Security Specialist
Listed on 2026-09-16
-
IT/Tech
Cybersecurity
Grow with us
Ericsson Inc. does not sponsor U.S work authorizations for this job position including U.S. immigration filings for initial and/or change of employer paperwork for H-1’s, H-1B1’s, E-3’s, O-1’s, and TN’s. Ericsson also does not hire F-1’s working on CPT or EAD for this position.
About This OpportunityEricsson is seeking a Security Specialist to join our global Cyber Defense Center (CDC), based in the US. This is a hybrid role requiring 4 days per week in the office, with working hours of 10:30 AM – 6:30 PM CT (11:30 AM – 7:30 PM CT during Daylight Saving Time), and one weekend shift per month.
The CDC is dedicated to detecting and responding to cyber attacks from external threat actors, with a primary focus on advanced persistent threats (APTs). The Security Operations Center (SOC) provides 24/7 monitoring, triage, incident response, and detection engineering, collaborating closely with CDC units covering Threat Intelligence, Incident Response & Threat Hunting, AI, Red Team, IT, and Process & Governance.
What You Will DoTriage and respond to prioritized alerts in a follow-the-sun SOC model, validating true/false positives, assessing malicious activity, and responding per established plans; elevate advanced threat activity to the Incident Response team and support scoping, containment, and eviction.
Collaborate with agentic AI systems (commercial and in-house) that automate repetitive tasks, enabling focus on analytical work.
Contribute to SOC improvement and automation, including detection engineering, reinforcement learning, Falcon Fusion workflows, and Foundry app development.
Continuously develop skills through Immersive Labs, on-the-job training, quality review sessions, conferences, and peer collaboration.
The Skills You Bring- 7+ years of experience in triage, incident response, and detection engineering within a SOC environment
- Proficiency with EDR, ITDR, cloud security, SIEM, and exposure management tooling;
Crowd Strike Falcon experience preferred - Broad technical knowledge across cloud platforms (AWS, GCP, Azure), Linux, Windows, networking, and identity management, with deep expertise in at least one area
- Strong understanding of threat actor TTPs, with the ability to recognize indicators in telemetry and logs and determine investigative next steps
- A growth mindset, genuine passion for cybersecurity, and a drive to continuously learn and improve without complacency
- Composure and resilience under pressure, with the ability to stay focused during high-stress situations and collaborate effectively with the team
- Strong professional integrity and commitment to handling confidential information with discretion
- Preferred certifications: SANS/GIAC — GCFA, GCFE, GCIA, GCIH, and/or GCFR
At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
Compensationand Benefits at Ericsson Your Pay
The salary range for this position is dependent on various factors including, but not limited to, location, and the candidate’s combination of job-related knowledge, qualifications, skills, education, training, and experience.
Short-Term Variable Compensation Plan :
Your pay also includes the opportunity for an annual bonus. Actual bonus payouts are based on performance of the business against the unit’s objectives, individual performance, and the individual bonus target. Certain eligibility and pro-ration rules apply.
Sales Incentive Plan :
Your pay also includes the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).