Overview
Skills
Job Details
Cyber Security Engineer IV
Duration: Long term will extend though the end of next year.
Location: Remote Eastern hours preferred
Interview Process: 2 rounds. 1st round with the manager. 2nd round with a panel.
Cybersecurity Engineer focused on vulnerability management, incident problem coordination, incident response, threat detection engineering
Team Part of the Cybersecurity Operations Center, responsible for managing cybersecurity incidents and operation enablement.
When new companies bought under the client umbrella - as onboarded through mergers and acquisitions they need to apply the same security standards
Needs someone who can support the onboarding process from end to end for Security Program work end to end. From scoping (understanding the company bought), figure out what process apply, work with engineers to talk through vulnerability management, standing up alerting, helping team set up alerting, working with Ops team to set up actual processes, work with intel team if there is brand monitoring, building out the cybersecurity incident response plan, etc.
Minimum 5 years of experience, ideally 5-7 years of experience
Tools: Databricks, Splunk, Power BI
- Cybersecurity Engineering background - less IT, more cybersecurity based
- Experience with Incident response highly preferred
- Previous SOC experience
- Threat detection engineering
- Incident response
- Incident problem coordination
- Mergers and acquisitions experience would be nice to have - a big nice to have
Day to Day: Weekly calls with GRC team and company coming in, conversations either weekly/bi-weekly having access to the tools, making updates as necessary; updating leadership, keeping up with trackers; manage dependencies; CSOC view point watch list integrations. High level risks that need to be called to leadership.
Official Job Description
Client is seeking a highly experienced and technically Proficient Engineer 5 to lead cybersecurity integration efforts for newly acquired organizations. This senior-level role is critical to maintaining client s security posture during mergers and acquisitions (M&A), ensuring seamless alignment with existing cybersecurity operations and standards.
Key Responsibilities:
- Cybersecurity Requirements Gathering: Lead the collection and documentation of CSOC s cybersecurity requirements for M&A activities with technical depth and accuracy.
- Vulnerability Management Integration: Oversee deployment of host agents and supplemental vulnerability scanners.
- Enable authenticated scanning and ensure scanner-target connectivity.
- Threat Intelligence Enablement: Identify and onboard new brands or domains for threat monitoring and reporting.
- Log Source Ingestion: Guide and track integration of critical log sources into the CSOC data lake, beyond CrowdStrike.
- Threat Detection Engineering: Support development of detection rules and engineering requirements for newly integrated systems.
- MSSP Migration Support: Assist in transitioning services to the client or implementing new requirements unique to the M&A.
- Ensure continuity and enhancement of alerting, detection, log onboarding, and automation capabilities.
- Incident Response & Playbook Development: Onboard contextual incident response processes.
- Update playbooks and processes in alignment with audit guidelines and CSOC standards.
- Maintain supplemental incident response plans as needed.
- Incident & Problem Management: Lead large-scale incident response efforts.
- Conduct After Action Reviews and implement Cyber Action Plans to prevent recurrence.
Qualifications:
- Proven experience in cybersecurity engineering, preferably in M&A environments.
- Deep understanding of vulnerability management, threat detection, and incident response.
- Strong technical knowledge of log ingestion, automation, and MSSP services.
- Excellent communication and leadership skills to coordinate across teams and stakeholders.
- Ability to manage complex integrations under tight timelines with a focus on risk mitigation.
Required Experience:
Cybersecurity Expertise:
- Minimum 10+ years of experience in cybersecurity engineering or operations.
- Proven track record in M&A cybersecurity integration, including vulnerability management, threat detection, and incident response.
- Hands-on experience with security tools and platforms such as CrowdStrike, SIEMs (e.g., Splunk, QRadar), vulnerability scanners (e.g., Qualys, Tenable), and threat intelligence platforms.
- Technical Skills:
- Strong understanding of network and endpoint security, log ingestion pipelines, and authenticated scanning.
- Experience with automation and orchestration tools (e.g., SOAR platforms) for incident response and phishing remediation.
- Familiarity with cloud environments (AWS, Azure, Google Cloud Platform) and hybrid infrastructure security.
- Ability to lead large-scale incident response and conduct After Action Reviews with follow-through on remediation plans.
- Leadership & Communication:
- Demonstrated ability to lead cross-functional teams, manage complex projects, and communicate effectively with technical and non-technical stakeholders.
- Experience in developing and maintaining playbooks, processes, and audit-compliant documentation.