Remote job
Staff Cyber Defense Engineer
Job details
About this role
Role overview Build and improve enterprise cyber defense capabilities across detection, incident response, threat hunting, automation, and readiness. This is a senior hands-on engineering role with independent ownership of technical solutions, complex investigations, and initiatives that strengthen defensive coverage.
Responsibilities - Develop and maintain detection content, from defining telemetry needs and writing logic to validation, tuning, and retirement. - Engineer telemetry integrations, response playbooks, SOAR workflows, and automation, including agent-assisted response with human oversight. - Hunt for threats using intelligence, adversary behavior, and security telemetry; turn findings into stronger detections and controls. - Lead complex investigations through containment, recovery, root-cause analysis, and lasting risk reduction. - Support red and purple team exercises, adversary simulations, and detection testing; identify and address defensive gaps. - Improve visibility and readiness through tooling assessments, technical exercises, playbook checks, and escalation testing.
Requirements - Typically a technical bachelor’s degree and 8–12 years of related experience, a master’s and 5–7 years, or a PhD and 2–4 years. - Experience owning cyber defense engineering solutions and complex technical work. - Strong knowledge of SIEM, SOAR, endpoint and network detection, identity and email telemetry, cloud security, and enterprise networking. - Engineering experience with detection logic, telemetry pipelines, security tooling, APIs, or automation; relevant languages and query tools may include Python, PowerShell, SPL, KQL, and SQL. - Knowledge of threat hunting, incident response, digital forensics fundamentals, threat intelligence, adversary behavior, and MITRE ATT&CK.
Benefits and work setup - Home-office remote arrangement; hybrid work may be available for people near an assigned site. - A flexible workplace option is mentioned; details are not specified.