, a comprehensive benefits package, and unlimited growth opportunities. Our benefits support financial, physical, emotional, and social well-being, with health plans, wellness programs, and customizable coverage options. Learn more about our benefits here.

About CSX Corporation

CSX is a transportation company focused on rail transportation and real estate and among other industries. The company’s rail and intermodal businesses provide rail-based transportation services including traditional rail service and the transport of intermodal containers and trailers. CSX serves major markets in the eastern United States and has access to over 70 ocean, river and lake port terminals along the Atlantic and Gulf Coasts, the Mississippi River, the Great Lakes and the St. Lawrence Seaway. The company also has access to Pacific ports through alliances with western railroads. CSX moves a broad portfolio of products across the country in a way that minimizes the effect on the environment, takes traffic off an already congested highway system, and minimizes fuel consumption and transportation costs.

CSX Corporation Careers

Join the dynamic team at CSX Corporation, a leading force in the transportation sector, where innovation, leadership, and diversity are at the heart of our operations. As one of the most prominent names in the industry, CSX Corporation offers unparalleled job opportunities that promise not only professional growth but also a commitment to sustainability and community development.

Work You’ll Do

At CSX Corporation, every position contributes to the seamless movement of goods across the country, supporting economic growth and stability. Our team members are empowered to lead, innovate, and operate at the intersection of technology and practicality, making our operations smarter and more efficient.

Explore a World of Opportunities

Whether you're looking for your first job or seeking to advance your career, CSX Corporation provides a platform where your skills and dedication shape the future of transportation. With a variety of positions available, from operational roles to corporate functions, your perfect job awaits.

Internship Programs

Kickstart your career with CSX Corporation’s internship programs. These opportunities allow you to apply your academic knowledge in real-world scenarios, enhancing your resume and providing a cornerstone for future employment. Interns at CSX gain invaluable experience, working alongside seasoned professionals and participating in projects that directly affect company operations.

Professional Growth and Development

CSX Corporation is deeply invested in the professional development of its employees. With comprehensive leadership and diversity training programs, we prepare our team to meet challenges head-on and lead with confidence. Our commitment to career advancement is evident in our robust training offerings that equip our team with the tools they need for success.

Benefits and Culture

Choosing a career at CSX Corporation means more than just employment. It means becoming part of a culture that values each individual’s contribution and well-being. Our benefits package is designed to support our team members in every aspect of their lives, whether that's health care, financial planning, or continuing education. At CSX, we believe in nurturing a workplace environment where diversity is celebrated, and every team member is respected.

Join Our Team

Ready to make a significant impact? Explore the job opportunities at CSX Corporation by visiting our Careers page. Search for open positions that match your skills and interests, and prepare to bring your curiosity, creativity, and enthusiasm. We are continuously hiring new talent who are ready to contribute to our legacy of innovation and excellence.

Stay Connected

Keep up to date with the latest at CSX Corporation by following our Careers Blog. Gain insider perspectives, industry-leading insights, and career tips that you can put to use today. Personalize your experience by subscribing to receive job alerts, news, and updates tailored to your preferences.

Networking and Community

At CSX Corporation, networking doesn’t just enhance your career—it strengthens the entire company. Engage with professionals across various departments, gaining insights and building relationships that last a lifetime. Our community of driven, solution-oriented team players is the perfect place to grow your career. Embark on your journey with CSX Corporation today and be part of a team that’s redefining the future of transportation. Your path to a rewarding career starts here.
Learn more about CSX Corporation
Size
21,000 employees
Market Cap
$65 billion
Industry
Net Income
$2.7 billion
Founded
1827
5 Year Trend
+2.5%
Revenue
$10.5 billion
NASDAQ

Similar Jobs

More Jobs at CSX Corporation

More Information Technology Jobs

Find similar Security Engineer II - Security Operations Center (SOC) jobs: