Cybersecurity Engineer
  • Saxon Global Inc.
4 Hours Ago
NA
W2
Midlothian-VA
10-15 Years
Required Skills: PowerShell, Python, Splunk, LogRhythm, Microsoft Sentinel
Job Description
Position Overview
Our client is strengthening and modernizing its Security Engineering & Operations capabilities as part of a broader effort to mature its cybersecurity posture. The organization is expanding its engineering depth, enhancing existing SIEM, EDR, and SOC practices, and evaluating the optimal team model for future growth. This initiative focuses on elevating current capabilities, closing visibility gaps, and evolving the tools, processes, and operational practices that will support a mature cybersecurity program.
The Cybersecurity Engineer will help broaden and strengthen core engineering functions that enable an effective SOC model, including SIEM/SOAR integration, identity and endpoint security engineering, secure configuration baselines, and cloud and enterprise architecture support. This role partners with IT operations, application teams, and SOC analysts while operating within an evolving security organization. Success in this role requires adaptability, process improvement experience, strong documentation habits, and a hands-on technical mindset.
 
Key Responsibilities
Security Engineering & Architecture
  • Design and implement security controls across identity, network, endpoint, and cloud environments.
  • Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.
  • Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.
  • Support enterprise security architecture development, including secure-by-design reviews with application and infrastructure teams.
  • Develop and tune detection use cases aligned with the security operations roadmap, prioritized by risk and threat exposure.
  • Engineer identity security controls, including IAM/PAM hardening, role-based access validation, and integration with monitoring solutions.
  • Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.
Security Operations Enablement
  • Build and maintain logging pipelines to ensure visibility across endpoints, servers, network devices, identity platforms, and cloud services.
  • Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.
  • Partner with security operations personnel to develop and tune detection rules, correlation logic, and enrichment processes.
  • Participate in incident investigations and root-cause analysis with a focus on implementing engineering solutions that prevent recurring issues.
  • Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.
Automation & Modernization
  • Identify and implement high-impact opportunities for security automation, including alert enrichment, ticket creation, and response workflow orchestration.
  • Evaluate tool health, tuning opportunities, and integration gaps; provide recommendations to support the cybersecurity modernization roadmap.
  • Support emerging AI-assisted capabilities designed to improve security operations and analyst effectiveness.
Collaboration & Cross-Functional Coordination
  • Work closely with IT operations, infrastructure, endpoint management, and application teams to drive secure configurations and optimize security controls.
  • Participate in governance meetings and contribute to progress reporting and strategic planning efforts.
  • Develop technical documentation, operational runbooks, and knowledge transfer materials for internal teams.
 
Required Qualifications
  • 10+ years of experience in security engineering, security operations, or systems engineering with cybersecurity responsibilities.
  • Hands-on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar technologies.
  • Experience with log onboarding, security monitoring, and detection engineering.
  • Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and role-based access design.
  • Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.
  • Experience implementing secure configuration baselines using CIS, DISA STIG, or comparable frameworks.
  • Proficiency in scripting and automation using PowerShell, Python, or similar languages.
  • Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.
  • Experience working within regulated environments and security compliance frameworks such as NIST CSF, RMF, CJIS, or similar standards.
 
Preferred Qualifications
  • Experience supporting large enterprise or public-sector environments.
  • Familiarity with SOAR platforms and security automation architecture.
  • Experience with vulnerability management tools and remediation workflow engineering.
  • Experience supporting hybrid security operations models involving internal teams and external service providers.
  • Relevant certifications such as CISSP, GSEC, GCIA, GCED, GCSA, AWS Security Specialty, or Azure Security certifications.
 
Expected Deliverables – Year One
  • Develop a SIEM/SOAR engineering plan with integration of at least 80% of core security tools.
  • Deploy 20-50 tuned, risk-based detection use cases.
  • Document logging and visibility improvements across identity, network, endpoint, and cloud environments.
  • Support development of incident response runbooks and cross-functional operational documentation.
  • Conduct a baseline assessment of security tools and provide recommendations for future enhancements.
  • Deliver complete documentation for implemented controls, configurations, and integrations.
 
Engagement Structure
  • May support technical evaluations, product assessments, procurement activities, and contributions to solution documentation.

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates