Security Engineer
Cloud Platforms
Data Loss Prevention
Edr And Xdr
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Powershell
Security
Security Automation
Security Dashboards
Security Detections
Security Engineer
Security Information And Event Management
Security Monitoring
Security Operations
SOAR
Vulnerability Management
Zero Trust Architecture
Job Description
The Security Engineer will operate within Neptune’s Security Operations Center (SOC), supporting the design, implementation, administration, and optimization of cybersecurity capabilities. This role combines hands-on engineering with technical leadership across incident detection, investigation, response, and remediation, while improving security outcomes through automation, integrations, detection engineering, and process refinement.
Key Responsibilities
- Design, configure, implement, and maintain security platforms including SIEM, EDR/XDR, SOAR, IAM, DLP, Vulnerability Management, and Cloud Security solutions
- Evaluate, test, and deploy new security technologies, including Proof of Concept (POC) assessments
- Create automation and orchestration workflows to improve operational efficiency
- Support cloud security and Zero Trust initiatives across the enterprise
- Develop and tune security detections, correlation rules, and dashboards to strengthen threat detection and reduce false positives
- Conduct proactive threat hunting and analyze telemetry across endpoint, network, identity, cloud, and SIEM environments
- Identify opportunities to enhance detection and response capabilities across the environment
- Monitor emerging threats, vulnerabilities, and industry best practices to guide detection strategy
- Provide technical leadership during investigation, containment, eradication, and recovery for complex and escalated security incidents
- Investigate advanced cyber threats and complex security alerts
- Collect and analyze forensic artifacts, logs, and endpoint telemetry during investigations
- Participate in the on-call rotation and deliver advanced technical support during critical security incidents
- Support root cause analysis and post-incident reviews
- Validate vulnerability findings and coordinate remediation activities with IT Operations, Infrastructure, and Engineering teams
- Implement security controls to address identified risks and track remediation progress within the vulnerability management program
- Partner with SOC Analysts, IT Operations, Infrastructure, Cloud, and Engineering teams to implement and maintain security solutions
- Develop response playbooks, engineering standards, and operational procedures
- Provide mentorship and technical guidance to SOC Analysts
- Create and maintain technical documentation for SOC operations
- Collaborate with Neptune’s MSSP and third-party security partners on engineering and investigation initiatives
- Support compliance initiatives aligned with NIST CSF, CIS Controls, ISO 27001, and Roper Cybersecurity requirements
- Recommend improvements to strengthen Neptune’s security posture, resilience, and compliance
- Assist with audit requests, evidence collection, and security documentation
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
- 2–5 years of experience in cybersecurity, security operations, incident response, or a related technical role
- Experience investigating security alerts, detections, and cybersecurity incidents
- Experience working in a Security Operations Center (SOC) environment
- Experience with SIEM and EDR platforms
- Understanding of security engineering concepts, including detection engineering, automation, and security tool administration
- Strong analytical, troubleshooting, and problem-solving skills
- Strong written and verbal communication skills
Technologies
- SIEM
- EDR/XDR
- SOAR
- Identity and Access Management (IAM)
- Data Loss Prevention (DLP)
- Vulnerability Management
- Cloud Security solutions
- CrowdStrike Falcon
- Google SecOps (Chronicle)
- Microsoft Defender
- Microsoft Entra ID (IAM)
- Cloud Security Platforms (AWS, Azure)
- MITRE ATT&CK Framework
- PowerShell
- Python
- NIST CSF
- CIS Controls
- ISO 27001
- Roper Cybersecurity requirements
Relevant Platforms (Expected Experience with Several)
- CrowdStrike Falcon
- Google SecOps (Chronicle)
- Microsoft Defender
- SIEM platforms
- Endpoint Detection and Response (EDR) platforms
- Security Orchestration, Automation, and Response (SOAR)
- Identity and Access Management (IAM) / Microsoft Entra ID
- Data Loss Prevention (DLP)
- Cloud Security Platforms (AWS, Azure)
- Vulnerability Management Platforms
Preferred Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field
- 2–5 years of experience in Security Operations, Cybersecurity, Incident Response, Vulnerability Management, or Information Technology
- Experience with SIEM platforms such as Google SecOps, Chronicle, Splunk, QRadar, Microsoft Sentinel, or similar technologies
- Experience with EDR platforms such as CrowdStrike Falcon or Microsoft Defender
- Familiarity with the MITRE ATT&CK Framework, threat hunting, and threat intelligence methodologies
- Experience supporting vulnerability management programs and remediation activities
- Knowledge of Windows, Active Directory, Microsoft Entra ID, networking fundamentals, and cloud security concepts
- Experience with AWS and/or Azure environments
- Familiarity with NIST Cybersecurity Framework, CIS Controls, ISO 27001, and security best practices
- Experience with scripting or automation using PowerShell, Python, or similar languages
Certifications (Preferred)
- Security+
- CySA+
- GSEC
- GCIH
- GCIA
- GCED
- CISSP (Associate or Full)
- SC-200
- SC-100
- CrowdStrike Certifications
- Google SecOps Certifications
- AWS or Azure Security Certifications
Education and Experience
- Minimum experience: 2 years
- Years of experience focus: 2–5 years across Information Technology, Cybersecurity, Security Operations, Compliance, or Incident Response
- Education: Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field preferred; equivalent military, technical, or professional experience will be considered
Location and Travel
- Location: Duluth, GA (onsite)
- Additional location mention: Tallassee, AL
- Travel requirement: Typically requires overnight travel less than 10% of the time