Role Overview
Our client is seeking a hands-on Senior Cybersecurity Engineer to serve as the senior technical escalation point for complex security platform, configuration, and integration issues. This person will lead implementation workstreams, optimize security controls, resolve difficult break/fix issues, and turn recurring operational problems into lasting engineering improvements.
The role spans Palo Alto firewall and network security, Microsoft Defender endpoint and email security, data loss prevention (DLP), secure connectivity, and incident response. The engineer will work closely with Security Operations, Network Engineering, Infrastructure, the Service Desk, Compliance, Audit, vendors, and the Vulnerability Management team.
Responsibilities
Security Engineering and Platform Ownership
- Lead the implementation, integration, administration, optimization, and lifecycle improvement of assigned enterprise security platforms.
- Serve as the escalation point for complex configuration, interoperability, performance, and break/fix issues.
- Maintain secure baselines, configuration standards, technical procedures, and engineering runbooks.
- Evaluate proposed technical solutions against approved architecture, policies, risk requirements, and operational needs.
- Identify opportunities to automate work, improve control effectiveness, and reduce recurring support issues.
Palo Alto Firewall and Network Security
- Own advanced Palo Alto firewall troubleshooting, policy optimization, complex rule analysis, and implementation work.
- Create and manage firewall rules in Prisma and SCM.
- Support network segmentation, remote access, web filtering, and other network security improvements.
- Test, document, and implement changes through approved change-management processes.
Microsoft Defender, Email Security, and DLP
- Provide advanced engineering support and optimization for Microsoft Defender endpoint detection and response, email security, and DLP technologies.
- Resolve complex mail-flow, security policy, detection, enforcement, and platform integration issues.
- Turn analyst findings and recurring threats into improved controls, configurations, and detection tuning.
- Coordinate remediation and platform changes with infrastructure, messaging, network, application, and vendor teams.
Incident Response and Operational Improvement
- Co-lead technical containment and remediation for complex security incidents.
- Support cybersecurity analysts and escalations from the outsourced SOC.
- Implement approved containment, eradication, recovery, and hardening changes.
- Improve technical response procedures, detection integrations, and engineering runbooks.
- Support platform upgrades, migrations, major configuration changes, audit remediation, and control validation.
- Communicate technical issues clearly, including risk, business impact, recommendations, and status.
Required Experience and Skills
- At least 5 years of cybersecurity or information security experience, including at least 5 years of hands-on security engineering, security operations, or infrastructure security experience.
- Advanced administration and troubleshooting of Palo Alto firewalls and network security controls.
- Hands-on experience with Microsoft Defender endpoint security, email security, and DLP, including SIEM/XDR integrations and detection-supporting technologies.
- Experience leading complex security platform implementations, integrations, optimization, and troubleshooting.
- Incident response engineering experience, including technical containment, root cause analysis, remediation, and control validation.
- Experience with secure vendor connectivity and related controls, including SecureLink, certificates, SFTP/FTP, PGP, and SSH keys.
- Experience planning, testing, deploying, and supporting security platform changes, including rollback and operational readiness.
- Experience supporting an enterprise security program in a highly regulated environment.
- Ability to lead technical staff and coordinate cross-functional implementation or remediation workstreams.
- Strong documentation, change-management, vendor-coordination, and stakeholder communication skills.
Preferred Certifications
- CISSP, CISM, or a comparable senior security certification.
- Microsoft Security certification relevant to the assigned platforms.
- Palo Alto PCNSE or a comparable advanced network security certification.