Cybersecurity Engineer - Threat Management

Cognizant

New York (NY)

On-site

USD 115,000 - 134,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
PTO & holidays
401(k) plan
Disability insurance
Parental leave
Employee stock plan

Job summary

Cognizant in New York, NY is seeking a Threat Management Associate to monitor, triage, investigate, and escalate cybersecurity threats across diverse environments. The role focuses on analyzing security events from SIEM, EDR, cloud, and network platforms and coordinating incident response activities.

The ideal candidate will have 3–7 years of security operations experience and hands-on expertise with SIEMs and EDR tools. Visa sponsorship is not available for this position.

Qualifications

  • 3–7 years in Security Operations or related roles.
  • Experience in SIEM analysis and incident triage.
  • Hands-on with SIEM platforms (Microsoft Sentinel, Splunk, QRadar).
  • Experience with EDR and threat detection tools.
  • Knowledge of MITRE ATT&CK and NIST Cybersecurity Framework.
  • Familiarity with ticketing systems (ServiceNow).
  • Strong analytical and documentation skills.
  • Security certifications preferred.

Responsibilities

  • Monitor and analyze security alerts from SIEM, EDR, cloud, network, and enterprise security platforms.
  • Perform initial triage and investigation to determine validity, severity and impact.
  • Analyze indicators of compromise (IOCs) and threat intelligence to identify threats.
  • Correlate logs and telemetry to support investigations and detection.
  • Escalate confirmed incidents to L2/L3 and support response processes.
  • Conduct threat monitoring, hunting, and situational awareness activities.
  • Document findings, actions, evidence, and metrics accurately.
  • Support handovers and reporting to stakeholders.
  • Leverage MITRE ATT&CK and threat intel to improve detection and response.
  • Collaborate with SOC, IR, Vulnerability Mgmt, and Security Eng teams.

Skills

Threat monitoring
Incident triage
SIEM analysis
Log correlation
Security investigations
EDR/Threat detection tools
MITRE ATT&CK familiarity
NIST CSF familiarity
ServiceNow / ticketing
Security certifications

Tools

Microsoft Sentinel
Splunk
QRadar
CrowdStrike
Microsoft Defender
Cortex XDR

Job description

Practice - CIS - Cloud, Infrastructure, and Security Services

About Cloud Infrastructure & Security Services: Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about embracing digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the rapidly evolving needs of the digital era. Our holistic approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to run the business in a secure environment.

Job Summary

We are seeking a Threat Management Associate to support enterprise security operations by monitoring, triaging, investigating, and escalating cybersecurity threats across diverse technology environments. This role will be responsible for analyzing security events from SIEM, EDR, cloud, and network security platforms, validating potential threats, and coordinating incident response activities. The ideal candidate will possess strong experience in threat monitoring, incident triage, threat intelligence analysis, and SOC operations. This position requires strong analytical skills, attention to detail, and the ability to operate effectively in a fast-paced security operations environment.

Please note, this role is not able to offer visa transfer or sponsorship now or in the future

In this role, you will:
  • Monitor and analyze security alerts generated from SIEM, EDR, cloud, network, and enterprise security platforms.
  • Perform initial triage and investigation of security events to determine validity, severity, business impact, and escalation requirements.
  • Analyze indicators of compromise (IOCs), threat intelligence feeds, attack patterns, and anomalous activity to identify potential threats.
  • Correlate logs, events, and telemetry across multiple security tools to support security investigations and threat detection activities.
  • Escalate confirmed security incidents to L2/L3 teams and support incident response processes according to established procedures.
  • Conduct threat monitoring, threat hunting, and situational awareness activities to identify emerging risks and attack techniques.
  • Document investigation findings, response actions, incident evidence, and operational metrics accurately and consistently.
  • Support shift handovers, operational reporting, and communication of security incidents and threats to relevant stakeholders.
  • Leverage MITRE ATT&CK, threat intelligence, and security frameworks to improve threat detection and response effectiveness.
  • Collaborate with SOC, Incident Response, Vulnerability Management, and Security Engineering teams to strengthen overall security operations.
What you need to have to be considered
  • 3–7 years of experience in Security Operations, Threat Management, Threat Hunting, SOC, or Cybersecurity Monitoring roles.
  • Strong knowledge of threat monitoring, incident triage, SIEM analysis, log correlation, and security investigation methodologies.
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or similar technologies.
  • Experience working with EDR and threat detection tools such as CrowdStrike, Microsoft Defender, Cortex XDR, or equivalent solutions.
  • Understanding of threat intelligence, IOC analysis, attack techniques, malware indicators, and adversary tactics.
  • Familiarity with MITRE ATT&CK, NIST Cybersecurity Framework, incident response processes, and SOC operations.
  • Experience using ServiceNow, ticketing systems, and security operational workflows.
  • Strong analytical, troubleshooting, communication, and documentation skills.
  • Experience supporting security incident escalation, reporting, and operational handoffs in a 24x7 or managed security environment.
  • Security certifications such as Security+, CySA+, GSEC, CEH, SC-200, or equivalent are preferred.

#LI-EF1

#CB

#Ind123

Applications will be accepted until 8 Sep 2026.

Salary and Other Compensation:

The annual salary for this position is between $[114,500 - 134,000] depending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.

Benefits:
  • Medical/Dental/Vision/Life Insurance
  • Paid holidays plus Paid Time Off
  • 401(k) plan and contributions
  • Long-term/Short-term Disability
  • Paid Parental Leave
  • Employee Stock Purchase Plan
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

Cognizant • New York (NY)

On-site
USD 134,000 - 155,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
401(k) plan and contributions
+3
Senior IAM Analyst
Senior IAM Analyst

Cognizant • New York (NY)

On-site
USD 134,000 - 155,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
CyberSecurity Project Manager
CyberSecurity Project Manager

Cognizant Technology Solutions • Dallas (TX)

Hybrid
USD 84,000 - 130,000
Medical/Dental/Vision/Life Insurance
401(k) plan and contributions
Paid holidays and PTO
+1
NOC Analyst
NOC Analyst

Cognizant • Plano (TX)

Remote
USD 37,000 - 69,000
Medical/Dental/Vision/Life Insurance
Paid holidays plus Paid Time Off
401(k) plan and contributions
+3
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • Tampa (FL)

On-site
USD 141,000 - 212,000
Medical, dental & vision coverage
401(k)
Life, accident, and disability保险
+3
Information Security Specialist
Information Security Specialist

Cytek Biosciences • Fremont (CA)

On-site
USD 110,000 - 150,000
Security Analyst II - SOC
Security Analyst II - SOC

Cyderes • Kansas City (MO)

On-site
USD 60,000 - 100,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Infosys Limited • Hartford (CT)

On-site
USD 90,000 - 120,000
Long-term/Short-term Disability
401(k) plan
Health and Dependent Care Reimburse
+1
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Infosys Limited • Carolina (RI)

On-site
USD 110,000 - 150,000
Disability benefits
Health insurance
401(k) plan