Detection & Response — SIEM/SOAR integrations, logging, and detection use cases
•
Network & Cloud Security — supporting NGFW/SASE, CSPM/CWPP, and related controls as needed
•
Perform hands-on engineering work: implement new controls, tune policies, resolve platform issues, and support integrations via APIs and automation.
•
Develop scripts and automation (Python, PowerShell, or similar) to improve operational efficiency, reduce toil, and enforce consistent configurations.
•
Document configurations, runbooks, standards, and procedures; contribute to knowledge sharing and continuous improvement.
Required Qualifications & Experience
•
7+ years of experience in cybersecurity engineering, security operations, or security platform administration roles.
•
Strong generalist foundation across multiple security domains (endpoint/EDR, identity/IAM, vulnerability management, SIEM/detection, network or cloud security). Deep expertise in every area is not required, breadth plus solid hands-on depth in several is key.
•
Proven experience managing and supporting multiple enterprise security platforms in production environments with operational ownership (beyond one-time deployments).
•
Solid scripting/automation skills (Python, PowerShell, Bash, or equivalent) and comfort working with APIs and integrations.
•
Ability to troubleshoot technical issues.
California Residents click below for Privacy Notice: