Cyber Defense Detection and Automation Engineer

Crane NXT, Co.

Northern (KY)

Hybrid

USD 100,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Crane NXT is seeking an experienced Cyber Defense Detection & Automation Engineer to join the Global Information Security Team. The role is hands-on within the SOC, focusing on enhancing SIEM/EDR detections and expanding SOAR-driven automation across a global security operations program.

You will collaborate with SOC analysts to reduce noise, improve alert quality, and drive the maturity of threat hunting. The position covers onboarding, testing, and incident response activities in a fast-paced

Qualifications

  • 5+ years of experience in a security operations environment performing investigations and supporting incident response.
  • 3+ years of technical experience developing automation, orchestration, or response solutions (e.g., SOAR, scripting, integrations).
  • 3+ years of hands-on experience with SIEM platforms, including query languages and log onboarding/integration.
  • Experience applying detection/content engineering best practices, including lifecycle management, testing, and tuning.

Responsibilities

  • Develop and maintain SOAR automated playbooks for triage, enrichment, and response.
  • Manage SOAR integration of security tools and data sources using APIs and orchestration workflows.
  • Support ongoing SOAR platform health, reliability, and operational support.
  • Design, develop, and maintain SIEM detection content, including correlation rules, alert logic, and enrichment strategies.
  • Continuously tune and optimize detections based on SOC feedback, incident learnings, and threat intelligence to improve signal quality and reduce false positives.
  • Document detection logic, playbooks, processes, and improvements to ensure consistency, auditability, and scalability.
  • Coordinate and execute the SOC threat hunting program, including defining hypotheses, guiding hunts, and operationalizing validated findings into detections.
  • Collaborate daily with SOC analysts to refine detections, improve triage workflows, and address gaps in visibility or response.
  • Support onboarding of log sources and monitoring capabilities for newly acquired entities, including validating data quality and detection coverage.
  • Assist in planning and execution of annual penetration testing, including detection validation and tracking remediation of identified gaps.
  • Contribute to incident response activities by providing detection expertise, building rapid-use queries/playbooks, and supporting investigations.
  • Engage with business stakeholders to coordinate SOC initiatives, communicate risks and progress, and manage escalations through to resolution.
  • Participate in a scheduled on-call rotation, including weekend coverage, to support timely response to security incidents, escalations, and critical operational needs.

Skills

SOAR automation
Python
PowerShell
Automation scripting
SIEM
Threat hunting

Tools

SIEM platforms
APIs
EDR
SOAR platforms

Job description

Crane NXT is looking for experienced professionals to join the Crane NXT Global Information Security Team! We have an exciting opportunity on our Cyber Defense team. You are an experienced security analyst / incident responder who wants to take the next step in their career as part of a Global cybersecurity team. You are passionate about threat hunting, have a clear vision about next-gen SOCs and SOAR, and enjoy digging deep to find the bad guys as part of a growing global team.

Crane NXT’s Global Information Security team utilizes world-class tools and processes, and this role will provide opportunities to work in an important function joining our global security operations and incident response program. The ideal candidate will have solid proficiency in security incident and event management solutions, using modern IR approaches and tools, and experience with implementing and honing a myriad of detective and preventive controls in an enterprise setting. You must have a desire to collaborate with others while furthering your own development, contributing to continuous improvement initiatives, and have a genuine passion for infosec! Previous security operations center or incident response experience, SOAR automation and detection engineering expertise, and endless curiosity required.

Core Function

The Cyber Defense Detection & Automation Engineer (SOC) is a hands-on technical role within the SOC, reporting to the Director of Security Operations and Incident Response. This position is responsible for engineering and improving detection capabilities across the SIEM & EDR, managing and enhancing SOAR-driven automation, and advancing the maturity of the SOC threat hunting program.

The role works closely with SOC analysts to continuously improve alert quality, reduce noise, and strengthen the organization’s ability to detect and respond to threats. In addition to core SOC engineering functions, this position supports acquisition integrations through SIEM onboarding, contributes to penetration testing activities, and plays an active role in incident response. The engineer also partners with business stakeholders to coordinate SOC initiatives and ensure effective communication and follow-through on escalations and improvements.

Responsibilities and Duties
  • Develop and maintain SOAR automated playbooks for triage, enrichment, and response
  • Manage SOAR integration of security tools and data sources using APIs and orchestration workflows
  • Support ongoing SOAR platform health, reliability, and operational support
  • Design, develop, and maintain SIEM detection content, including correlation rules, alert logic, and enrichment strategies
  • Continuously tune and optimize detections based on SOC feedback, incident learnings, and threat intelligence to improve signal quality and reduce false positives
  • Document detection logic, playbooks, processes, and improvements to ensure consistency, auditability, and scalability
  • Coordinate and execute the SOC threat hunting program, including defining hypotheses, guiding hunts, and operationalizing validated findings into detections
  • Collaborate daily with SOC analysts to refine detections, improve triage workflows, and address gaps in visibility or response
  • Support onboarding of log sources and monitoring capabilities for newly acquired entities, including validating data quality and detection coverage
  • Assist in planning and execution of annual penetration testing, including detection validation and tracking remediation of identified gaps
  • Contribute to incident response activities by providing detection expertise, building rapid-use queries/playbooks, and supporting investigations
  • Engage with business stakeholders to coordinate SOC initiatives, communicate risks and progress, and manage escalations through to resolution
  • Participate in a scheduled on-call rotation, including weekend coverage, to support timely response to security incidents, escalations, and critical operational needs
Qualifications and Competencies
Experience
  • 5+ years of experience in a security operations environment performing investigations and supporting incident response
  • 3+ years of technical experience developing automation, orchestration, or response solutions (e.g., SOAR, scripting, integrations)
  • 3+ years of hands-on experience with SIEM platforms, including query languages and log onboarding/integration
  • Experience applying detection/content engineering best practices, including lifecycle management, testing, and tuning
Technical Skills
  • Strong understanding of detection engineering concepts and security telemetry (endpoint, identity, network, cloud, email, etc.)
  • Experience building and maintaining automated workflows and integrations using APIs or scripting
  • Strong proficiency with Python for automation, data parsing, enrichment, and security workflow development
  • Strong proficiency with PowerShell for scripting, systems interaction, automation, and investigative support across enterprise environments
  • Ability to analyze and troubleshoot data ingestion, parsing, and alerting issues across security tools
  • Familiarity with threat hunting methodologies and incident response processes
Communication & Collaboration
  • Ability to clearly communicate complex technical concepts to both technical teams and business stakeholders
  • Experience working cross-functionally with SOC analysts, IT teams, and business units
  • Strong organizational skills with the ability to manage multiple initiatives and drive outcomes
Attributes
  • Analytical mindset with a focus on improving detection quality and operational efficiency
  • Self-driven with a strong sense of ownership and accountability
  • Comfortable operating in a fast-paced, evolving SOC environment
  • Willingness and ability to support weekend on-call responsibilities as part of a team rotation

#LI-Remote #LI-CM1

Crane NXT is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, or national origin or any other characteristic protected under applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Detection and Automation Engineer
Cyber Defense Detection and Automation Engineer

Crane NXT • United States

On-site
USD 120,000 - 150,000
Cyber Defense Detection & SOAR Engineer (Remote)
Cyber Defense Detection & SOAR Engineer (Remote)

Crane NXT, Co. • Northern (KY)

Hybrid
USD 100,000 - 180,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
Cyber Defense: SOAR & Detection Automation Engineer
Cyber Defense: SOAR & Detection Automation Engineer

Crane NXT • United States

On-site
USD 120,000 - 150,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
SOC Engineer
SOC Engineer

Tenex • Sarasota (FL), Scottsdale (AZ), Kansas City (MO)

On-site
USD 90,000 - 140,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Senior Cyber Security Architect
Senior Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000