Sr. IT Engineer (Security)
Job Summary
Position Summary
We are seeking a strategic and experienced Senior IT Security Engineer to lead our Security Operations Center (SOC) and drive our organizations cybersecurity excellence. You will play a critical leadership role in managing complex security incidents designing vulnerability management strategies overseeing security compliance frameworks and mentoring our security team. With 6-8 years of advanced hands-on security experience deep expertise in incident response and threat investigation proficiency with enterprise security platforms (Sophos Intercept X Windows Defender Proofpoint ManageEngine) and a demonstrated track record of building secure infrastructure you will help establish DataCore as a security leader. If you can think strategically about security architecture lead incident response investigations mentor junior analysts and drive compliance initiatives across SOC 2 Type II ISO 27001 and GDPR we want to hear from you!
Duties & Responsibilities
Strategic & Leadership Responsibilities:
- Lead the Security Operations Center (SOC) team mentor junior and mid-level analysts and establish best practices for incident response and threat detection
- Design and implement security monitoring strategies detection engineering capabilities and alert tuning frameworks across Sophos Proofpoint Windows Defender and ManageEngine
- Develop and maintain security policies procedures runbooks and playbooks for the organization; ensure alignment with SOC 2 Type II ISO 27001 GDPR and NIS2 requirements
- Conduct security risk assessments and threat modeling; recommend security architecture improvements and infrastructure hardening initiatives
- Serve as primary liaison with compliance teams; drive audit readiness activities and evidence collection for SOC 2 ISO 27001 and regulatory compliance programs
- Evaluate select and manage security tools and vendor relationships; conduct cost-benefit analysis and ROI assessments for new security solutions
- Lead incident response for complex multi-stage security incidents; perform advanced root cause analysis and develop strategic remediation plans
Operational & Technical Responsibilities:
- Monitor detect analyze and respond to security incidents and alerts from Sophos Intercept X Advanced Windows Defender Proofpoint and other security platforms with advanced investigation techniques
- Conduct comprehensive vulnerability assessments and security scans using ManageEngine; establish prioritization frameworks based on business context and threat landscape
- Investigate advanced threats malware incidents and suspected breaches; perform forensic analysis and produce detailed incident reports with executive summaries
- Manage email security at scale; develop and enforce email security policies investigate sophisticated phishing and BEC campaigns and implement email authentication standards (SPF DKIM DMARC)
- Perform threat hunting using MITRE ATT&CK framework; identify emerging threats and proactive security gaps before they are exploited
- Collect analyze and report security metrics KPIs and incident trends to management; design security dashboards and executive-level security briefings
- Support continuous improvement of security awareness and training programs; assess training effectiveness and adjust content based on threat landscape
Requirements
Essential Skills and Experience Required
- Bachelors degree in Computer Science Computer Engineering Cybersecurity or related field (or equivalent professional experience and demonstrated expertise)
- 6-8 years of hands-on experience in IT Security incident response or security operations.
- Advanced expertise in Security Operations Center (SOC) operations incident response management and threat investigation with demonstrated ability to lead complex investigations
- Expert-level knowledge of operating systems (Windows Server Linux) including security hardening OS-level threat detection and endpoint security architecture
- Advanced understanding of networking concepts (TCP/IP DNS firewalls VPN proxies) and network security architecture; ability to design secure network segmentation
- Deep understanding of attack vectors attack chains and the cyber kill chain; ability to map threats to MITRE ATT&CK framework and develop countermeasures
- Expert hands-on experience with Sophos Central Intercept X Advanced or similar advanced EDR (Endpoint Detection and Response) solutions; demonstrated ability to configure tune and leverage advanced EDR capabilities
- Expert experience with Windows Defender for Endpoint and/or other enterprise antivirus/anti-malware solutions at scale
- Expert-level knowledge of email security; deep experience with Proofpoint or similar enterprise email security platforms; proficiency in email authentication protocols (SPF DKIM DMARC BIMI)
- Expert-level experience with vulnerability scanning and management tools preferably ManageEngine; demonstrated ability to design vulnerability management programs prioritize remediation and track metrics
- Advanced expertise in SIEM tools and log analysis; proven ability to design SIEM architectures develop correlation rules and build security use cases
- Demonstrated expertise in compliance frameworks (SOC 2 Type II ISO 27001 GDPR NIS2); experience leading compliance assessments and audit preparations
- Expert-level analytical and problem-solving skills with ability to think strategically about security architecture and long-term security posture
- Exceptional communication skills; ability to present technical security findings to executive leadership and non-technical stakeholders; strong written and verbal communication
- Proven ability to mentor and develop junior security analysts; experience building and scaling security teams
- Leadership experience managing security incidents and coordinating response across multiple teams
Preferred Skills and Certifications
- Advanced security certifications such as CISSP (Certified Information Systems Security Professional)
- CompTIA Security or equivalent foundational certifications
- Advanced experience with threat intelligence platforms threat research and intelligence-driven security operations
- Advanced scripting skills (PowerShell Python Bash) for security automation SIEM rule development and workflow optimization
- Advanced cloud security expertise (Azure AWS); demonstrated ability to design and secure cloud infrastructure; knowledge of cloud-native threat detection
- Experience with SOAR (Security Orchestration Automation and Response) platforms and advanced automation of incident response workflows
- Incident response leadership; experience as incident commander or on incident response teams for critical incidents
- Security architecture and design expertise; experience building or redesigning security infrastructure
- Experience with GRC (Governance Risk Compliance) platforms and compliance automation
- Vendor management experience; track record of evaluating negotiating and managing security tool contracts
- Threat hunting expertise and experience with advanced threat hunting methodologies
Required Experience:
Senior IC
About Company
DataCore provides IT with advanced data storage technology to accelerate performance, increase efficiency, and achieve zero-downtime availability.