Senior Cybersecurity Engineer

Rogue Fitness

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Hands-on experience with web application firewalls, such as Cloudflare.
  • Strong grasp of core web security principles, including HTTP/HTTPS and OWASP risks.
  • Experience with security controls in public cloud environments like GCP and Azure.
  • Proficiency in EDR/XDR tools and SIEM/SOAR for investigations.
  • Knowledge of vulnerability management, penetration testing, and incident response.
  • Familiarity with Linux and Windows system administration and networking.
  • Experience with compliance frameworks like PCI DSS and GDPR.

Responsibilities

  • Administer and enhance WAF systems, managing rules and investigating blocked requests.
  • Implement security controls across various cloud platforms, remediating misconfigurations.
  • Support application security and DevSecOps practices throughout the software lifecycle.
  • Manage EDR solutions and operate SIEM tools, developing alerts and response automation.
  • Lead incident investigations and maintain incident response playbooks.
  • Conduct automated penetration testing and validate findings against security infrastructure.
  • Administer Zscaler and manage firewall and remote access configurations.

Benefits

  • Full-time onsite position in Columbus, Ohio without remote work options.
  • Opportunity to work hands-on and implement security solutions directly.
  • Engagement with a variety of security technologies and incident response activities.
  • Collaboration with cross-functional teams, enhancing communication skills.
  • Support for continuous improvement and self-initiative in the role.
Full Job Description
Job Description:

We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position - you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership.

The Senior Cybersecurity Engineer is a fully onsite role in Columbus, Ohio. Remote work is not available. Applicants must be authorized to work in the United States for any employer.

Responsibilities
  • Administer and improve WAF platforms - managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives
  • Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions
  • Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications
  • Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation
  • Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future
  • Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure
  • Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix
  • Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4
  • Administer and secure Google Workspace identity - MFA, access controls, account lifecycle, least privilege - and investigate suspicious sign-ins and identity-related alerts


Qualifications
  • Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform)
  • Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS
  • Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging
  • Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations
  • Experience with vulnerability management, penetration testing, threat hunting, and incident response
  • Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure
  • Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks
  • Strong communicator who can work independently and partner effectively with technical and business stakeholders


Preferred Experience
  • Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware
  • Python or other scripting experience for security automation, detections, and SIEM workflow development
  • Background in ethical hacking, application security, digital forensics, or OSINT
  • Familiarity with DevSecOps, IaC, containers, and cloud-native services
  • Awareness of AI security risks and secure use of generative AI
  • Security or cloud certifications are a plus but not required


Similar Jobs

More Jobs at Rogue Fitness

More Information Technology Jobs

Find similar Senior Cybersecurity Engineer jobs: