Cybersecurity Engineer
Job Description
The Cybersecurity Engineer will design, implement, and automate advanced security controls with the Security Operations team, improving monitoring, detection, and incident response across key security programs.
Key Responsibilities
- Manage and optimize SOC operations, tools, and workflows to support effective security monitoring, detection, and incident response.
- Develop and implement SOC processes that improve operational efficiency and enable advanced threat detection.
- Manage and optimize EDR/XDR coverage for servers, workstations, and mobile endpoints.
- Implement endpoint hardening controls aligned with CIS Controls, including attack surface reduction, application control, host firewall, and disk encryption.
- Develop and maintain automated endpoint containment and remediation capabilities to reduce attacker dwell time.
- Partner with IT and Infrastructure teams to remediate endpoint security gaps and validate control effectiveness.
- Implement and optimize DLP policies across endpoints, email, SaaS, and cloud environments to protect sensitive and regulated data.
- Partner with Legal, GRC, and business stakeholders to establish data classification and sensitivity labeling standards.
- Investigate DLP and insider risk alerts, tuning policies to balance security coverage and false positives.
- Automate DLP response actions and define metrics to measure program effectiveness and compliance.
- Support incident response across identification, containment, eradication, and recovery.
- Develop and maintain incident response playbooks and conduct simulations to strengthen readiness.
- Lead post-incident reviews and implement lessons learned to improve security controls and processes.
- Support vulnerability assessments, prioritization, remediation, and ongoing program management, including patching and mitigation with IT and Development teams.
- Establish program metrics and communicate security risks and opportunities to leadership.
- Develop and maintain SOAR playbooks to automate enrichment, triage, and response for high-volume security alerts.
- Apply Infrastructure as Code (IaC) and CI/CD practices so security tooling, detections, policies, and integrations are version-controlled, peer-reviewed, and repeatable.
- Identify manual security processes and build scalable, measurable automated workflows with defined owners and success criteria.
Required Qualifications
- 2–4+ years of hands-on experience in security engineering roles.
- 1+ year of hands-on experience in software engineering.
- Strong understanding of security principles, software development, IAM, networking, cloud, SOAR, and security operations.
- Strong problem-solving, communication, and documentation skills.
- Proven ability to collaborate effectively with cross-functional technical teams.
- Experience applying Zero Trust methodologies and SSE platforms, including Cloudflare, Cisco, Microsoft, and Palo Alto Networks.
- Python, REST APIs, and familiarity with data formats including JSON, CSV, and XML.
- Security automation experience, including SOAR, CI/CD, and Infrastructure as Code (IaC).
- Cloud environments experience, including Azure and AWS.
- IAM/PIM solutions experience, including Entra ID, CyberArk, Okta, and Auth0.
- Linux and Windows administration experience.
- SIEM platform experience, including Microsoft Sentinel, Splunk, and Rapid7.
- DevOps methodologies and principles.
- Next-Generation Firewall experience, including Palo Alto, Fortinet, Sophos, and Check Point.
- Compliance frameworks experience, including PCI DSS, SOX, NIST, and CIS Controls.
- EDR platforms experience, including Microsoft, CrowdStrike, and SentinelOne.
- DLP solutions experience, including Microsoft Purview, Symantec, and Trellix.
- Large Language Models (LLMs) and prompt engineering concepts.
- Certifications: CISSP, CCSP, or OSCP.
- AWS Certified Solutions Architect – Associate.
- AWS Certified Security – Specialty.
- Microsoft Certified: Azure Security Engineer Associate.
- CCNA.
- HashiCorp Certified: Terraform Associate.
Technologies
- Python, REST APIs, JSON, CSV, XML
- SOAR, CI/CD, Infrastructure as Code (IaC)
- Azure, AWS
- Entra ID, CyberArk, Okta, Auth0
- Linux, Windows
- Microsoft Sentinel, Splunk, Rapid7
- Cloudflare, Cisco, Palo Alto Networks
- Next-Generation Firewalls: Palo Alto, Fortinet, Sophos, Check Point
- EDR: Microsoft, CrowdStrike, SentinelOne
- DLP: Microsoft Purview, Symantec, Trellix
- Large Language Models (LLMs), Terraform
- CIS Controls, Microsoft Entra ID
Location and Work Schedule
- Tempe, Arizona (onsite)
- In-office requirement: 4 days per week (Mon–Thurs); Fridays are optional remote work days
Compensation
DOE
Physical Requirements
- Must be able to work in a busy, crowded, and loud office with frequent distractions and interruptions.
- Must be able to collaborate in-person with occasional impromptu in-person meetings.
- Ability to adapt to typical office conditions, including exposure to air conditioning, heating, artificial lighting, and varying noise levels.
- Mobility for desk work, including sitting, standing, reaching, twisting, stretching, and occasional movement or lifting of office items up to 25 pounds.
- Hearing sufficient (or correctable) to understand spoken information for virtual meetings and phone calls; hearing aids or assistive devices acceptable.
- English reading and writing proficiency for processing documents, drafting reports, and following up on actions.
- Vision sufficient (or correctable) for computer-screen reading and use of visual tools.
- Proficiency operating a computer and office tools such as printers, scanners, and collaboration software.
- Strong verbal and written communication for interactions via email, video conferencing, and in-office communication tools.