Principal Cyber Defense Engineer
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, IT Support
Sony Corporation of America, located in New York, NY, is the U.S. headquarters of Sony Group Corporation, based in Tokyo, Japan. Sony's principal U.S. businesses include Sony Electronics Inc., Sony Interactive Entertainment LLC, Sony Music Entertainment, Sony Music Publishing and Sony Pictures Entertainment Inc. With some 900 million Sony devices in hands and homes worldwide today, a vast array of Sony movies, television shows and music, and the Play Station Network, Sony creates and delivers more entertainment experiences to more people than anyone else on earth.
To learn more:
Sony Corporation of America is seeking a Principal Engineer, Cyber Defense, to join the CISD, GSIRT located in Reston, VA.
This position will report to the Cyber Defense Team Senior Manager, Cyber Defense, US1, supporting Sony companies headquartered in the United States. The incumbent will lead the team that provides designs, engineering support, data source on-boarding, implementations, and support of the technology infrastructure that supports a global incident response team. The Cyber Defense team is a pivotal part of Sony’s program to secure its information assets, services, and the products that depend on them, building trust with customers and stakeholders and protecting the privacy of Sony’s customers.
JOBRESPONSIBILITIES
- Lead engagements with Sony Group Companies (SGCs) to identify cyber security requirements, understand Sony’s corporate structure and IT environments, gather IT asset inventories, and facilitate implementation of GSIRT projects
- Implement and manage Microsoft Azure security services, including Azure Security Center, Azure Active Directory, and Defender for Cloud (policies and frameworks
- Plan the deployment of hardware and software based cyber security tools to locations on-prem and in cloud environments (Azure/AWS/GCP preferred)
- Ensure data on-boarding goals as met from on-prem, cloud (IaaS), and software-as-a-service (SaaS) systems into GSIRT’s Security Incident Event Management (SIEM) system
- Prioritize the review of vulnerabilities for potential impact to SGCs and work with SGCs to prioritize remediation or deployment of mitigating controls
- Work closely with engineering, Dev Ops, compliance, and executive teams to drive cloud security initiatives and maintain a robust security posture
- Act as a subject matter expert in cloud security, providing recommendations and insights to stakeholders
- Monitor SIEM solutions for cyber security incident data and provide engineering support to incident response activities
- Role requires flexible work hours and on-call duties during non-standard business hours to support the needs of a global corporation
- Other duties related to cyber defense as assigned
- Ingest and transform data from diverse sources (e.g., logs, databases, APIs) into Splunk, ensuring proper indexing, field extraction, and sourcetypes (including implementing Splunk apps, inputs, etc. as necessary)
- Honesty, trustworthiness, and ethical conduct are essential for this role
- Broad understanding of information technology, cyber security concepts, and cyber security tools
- Understanding of processes and procedures for the aggregation, transport, and on-boarding of data into SIEM solutions (Splunk preferred)
- Experience with one or more programming languages, such as Python
- Working knowledge of networking technologies and protocols; including TCP/IP and standard Internet related protocols
- Competency in one or more data query languages, such as SPL
- Strong ability to design and implement customized Splunk dashboards, reports, and alerts
- Comfort working from the command line interface and leveraging shell scripts to automate repetitive tasks
- Proven expertise in Microsoft Azure services, including Azure Security Center, Azure Active Directory, and Defender for Cloud
- Deep understanding of cloud security best practices, threat management, and compliance frameworks (e.g., NIST, CIS, ISO 27001)
- Experience leading or managing a technical team, preferably a team in a cyber defense related discipline preferred, but this role will primarily be…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).