Security Engineer II - Security Operations Center (SOC)

CSX Corporation

Jacksonville (FL)

On-site

USD 110,000 - 150,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

CSX Corporation is seeking a Security Engineer II for its Security Operations Center in the Jacksonville area. You will monitor, detect, analyze, investigate, and respond to cybersecurity threats impacting CSX systems, networks, and data across rail operations and corporate assets.

Responsibilities include leading incident response efforts, developing detection use cases, and collaborating with infrastructure, engineering, and business teams to strengthen CSX’s cyber posture.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 3+ years of cybersecurity experience.
  • 2 years in a Security Operations Center, incident response, security engineering, or a related security role.
  • Experience investigating security incidents across enterprise environments.
  • Experience with Microsoft security technologies and cloud security solutions.
  • Equivalent minimum qualifications include HS Diploma and 8+ years in cybersecurity.

Responsibilities

  • Monitor security alerts and events across SIEM, EDR, email, cloud, and network security platforms.
  • Investigate and respond to cybersecurity incidents including malware, phishing, ransomware, and data loss.
  • Analyze endpoint, network, cloud, identity, and application security events.
  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.
  • Participate in major incident response activities and cyber crisis management.

Skills

Security operations
Incident response
Threat hunting
Threat intelligence analysis
Scripting (PowerShell, Python)

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering
High School Diploma/GED

Tools

Microsoft Defender XDR
Microsoft Sentinel
Microsoft Defender for Endpoint
Microsoft Entra ID

Job description

Job Summary

The Security Engineer II - Security Operations Center (SOC) is responsible for monitoring, detecting, analyzing, investigating, and responding to cybersecurity threats impacting CSX systems, networks, applications, and data. This role serves as a technical contributor within the Security Operations Center and collaborates with infrastructure, engineering, application, and business teams to protect critical railroad operations and corporate assets.

The Security Engineer II leverages advanced security technologies, threat intelligence, automation, and incident response methodologies to identify and mitigate security risks while supporting continuous improvement of CSX's cybersecurity posture.

Primary Responsibilities
Security Monitoring and Incident Response
  • Monitor security alerts and events generated by SIEM, EDR, email security, cloud security, and network security platforms.

  • Investigate and respond to cybersecurity incidents including malware, phishing, ransomware, unauthorized access, data loss, insider threats, and advanced persistent threats.

  • Conduct analysis of endpoint, network, cloud, identity, and application security events.

  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.

  • Participate in major incident response activities and cyber crisis management efforts.

Threat Detection and Threat Hunting
  • Conduct proactive threat hunting activities across enterprise environments.

  • Research emerging threats, adversary tactics, and attack techniques using threat intelligence sources.

  • Develop and tune detection use cases aligned with the MITRE ATT&CK framework.

  • Analyze indicators of compromise and indicators of attack.

  • Recommend improvements to detection capabilities and monitoring coverage.

Security Engineering and Operations
  • Administer and support security technologies, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Entra ID, Azure security services, email security platforms, vulnerability management solutions, and network security monitoring tools.

  • Develop and maintain security monitoring rules, analytics, dashboards, and alerting mechanisms.

  • Support the implementation, integration, testing, and operationalization of new security technologies.

Automation and Process Improvement
  • Develop and maintain security automation workflows and incident response playbooks.

  • Leverage Power Automate, Logic Apps, SOAR technologies, scripting, and AI-enabled solutions to improve operational efficiency.

  • Identify opportunities to reduce manual effort, improve alert quality, and shorten response times.

  • Contribute to SOC process optimization and continuous improvement initiatives.

Compliance and Reporting
  • Support cybersecurity compliance activities related to SOX, applicable FRA and CISA requirements, internal policies, and security standards.

  • Create accurate technical reports, executive summaries, metrics, and incident documentation.

  • Maintain evidence and records required for audits, investigations, and regulatory reporting.

Collaboration and Knowledge Sharing
  • Partner with infrastructure, cloud, network, identity, application, legal, and business teams to resolve security findings and incidents.

  • Participate in cybersecurity tabletop exercises, simulations, and readiness activities.

  • Provide mentoring and technical guidance to junior analysts and engineers.

  • Contribute to SOC procedures, runbooks, knowledge articles, and response documentation.

Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.

  • 3 or more years of cybersecurity experience.

  • 2 years of experience in a Security Operations Center, incident response, security engineering, or a related security role.

  • Experience investigating security incidents across enterprise environments.

  • Experience with Microsoft security technologies and cloud security solutions

Equivalent Minimum Qualifications
  • High School Diploma/GED

  • 8 or more years of cybersecurity experience, a Security Operations Center, incident response, security engineering, or a related security role.

Preferred Qualifications

5 or more years of cybersecurity experience.

One or more of the following certifications is preferred:

  • CISSP

  • GIAC certifications such as GCIH, GCIA, or GCFA

  • Microsoft security certifications, including SC-200 or SC-100

  • CompTIA Security+ or CySA+

  • Experience in the following is preferred:

    • Railroad, transportation, critical infrastructure, or industrial environments.

    • MITRE ATT&CK-based detection engineering and threat hunting programs.

    • Security orchestration, automation, and response platforms.

    • Vulnerability management and cloud security operations.

Knowledge and Skills
  • Security Information and Event Management platforms and security analytics.

  • Endpoint Detection and Response technologies.

  • Microsoft Sentinel, Microsoft Defender XDR, Azure, and Microsoft Entra ID security.

  • Threat hunting, threat intelligence analysis, and incident response.

  • Working knowledge of Windows and Linux operating systems.

  • Networking concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, and firewalls.

  • Security automation and scripting; PowerShell, Python, and KQL are preferred.

  • Digital forensics and evidence-handling fundamentals.

  • Ability to work independently or collaboratively

  • Technical agility and strong analytical skills

Job Requirements

This position may participate in an on-call rotation and provide support during cybersecurity incidents impacting CSX operations, systems, or critical business functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II - Security Operations Center (SOC)
Security Engineer II - Security Operations Center (SOC)

CSX • Jacksonville (FL)

On-site
USD 110,000 - 140,000
SOC Security Engineer II: Threat Detection & IR
SOC Security Engineer II: Threat Detection & IR

CSX • Jacksonville (FL)

On-site
USD 110,000 - 140,000
SOC Security Engineer II: Threat Hunter & Incident Response
SOC Security Engineer II: Threat Hunter & Incident Response

CSX Corporation • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Cyber Security Operations Engineer
Cyber Security Operations Engineer

OakTree Staffing • Tulsa (OK)

On-site
USD 100,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

Empirical-Food • Dakota Dunes (SD)

On-site
USD 95,000 - 120,000
Sr Security Engineer I - IAM / Cloud Security
Sr Security Engineer I - IAM / Cloud Security

CSX • Jacksonville (FL)

On-site
USD 120,000 - 190,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Sr Cyber Defense Sys Engineer
Sr Cyber Defense Sys Engineer

Constellation Energy Corp. • Baltimore (MD), Northern (KY)

Hybrid
USD 122,000 - 135,000
Cyber Security Engineer
Cyber Security Engineer

TEEMA Solutions Group • Washington

On-site
USD 90,000 - 120,000