Cyber Security Engineer
Posted 27 days ago · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
This role involves owning incident detection, triage, and response across the organization's infrastructure and enterprise browser platform. You will develop and tune detection rules, build automated response workflows using platforms like Torq, and monitor the environment for anomalies. Additionally, you will investigate cloud security findings and collaborate with engineering teams on remediation.
- 3+ years of hands-on experience in security operations, incident response, or detection engineering
- Practical experience with SIEM, EDR, and cloud security platforms - Wiz, Coralogix, or equivalents
- Proficiency in scripting and automation
- experience building or extending security automation workflows (Torq, Tines, SOAR, or similar)
- Strong grasp of attacker techniques, common detection evasion methods, and incident investigation methodology
- Experience with threat intelligence operationalization
- Familiarity with compliance frameworks (SOC2 or equivalent)
Extracted from the job description · kept up to date automatically
Who this suits
This role suits security professionals with 3 or more years of hands-on experience in security operations, incident response, or detection engineering who are proficient in scripting and security automation. It is less ideal for those who prefer highly structured environments with static priorities or those without practical experience in SIEM, EDR, and cloud security platforms.
Full job description
Original listing · kept for referenceSecOps IR Engineer:
This is a hands-on, build-and-operate role - ideal for someone who is equally comfortable writing a detection rule, investigating a live incident, and shipping a Torq workflow before end of day.
You will be a core member of the SecOps team, owning incident detection, triage, and response across the organization's infrastructure and enterprise browser platform. You will work closely with the SecOps Lead to mature incident response capabilities, build the automation and tooling that power operational workflows, and help keep the organization and its customers ahead of real-world threats.
Key Responsibilities
Incident Response: Lead and participate in the full incident lifecycle - detection, triage, investigation, containment, and post-mortem. Own runbooks and ensure they reflect current threat landscape and tooling.
Detection Engineering: Develop, tune, and maintain detection rules across SIEM, EDR, and security audits. Minimize false positives; maximize signal value.
Security Automation: Build and improve automated response workflows using platforms like Torq; reduce manual toil on alert triage, enrichment, and escalation paths.
Threat Monitoring & Hunting: Continuously monitor the environment for anomalies and indicators of compromise; proactively hunt for threats aligned to our threat model.
Cloud Security Operations: Investigate and triage findings from cloud-native security tooling (Wiz, AWS CloudTrail); collaborate with engineering teams on remediation of infrastructure-level issues.
Tooling & Integrations: Contribute to the ongoing development of the SecOps toolchain - integrating alert sources, building dashboards, and improving the Jira-based alert center.IR Documentation: Maintain incident.io flows, response playbooks, and post-incident reports; contribute to the team's runbook hub.
Requirements
3+ years of hands-on experience in security operations, incident response, or detection engineering.
Practical experience with SIEM, EDR, and cloud security platforms - Wiz, Coralogix, or equivalents.
Proficiency in scripting and automation; experience building or extending security automation workflows (Torq, Tines, SOAR, or similar).
Strong grasp of attacker techniques, common detection evasion methods, and incident investigation methodology.
Ability to work independently and drive initiatives end-to-end; comfortable in a fast-moving environment with shifting priorities.
Experience with threat intelligence operationalization is a plus.
Familiarity with compliance frameworks (SOC2 or equivalent) is a plus
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- 3+ years of hands-on experience in security operations, incident response, or detection engineering, Practical experience with SIEM, EDR, and cloud security platforms - Wiz, Coralogix, or equivalents, Proficiency in scripting and automation, experience building or extending security automation workflows (Torq, Tines, SOAR, or similar), Strong grasp of attacker techniques, common detection evasion methods, and incident investigation methodology