Senior Cybersecurity Engineer

The Redesign Group

$120K — $160K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security engineering or security operations with hands-on platform ownership.
  • In-depth experience with endpoint detection, SIEM, and vulnerability management platforms.
  • Experience with cloud security across a major provider (Azure, AWS, or GCP).
  • Proficient in automation using scripting languages like Python or PowerShell.
  • Clear and analytical problem-solver with client-facing communication skills.

Responsibilities

  • Administer and tune security platforms across multiple clients, ensuring operational health.
  • Build and refine detection logic, creating operational playbooks for incident response.
  • Onboard SIEM log sources, troubleshooting ingestion issues and API integration.
  • Serve as a technical lead during live incidents, coordinating with clients and internal teams.
  • Prioritize vulnerability remediation based on real exploitability, driving closure with engineers.
  • Define access controls and monitoring for AI systems in production.
  • Automate recurring security tasks using scripting and APIs.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) retirement plan with company match
  • Flexible time off plan
  • 15 paid holidays
  • Short-term and long-term disability
  • Life insurance
  • Paid parental leave
Full Job Description
Job Description

The Senior Cybersecurity Engineer is a hands-on engineering role in our Managed Security Services team. You will own the configuration, tuning, and operational health of the security platforms protecting our clients: tuning detections, onboarding log sources, driving vulnerability remediation to closure, and acting as technical lead when an incident is live. You will work alongside a team of security staff, supported by a global network operations center that handles first-line monitoring and triage.

Our core platforms are CrowdStrike Falcon, Rapid7 InsightIDR and InsightVM, and the Microsoft security stack, and experience with Palo Alto Networks is a plus. You will also help shape how we secure AI and agentic systems: agents with genuine access to production environments, and the authorization, monitoring, and adversarial testing that has to sit around them. We do not expect you to have used every tool across our client base, but we do expect real depth in endpoint detection and response and in SIEM and vulnerability management.

Key Responsibilities

  • Administer, configure, and tune core security platforms across multiple client tenants, owning configuration baselines, policy alignment, and platform health.
  • Build and refine detection logic, reduce false positives, and create the operational playbooks that turn a detection into a repeatable response.
  • Onboard and troubleshoot SIEM log sources, and diagnose and repair broken ingestion and API integrations between security, monitoring, and ticketing platforms.
  • Triage alerts and events, serve as a technical lead during live incidents alongside clients, internal teams, and third-party incident response firms.
  • Run vulnerability scanning and reporting, prioritize by real exploitability rather than raw severity score, and drive remediation to closure with engineering teams.
  • Define and enforce the controls around AI systems that hold real access to internal and client environments, including tool authorization, activity monitoring, and adversarial testing.
  • Automate recurring security operations work using scripting and platform APIs.
  • Own the technical relationship with our security and managed detection vendors, and judge whether what we are getting matches what we bought.
  • Write formal root cause analyses, execute changes through structured change management, and maintain documentation of baselines, incidents, and tuning decisions that client audits rely on.
  • Tailor configurations to each client environment and give stakeholders clear status reporting, executive-level summaries, and practical best-practice guidance.
  • Mentor junior engineers and work with infrastructure, network, and service delivery teams so security fits the wider environment rather than sitting beside it.

Required Skills & Experience

  • Hands-on ownership of enterprise endpoint detection and response and of a SIEM and vulnerability management platform. CrowdStrike Falcon and Rapid7 InsightIDR and InsightVM are what we run most; comparable platforms such as Microsoft Sentinel, Splunk, Cortex, SentinelOne, or Tenable are equally relevant.
  • Hands-on experience securing and administering Microsoft identity and endpoint services: Entra ID, Conditional Access, Intune, and Microsoft Defender.
  • Cloud security experience in at least one major provider (Azure, AWS, or GCP) covering identity, workload, and posture management.
  • Automation ability using AI tooling, scripting (Python, PowerShell, or an equivalent), and direct work against vendor APIs.
  • Experience writing formal root cause analyses and working inside a structured change management process.
  • Strong analytical and troubleshooting instincts, clear client-facing communication, and the ability to work independently across many client environments at once without losing track of any of them.

Preferred Qualifications

  • Security or vendor certifications such as Security+, GCIH, or CISSP, or certifications from Palo Alto Networks, CrowdStrike, Rapid7, or Microsoft.
  • Working knowledge of a major control framework (NIST CSF or 800-53, CIS Controls, ISO 27001, SOC 2, PCI DSS, HIPAA, or CMMC).
  • Experience with data loss prevention, privileged access management, or zero trust network access.

Background

  • 5+ years in security engineering or security operations, in roles where you owned the platforms rather than working from their dashboards.
  • Prior MSP/MSSP or other multi-client security experience strongly preferred, with demonstrated ability to manage competing priorities across multiple client environments.
  • Bachelor's degree in information technology, cybersecurity, or a related field, or equivalent hands-on experience.


Benefits

We offer a comprehensive benefits package which may include:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • 401(k) retirement plan with company match (annual dollar cap applied)
  • Flexible time off plan
  • 15 paid holidays
  • Sick leave (amount varies by state requirements and is at least the minimum required by any state)
  • Short-term and long-term disability
  • Life insurance
  • Paid parental leave


The pay range for this role is:

120,000 - 160,000 USD per year (Remote (United States))

Similar Jobs

More Jobs at The Redesign Group

More Information Technology Jobs

  • Reynolds & Reynolds
    Director of Engineering
    Reynolds & Reynolds
    North Andover, MA 01845 (Essex County)
  • Program Manager
    $225K — $275K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Full Stack Python Developer
    $126K — $128K *
    Edgewater Federal Solutions, Inc.
    Washington, DC 20011 (District Of Columbia County)
  • Service Desk Technical Lead
    $175K — $225K *
    Edgewater Federal Solutions, Inc.
    La Canada Flintridge, CA 91011 (Los Angeles County)
  • Flexsteel Industries
    ServiceNow Architect
    $156K — $195K *
    Flexsteel Industries
    Washington, DC 20011 (District Of Columbia County)

Find similar Senior Cybersecurity Engineer jobs: