Cyber Defense Platforms Staff Engineer
Job in
Cambridge, Middlesex County, Massachusetts, 02140, USA
Listed on 2026-08-30
Listing for:
Scorpion Therapeutics
Full Time
position Listed on 2026-08-30
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Systems Engineer
Job Description & How to Apply Below
Responsibilities:
- Own deployment, configuration, administration, and lifecycle of defense platforms including SIEM, SOAR, EDR, DLP, email security, and anti-phishing.
- Define the platform roadmap: evaluate, deploy, integrate, and rationalize security technologies.
- Engineer and maintain enterprise security data pipelines (log onboarding, normalization, enrichment, retention, cost management).
- Own the detection content lifecycle end-to-end (development, testing, tuning, versioning, retirement).
- Establish detection-as-code practices (version control, peer review, CI/CD, automated validation).
- Map detection coverage to MITRE ATT&CK; identify gaps and partner with threat intel/IR/offensive security to create durable detections.
- Design and build SOAR playbooks and workflow automation to reduce manual effort and accelerate triage/response (including automated handling of user-reported phishing).
- Build internal tooling, integrations, and APIs connecting security platforms to each other and enterprise systems.
- Set standards for building/deploying/operating the defense technology domain; serve as technical authority.
- Lead cross-functional technical initiatives and mentor engineers and analysts.
- 8+ years in security engineering/operations/detection engineering with ownership of defense/security platforms.
- Hands-on expertise architecting/administering SIEM/SOAR/EDR/DLP or email security and anti-phishing.
- Strong security automation software engineering (e.g., Python, Go, Power Shell) with production integrations.
- Experience building/managing detection content at scale (e.g., MITRE ATT&CK).
- Proven automation-driven operational improvements.
- Ability to operate autonomously in a build-from-zero environment.
- Experience standing up or modernizing a security ops stack (e.g., SIEM migration, SOAR implementation, EDR rollout).
- Cloud security experience, especially AWS-native services.
- Experience in regulated industries (pharma/biotech/healthcare/financial services).
- Relevant certifications (e.g., GIAC GCDA/GDAT/GCIA, CISSP) or equivalent expertise.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×