
Senior Cybersecurity Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Manage, configure, and optimize core security platforms across various client environments.
• Take ownership of configuration baselines, policy alignment, and overall platform health.
• Develop and enhance detection logic, minimize false positives, and create operational response playbooks.
• Onboard and resolve issues with SIEM log sources.
• Identify and fix issues with ingestion and API integrations among security, monitoring, and ticketing platforms.
• Assess alerts and events.
• Act as the technical lead during live incidents in collaboration with clients, internal teams, and third-party incident response companies.
• Conduct vulnerability scanning and generate reports.
• Prioritize vulnerabilities based on actual exploitability and drive remediation efforts to completion with engineering teams.
• Establish and enforce controls around AI systems that have access to internal and client environments, which includes tool authorization, activity monitoring, and adversarial testing.
• Streamline recurring security operations tasks through automation using scripting and platform APIs.
• Manage the technical relationship with security and managed detection service vendors.
• Assess whether vendor services align with purchased requirements.
• Compose formal root cause analyses.
• Implement changes through a structured change management process.
• Keep documentation of baselines, incidents, and tuning decisions for client audits.
• Customize configurations to fit each client environment.
• Provide stakeholders with status updates, executive summaries, and practical best-practice advice.
• Mentor junior engineers.
• Collaborate with infrastructure, network, and service delivery teams.
• Direct experience managing enterprise endpoint detection and response, as well as a SIEM and vulnerability management platform.
• Proficiency with CrowdStrike Falcon and Rapid7 InsightIDR and InsightVM, or similar platforms like Microsoft Sentinel, Splunk, Cortex, SentinelOne, or Tenable.
• Hands-on experience with the security and administration of Microsoft identity and endpoint services: Entra ID, Conditional Access, Intune, and Microsoft Defender.
• Cloud security experience with at least one major provider: Azure, AWS, or GCP, covering identity, workload, and posture management.
• Capability in automation using AI tools, scripting (Python, PowerShell, or a similar language), and direct interaction with vendor APIs.
• Experience in writing formal root cause analyses and participating in a structured change management process.
• Strong analytical skills and troubleshooting abilities.
• Excellent communication skills for client interactions.
• Ability to work independently across multiple client environments simultaneously.
• Security or vendor certifications such as Security+, GCIH, or CISSP, or certifications from Palo Alto Networks, CrowdStrike, Rapid7, or Microsoft are preferred.
• Familiarity with a major control framework such as NIST CSF or 800-53, CIS Controls, ISO 27001, SOC 2, PCI DSS, HIPAA, or CMMC is preferred.
• Experience with data loss prevention, privileged access management, or zero trust network access is preferred.
• 5+ years of experience in security engineering or security operations.
• Previous experience in MSP/MSSP or other multi-client security roles is strongly preferred.
• Bachelor’s degree in information technology, cybersecurity, or a related field, or equivalent hands-on experience.
• This role is remote within the United States.
• Medical Insurance
• Dental Insurance
• Vision Insurance
• 401(k) retirement plan with company match (annual dollar cap applied)
• Flexible time off plan
• 15 paid holidays
• Sick leave (amount varies by state requirements and is at least the minimum required by any state)
• Short-term and long-term disability
• Life insurance
• Paid parental leave
• Reasonable accommodations throughout the hiring process
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.