Our client is seeking a Cyber Security Engineer to support enterprise security operations, threat detection, and incident response across a complex technology environment. This position will play a hands‑on role in monitoring security events, investigating potential threats, improving detection capabilities, and maintaining the technologies and processes that support the organization’s security operations.
The ideal candidate will bring strong technical security experience, sound judgment, and the ability to collaborate effectively with teams across IT, infrastructure, operations, and business functions.
Key Responsibilities
- Monitor and investigate security events and alerts, identifying potential threats and determining appropriate response actions.
- Participate in incident response activities, including investigation, containment, remediation, escalation, and post-incident analysis.
- Support and improve security monitoring capabilities across enterprise IT and operational technology (OT) environments.
- Maintain and enhance SOC technologies, including SIEM, log management, network security, and related security platforms.
- Develop, tune, and improve detection rules and security monitoring processes to reduce false positives and identify emerging threats.
- Assist with security assessments and risk analysis to identify vulnerabilities and develop appropriate security requirements and controls.
- Maintain detailed incident documentation, including findings, root cause, remediation activities, lessons learned, and recommended improvements.
- Identify opportunities to automate security monitoring, detection, and response activities.
- Develop and maintain security procedures, playbooks, standards, and technical documentation.
- Track and report SOC performance metrics and security operations KPIs.
- Provide technical guidance related to network security and next-generation firewall technologies.
- Continuously evaluate emerging security technologies, threats, and industry practices to improve the organization’s security posture.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field; equivalent professional experience may be considered.
- 3–5+ years of experience in a SOC, security operations, incident response, or related cybersecurity environment.
- Experience supporting security operations across multiple locations, business units, or complex enterprise environments.
- Strong hands‑on experience with SIEM and security monitoring technologies.
- Working knowledge of network security concepts, firewalls, intrusion detection/prevention, endpoint security, and vulnerability management.
- Experience analyzing security alerts and determining appropriate escalation and remediation.
- Strong understanding of incident response methodologies and security best practices.
- Experience working with both IT and/or OT environments is highly desirable.
- Excellent analytical, troubleshooting, communication, and documentation skills.
Preferred Certifications
- CompTIA Security+
- CompTIA Network+
- CompTIA CySA+ or CASP+
- GIAC certifications
- CISM or comparable security certification