Senior Engineer, Cyber Defense Center
Listed on 2026-08-31
-
IT/Tech
Cybersecurity
Select how often (in days) to receive an alert:
Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.
We are seeking a Senior Security Engineer to join our global Cyber Defense Center Engineering team. You will apply an Everything-as-Code approach to build and manage our software-defined security operations architecture, designing the logic and systems that power our global detection and response platform.
Key Responsibilities:- Engineer Detection-as-Code:
Write detection logic using KQL, SPL, SQL, and Python. Manage the lifecycle strictly through version control and CI/CD pipelines. Create new monitoring use cases based on red team exercises, CTIC reports, and your own hypothesis-driven threat research. - Automate Threat Response:
Build and integrate modular automation playbooks across the security stack to accelerate incident response. - Optimize Security Controls:
Configure and tune enterprise security controls (XDR, firewalls, cloud security, DLP) to adapt to new threats. - Drive Capability Engineering:
Partner with cross-functional teams to translate analytical needs into architecture and working code. Ensure engineering output directly supports frontline defenders without adding operational friction. - Establish AI & Data Foundations:
Integrate contextual data models (like knowledge graphs), API gateways, and threat intelligence pipelines to support our targeted AI and ML workloads. - Leverage Hybrid Data Ecosystems:
Develop detection and automation use cases across a variety of different data architectures (SIEM, data lakes, S3/Storage blobs, Federated Search). - Mitigate Security Gaps:
Mitigate detection and response gaps through the creation of new detection rules, improvement of processes, new architectural designs, and hand-over to other technical teams. - Enforce Pipeline Quality:
Build and maintain CI/CD pipelines with automated validation gates for secure content deployment. Use breach attack simulation & threat intelligence verification where applicable in larger validation workflows.
Do you dream big? We do too, and we are excited to grow together. In this role, you will bring:
- Collaboration & Articulation:
Problem-solving mindset with the ability to bridge the gap between engineering and SOC operations effectively. Able to convey targeted messages to different audiences. - Core Security Expertise:
Strong background in SOC and/or Sec Ops engineering. - Engineering Mindset:
Proficiency in Python or Power Shell, software engineering best practices, APIs, and data structures (JSON/YAML). - Query Mastery & Scripting:
Deep proficiency in security query languages (Splunk SPL, KQL, SQL) and Python/Type Script. - Git Ops & CI/CD:
Hands-on experience with Git and CI/CD platforms for managing infrastructure and logic as code. - Security Tooling:
Technical experience configuring and administering enterprise security controls (XDR/EDR/NDR, Firewalls, Cloud Security, DLP, Identity).
- Data Modeling:
Familiarity with Graph Databases (Neo4j, Cosmos DB Gremlin) and entity relationship modeling. - Applied AI:
Experience integrating LLMs or building RAG pipelines for enterprise use cases. - Containerization & IaC:
Experience with Docker, API Gateways, and Infrastructure-as-Code (Terraform/Bicep). - Software Development:
Experience working with compiled languages (C# / .NET). - OT Security:
Exposure to Operational Technology (OT) and manufacturing environments.
At the Volvo Group, we strive for a clear, transparent, and straightforward compensation approach, motivating you to contribute to the company’s growth. For this position, the base pay is set at $ - $ annually, and where applicable, bonus eligible. The range for this role, as well as final salary offered, is determined by several factors including, but not limited to, geographic location, work-related knowledge, certifications, skills, education, and experience.
In addition to these factors, we believe in the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).