Security Engineer II
The Security Engineer II will safeguard systems, data, and assets by improving prevention, detection, investigation, response, and recovery from cyber threats. The role focuses on security infrastructure, threat hunting, incident response, vulnerability management, automation, and AI security.
Responsibilities
- Analyze security incidents and threat actors using the MITRE ATT&CK framework.
- Investigate and respond to security incidents and develop effective triage processes.
- Manage enterprise security infrastructure including IDS/IPS, SIEM, EDR, MFA, and email security.
- Develop threat hunting activities using anomalous log data and intelligence.
- Create telemetry signals for threat detection and response using APIs.
- Engineer incident analysis and response automation.
- Conduct war-gaming and tabletop activities to strengthen incident response capabilities.
- Conduct vulnerability assessments and recommend remediation actions.
- Implement threat detection rules and event correlation using SIEM platforms.
- Identify security monitoring blind spots and opportunities for threat detection.
- Maintain information security infrastructure.
- Educate users on security best practices and promote cybersecurity awareness.
Requirements
- 3–5 years of experience in cybersecurity, security engineering, or cyber defense.
- Experience with SIEM, EDR, firewalls, IDS/IPS, vulnerability management, identity and access management, and Microsoft 365 security.
- Experience investigating security events through log analysis and incident response.
- Understanding of vulnerability identification, prioritization, remediation, and validation.
- Experience securing cloud environments and SaaS platforms.
- Working knowledge of Windows, Linux, and macOS security.
- Experience writing PowerShell, Python, or similar scripts.
- Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, and enterprise network security.
- Experience with endpoint protection technologies.
- Strong communication and documentation skills.
- Experience with SOAR platforms.
- Knowledge of NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, or ISO 27001.
- Experience using AI and LLM tools for security operations.
- Awareness of AI security risks and responsible AI practices.
Benefits
- Employer-paid medical insurance
- Dental insurance
- Vision insurance
- Retirement contributions
- Paid time off
- Discretionary performance bonus