Cybersecurity Engineer
Core
Design, build, and harden platforms and automation for a 24/7 managed SOC delivering threat detection, investigation, and response.
Role type
Mid-level Cybersecurity Engineer (SOC Operations & Automation)
Builds
Detection stack (SIEM, EDR/XDR, SOAR), automated workflows, and hardened customer cloud environments
Domain
Cybersecurity / Managed Security Services Operations (MSSP)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM/EDR/XDR/SOAR engineering and administration, scripting (Python, PowerShell, Bash), API integrations, networking, Windows/Linux, cloud/virtualization, IaC concepts, complex system troubleshooting
Preferred skills
Clean automation design, solid systems engineering, documentation, collaboration with analysts and customers
Technologies
SIEM, EDR, XDR, SOAR, Python, PowerShell, Bash, private cloud, IaC
Responsibilities
Engineer and operate detection stack (SIEM, EDR/XDR, SOAR) including onboarding and log pipelines, Automate SOC workflows with playbooks and scripting, Provision and harden dedicated customer environments in private cloud, Develop detections and content (correlation rules, use cases, parsers)
Seniority
Mid-level, hands-on IC