Information Security Engineer
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Network Security, Information Security & Data Protection
Position overview
The Information Security Engineer is responsible for supporting and advancing the organization's information security program through security operations, incident response, automation, and continuous improvement initiatives. Working directly with the Information Security Manager, this role helps protect the organization's users, systems, applications, and data by monitoring security events, investigating incidents, administering security technologies, and improving operational capabilities.
This position is highly technical and hands-on. Successful candidates possess a strong understanding of enterprise technologies, enjoy solving complex technical problems, and are driven to improve systems through engineering, automation, and process optimization.
The ideal candidate is intellectually curious, communicates effectively, learns new technologies rapidly, and takes ownership of problems from initial investigation through implementation of practical, long-term solutions. They are comfortable working across infrastructure, cloud, identity, and endpoint technologies while collaborating with multiple technical teams to strengthen the organization's overall security posture.
Responsibilities- Monitor, investigate, and respond to security alerts and incidents.
- Administer Microsoft XDR, Crowd Strike Falcon, and Microsoft Entra .
- Investigate phishing, identity attacks, endpoint detections, account compromise activity, and other security events.
- Develop scripts, automations, and operational workflows to improve efficiency and reduce manual effort.
- Create, maintain, and improve security run books, Standard Operating Procedures (SOPs), and incident response playbooks.
- Document investigations, findings, technical procedures, and operational processes.
- Assist with vulnerability management and remediation efforts.
- Coordinate with Infrastructure, Cloud, IT, and Engineering teams to resolve security findings.
- Research emerging threats, attack techniques, and security technologies.
- Utilize AI tools to improve research, scripting, documentation, troubleshooting, and engineering productivity.
- Recommend and implement improvements to security processes, detections, workflows, and automations.
- Participate in security projects and perform additional duties as assigned.
- Bachelor's degree in Cybersecurity, Cyber Operations, Systems Security Engineering, Computer Science, Information Assurance, or a related technical discipline.
- Three (3) or more years of experience in Information Security, Security Operations, or Security Engineering.
- Experience with Microsoft XDR.
- Experience with Crowd Strike Falcon.
- Experience with Microsoft Entra , including Risky Users and Identity Protection.
- Working knowledge of AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Experience investigating security incidents.
- Experience writing Power Shell, Python, or similar scripting languages.
- Experience developing automations and operational workflows.
- Experience creating, maintaining, and improving security run books, Standard Operating Procedures (SOPs), and incident response playbooks.
The ideal candidate should have experience with, or the ability to quickly become proficient in, the following:
- Security incident response and investigation.
- Endpoint Detection and Response (EDR/XDR) platforms.
- Security Information and Event Management (SIEM) platforms.
- Log analysis, event correlation, and threat hunting.
- Detection engineering and alert tuning.
- Identity and authentication investigations.
- Microsoft 365 and Microsoft Entra investigations.
- Email security and phishing investigations.
- Vulnerability management and remediation workflows.
- Power Shell, Python, or similar scripting languages.
- Kusto Query Language (KQL) and/or Splunk Processing Language (SPL).
- Microsoft Graph API, REST APIs, and security automation.
- Cloud security investigations across AWS, Azure, and GCP.
- Developing and maintaining security run books, Standard Operating Procedures (SOPs), and incident response playbooks.
- Working knowledge of the NIST Cybersecurity Framework (CSF).
- Familiarity with the MITRE ATT&CK Framework and common adversary tactics,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).