Cyber Defense Platforms Staff Engineer
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, Security Management & Operations
Cyber Defense Platforms Staff Engineer
As the Associate Director (Staff Engineer) for Cyber Defense Platforms, you will own the defense technology stack end-to-end: SIEM, SOAR, EDR, DLP, email security, and anti-phishing platforms, along with the detection content, automation, and tooling that make them effective. This is a senior individual contributor role with enterprise-wide impact: every alert triaged, threat detected, and incident contained across the company depends on the systems you build and operate.
This is a hybrid position and will be primarily based in Cambridge, MA.
Responsibilities:
- Own the deployment, configuration, administration, and lifecycle of defense platforms including SIEM, SOAR, EDR, DLP, email security, and phishing
- Define the platform roadmap: evaluate, deploy, integrate, and rationalize security technologies to maximize defensive coverage and operational efficiency
- Engineer and maintain security data pipelines across the enterprise: log source onboarding, normalization, enrichment, retention, and cost management
- Own the detection content lifecycle end-to-end: development, testing, tuning, versioning, and retirement of rules and analytics across all platforms
- Establish detection-as-code practices, including version control, peer review, CI/CD deployment, and automated validation of content
- Map detection coverage to MITRE ATT&CK, identify gaps, and partner with threat intel, IR, and offensive security to convert findings into durable detections
- Design and build SOAR playbooks and workflow automation that reduce manual analyst effort and accelerate triage and response, including automated handling of user-reported phishing
- Build internal tooling, integrations, and APIs that connect security platforms to each other and to enterprise systems
- Set the standards for how Cyber Defense builds, deploys, and operates its technology, and serve as the technical authority for the defense technology domain
- Lead cross-functional technical initiatives across IT, infrastructure, and engineering teams, and mentor engineers and analysts across the broader team
Qualifications:
- 8+ years of progressive experience in security engineering, security operations, or detection engineering, with demonstrated ownership of defense and security platforms
- Deep hands-on expertise architecting and administering: SIEM, SOAR, EDR, DLP, or email security and anti-phishing platforms
- Strong software engineering skills in a language commonly used for security automation (e.g., Python, Go, Power Shell), with experience building production-quality integrations and tooling
- Proven experience building and managing detection content at scale, measured against frameworks like MITRE ATT&CK
- Track record of delivering measurable operational improvements through automation, such as reduced response times or expanded capacity without added headcount
- Ability to operate autonomously in a build-from-zero environment and drive technical work across teams you don't manage
- Experience standing up or modernizing a security operations stack (SIEM migration, SOAR implementation, EDR rollout) from early maturity
- Cloud security experience, particularly AWS-native security services
- Experience in regulated industries (pharma, biotech, healthcare, financial services)
- Relevant certifications (e.g., GIAC GCDA/GDAT/GCIA, CISSP) or equivalent expertise
U.S. Pay Range $ - $
The pay range reflects the full-time base salary range we expect to pay for this role at the time of posting. Base pay will be determined based on a number of factors including, but not limited to, relevant experience, skills, and education. This role is eligible for an annual short-term incentive award (e.g., bonus or sales incentive) and an annual long-term incentive award (e.g., equity).
Alnylam's robust Total Rewards package is designed to support your overall health and well-being.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).