Sr Cyber Defense Sys Engineer
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Network Security, Systems Engineer
Sr Cyber Defense Sys Engineer
Responsible for the maintenance and operation of the Cyber Security Operations Center (CSOC) and for providing targeted security advisory services. Tests, implements, deploys, maintains, reviews, and administers the infrastructure hardware, software, and documentation that are required to effectively manage network defense. Enables the Cyber SOC to meet key performance metrics across five key capabilities:
Security Monitoring, Incident Handling & Response, Digital Forensics & eDiscovery, Cyber Threat Intelligence, and Technical Solutions Development. Responsible for the creation of content for use in monitoring toolsets while maintaining a uniform view of security monitoring architecture. Tests, implements, deploys, maintains, and administers the infrastructure hardware and software.
Continually monitor, refine & improve upon the security technologies utilized by the CSOC. Perform system administration on specialized cyber defense applications and systems (e.g., EDR, Cloud and Email Security, SIEM, appliances) to include installation, configuration, maintenance, backup and restoration. Build, install, configure, and test dedicated cyber defense hardware.
Provide Log & Monitoring Design Services. Identify potential conflicts with implementation of any cyber defense capability (e.g., tool testing and optimization).
Deploy new data source feeds into SIEM & develops initial content for monitoring
Monitor SIEM infrastructure performance
Provide Security Advisory Services
Assist in identifying, prioritizing, and coordinating the protection of critical cyber defense infrastructure and key resources.
Responsible for SOC Release Management & SOC Change Management
Assure that all equipment, systems, applications & appliances of threat & vulnerability management technologies are available & running effectively.
Assist in assessing the impact of implementing and sustaining a dedicated cyber defense infrastructure.
Lead projects to further enhance security technologies, practices, processes
Bachelor's degree and 5-years relevant experience, in lieu of degree 9 years of relevant experience
5-years solid, diverse experience in cyber security vulnerability assessments, or equivalent combination of education and work experience
Knowledge in the following core technical competencies: SIEM, EDR, Microsoft security suite, Linux, Palo Alto, Operations, Engineering, Content Development, Internetworking, TCP IP
Strong knowledge of the Software Development Life Cycle (SDLC) and digital product development
Knowledge of how network services and protocols interact to provide network communications.
Knowledge of Security principles such as Threat Lifecycle Management & Incident Management & Lifecycle.
Knowledge of Cyber SOC processes and Cyber SOC Engineering
Knowledge of network protocols (e.g., Transmission Control Protocol/Internet Protocol [TCP/IP], Dynamic Host Configuration Protocol [ DHCP] and directory services (e.g., Domain Name System [DNS], Active Directory)
Knowledge of network traffic analysis methods
Knowledge of packet level analysis using appropriate tools (e.g., Wireshark, tcpdump).
Knowledge of basic system administration, network, and operating system hardening techniques
Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense in-depth).
Knowledge of OSI model and underlying network protocols (e.g., TCP/IP, Dynamic Host Configuration Protocol [DHCP]), and directory services (e.g., Domain Name System [DNS]).
Skill in troubleshooting and diagnosing cyber defense infrastructure anomalies and work through resolution
Skill in securing network communications
Knowledge of protecting a network against malware
Knowledge of web filtering technologies
Knowledge of cyber defense policies, procedures, and regulations
Knowledge of test procedures, principles, and methodologies (e.g., Capabilities and Maturity Model Integration (CMMI))
Knowledge of basic system, network, OS hardening techniques and security benchmarks
Graduate degree in cyber security or related area of expertise.
Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff
Skill in using security event correlation tools
In-depth knowledge of cyber security program elements such as Policy Development, Application Security, Information Security, Network Security, Disaster Recovery Planning, Operational Security, Incident Response, and End User Education
Experience with Data Pipelines such as Cribl and Bind Plane.
CIM Normalization
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).