Senior Cybersecurity Engineer
Posted 6hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Cybersecurity Engineer managing endpoint, SIEM, vulnerability, and cloud security for clients. Securing AI systems through authorization, monitoring, and adversarial testing.
Responsibilities:
- Administer, configure, and tune core security platforms across multiple client tenants
- Own configuration baselines, policy alignment, and platform health
- Build and refine detection logic, reduce false positives, and create operational response playbooks
- Onboard and troubleshoot SIEM log sources
- Diagnose and repair broken ingestion and API integrations between security, monitoring, and ticketing platforms
- Triage alerts and events
- Serve as technical lead during live incidents alongside clients, internal teams, and third-party incident response firms
- Run vulnerability scanning and reporting
- Prioritize vulnerabilities by real exploitability and drive remediation to closure with engineering teams
- Define and enforce controls around AI systems with access to internal and client environments, including tool authorization, activity monitoring, and adversarial testing
- Automate recurring security operations work using scripting and platform APIs
- Own the technical relationship with security and managed detection vendors
- Evaluate whether vendor services match purchased requirements
- Write formal root cause analyses
- Execute changes through structured change management
- Maintain documentation of baselines, incidents, and tuning decisions for client audits
- Tailor configurations to each client environment
- Provide stakeholders with status reporting, executive-level summaries, and practical best-practice guidance
- Mentor junior engineers
- Collaborate with infrastructure, network, and service delivery teams
Requirements:
- Hands-on ownership of enterprise endpoint detection and response and of a SIEM and vulnerability management platform
- Experience with CrowdStrike Falcon and Rapid7 InsightIDR and InsightVM, or comparable platforms such as Microsoft Sentinel, Splunk, Cortex, SentinelOne, or Tenable
- Hands-on experience securing and administering Microsoft identity and endpoint services: Entra ID, Conditional Access, Intune, and Microsoft Defender
- Cloud security experience in at least one major provider: Azure, AWS, or GCP, covering identity, workload, and posture management
- Automation ability using AI tooling, scripting (Python, PowerShell, or an equivalent), and direct work against vendor APIs
- Experience writing formal root cause analyses and working inside a structured change management process
- Strong analytical and troubleshooting instincts
- Clear client-facing communication
- Ability to work independently across many client environments at once
- Security or vendor certifications such as Security+, GCIH, or CISSP, or certifications from Palo Alto Networks, CrowdStrike, Rapid7, or Microsoft are preferred
- Working knowledge of a major control framework such as NIST CSF or 800-53, CIS Controls, ISO 27001, SOC 2, PCI DSS, HIPAA, or CMMC is preferred
- Experience with data loss prevention, privileged access management, or zero trust network access is preferred
- 5+ years in security engineering or security operations
- Prior MSP/MSSP or other multi-client security experience is strongly preferred
- Bachelor’s degree in information technology, cybersecurity, or a related field, or equivalent hands-on experience
- Role is remote within the United States
Benefits:
- Medical Insurance
- Dental Insurance
- Vision Insurance
- 401(k) retirement plan with company match (annual dollar cap applied)
- Flexible time off plan
- 15 paid holidays
- Sick leave (amount varies by state requirements and is at least the minimum required by any state)
- Short-term and long-term disability
- Life insurance
- Paid parental leave
- Reasonable accommodations throughout the hiring process



















