Cybersecurity Engineer
The job description
Tech stack. Splunk or Microsoft Sentinel SIEM, CrowdStrike or Microsoft Defender EDR, Palo Alto or Fortinet firewalls, Tenable or Qualys vulnerability scanning, Python, Bash, MITRE ATT&CK framework, phishing simulation platforms, ticketing and SOAR basics
About the role
You will join the security operations team of a software company that serves millions of users across web and mobile platforms, where you are the front line turning alerts into action every single day. The team defends cloud workloads, corporate infrastructure, and customer data around the clock, partnering closely with IT and engineering on every investigation from triage to closure. You will own alerts end to end, tune the detections that generate them, and build the runbooks that make response repeatable. This role matters because every detection you sharpen and every incident you contain directly reduces the blast radius of real attacks, and your work sets the tone for how seriously the entire company takes defense.
What you will achieve
- Cut mean time to respond to critical alerts from hours to under 30 minutes by tuning noisy detections, tightening response runbooks, and automating the most common enrichment steps analysts repeat daily.
- Harden 95 percent of endpoints to the company security baseline within your first two quarters, closing the gaps surfaced in audits and driving every approved exception to a documented closure date.
- Ship detection rules that catch genuine attacker behavior across endpoint and cloud telemetry while holding the false positive rate under 5 percent, measured against labeled validation data.
- Run quarterly phishing simulations and drive employee click rates below 3 percent through targeted coaching follow-ups, with extra attention for departments that repeatedly click.
- Deliver monthly vulnerability reports with clear ownership and deadlines that push critical patch SLAs to 90 percent on-time remediation across servers, workstations, and network gear.
What you will bring
Must-haves
- 2 to 5 years in a SOC, security engineering, or IT operations role with hands-on alert triage experience in live production environments.
- Working knowledge of SIEM query languages such as SPL or KQL, plus confident day-to-day EDR console work during active investigations.
- Solid grasp of TCP/IP, DNS, HTTP, and common attack techniques mapped to the MITRE ATT&CK framework.
- Scripting ability in Python or Bash to automate repetitive analysis, data enrichment, and recurring reporting tasks.
- Experience managing firewall rules, VPN configurations, and endpoint security policies at organizational scale.
- Clear written communication; you can explain an incident timeline to a non-technical stakeholder without jargon or hand-waving.
- Reliability under pressure: you stay organized and decisive when several serious alerts fire at once.
Nice-to-haves
- Security+, CySA+, or a similar foundational certification showing structured security knowledge.
- Familiarity with AWS or Azure security fundamentals, including IAM concepts and logging services.
- Experience with SOAR playbooks or ticketing automation that measurably reduced manual analyst toil.
- Exposure to threat intelligence feeds and indicator lifecycle management.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta