
Cyber Defense Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Romania.
• Engage in the Incident Response (IR) function by investigating and responding to security incidents promptly and effectively.
• Streamline IR and defense center operations through the use of playbooks, automation rules, and scripting.
• Refine and create detection rules tailored to organizational requirements to sustain robust detection coverage and a high true-positive rate.
• Collaborate with IT and various stakeholders to guarantee that hardening configurations are properly implemented across laptops and servers.
• Work alongside the Privacy team to notify affected parties in the case of a data breach.
• Maintain ongoing compliance with ISO 27001, SOC 2, DORA, and other pertinent standards and frameworks.
• Assist the security operations team and contribute to the continuous enhancement of the organization's overall security posture.
• Over 3 years of experience in defense engineering or incident response, with practical expertise in configuring detection mechanisms.
• In-depth knowledge of cloud environments and experience with security tools for detection and response (e.g., SIEM/XDR/EDR platforms such as Microsoft Sentinel, Defender, or equivalents). Familiarity with Azure is a plus.
• Comprehensive understanding of attacker methodologies, TTPs, and attack vectors within cloud environments, as well as across Windows, macOS, and Linux operating systems.
• Skilled in scripting and KQL (Kusto Query Language) or comparable query languages.
• Practical knowledge of APIs related to security tools and automation (e.g., Microsoft Graph, Defender, Purview, or equivalents).
• Proficient in English, both written and spoken.
• Flexible work environment.
• A diverse and globally connected team.
• Competitive compensation packages.
• Opportunities for career advancement based on performance.
Mercor
RTX
ICF
HETI
Get handpicked remote jobs straight to your inbox weekly.