it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

10 jobs found

Email me jobs like this
Refine Search
Current Search
lead detection engineer cyber defense response
Senior ML Engineer - Cyber Security
Altice USA
Are you looking to Optimize your life? Start your exciting path to a rewarding career today! We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities. If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you! Job Summary As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks. Responsibilities • Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization. • Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed. • Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses. • Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR). • Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases. • Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production. • Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation. • Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations. • Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams. • Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments. • Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements. • Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness. • Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness. • Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC. Qualifications • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience • 7+ years of combined experience across security operations, incident response, and software engineering • Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered • Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing • Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks • Experience with SOAR/automation and detection engineering (detection-as-code) • Data engineering skills, including working with large security datasets, APIs, and pipelines • Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL • Cloud security and cloud-platform experience • Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10 • Ability to translate fluently between security and engineering stakeholders. Preferred Qualifications • MLOps experience deploying and maintaining models in production • Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops. If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity. All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company's discretion based on business necessity. We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law. The Company collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state and local law. Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details. Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100,246.00 - $164,689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity. We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time, we do not provide visa sponsorship for employment.
09/26/2026
Full time
Are you looking to Optimize your life? Start your exciting path to a rewarding career today! We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities. If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you! Job Summary As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks. Responsibilities • Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization. • Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed. • Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses. • Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR). • Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases. • Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production. • Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation. • Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations. • Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams. • Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments. • Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements. • Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness. • Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness. • Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC. Qualifications • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience • 7+ years of combined experience across security operations, incident response, and software engineering • Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered • Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing • Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks • Experience with SOAR/automation and detection engineering (detection-as-code) • Data engineering skills, including working with large security datasets, APIs, and pipelines • Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL • Cloud security and cloud-platform experience • Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10 • Ability to translate fluently between security and engineering stakeholders. Preferred Qualifications • MLOps experience deploying and maintaining models in production • Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops. If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity. All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company's discretion based on business necessity. We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law. The Company collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state and local law. Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details. Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100,246.00 - $164,689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity. We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time, we do not provide visa sponsorship for employment.
Senior ML Engineer - Cyber Security
Altice USA Norwalk, Connecticut
Are you looking to Optimize your life? Start your exciting path to a rewarding career today! We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities. If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you! Job Summary As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks. Responsibilities • Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization. • Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed. • Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses. • Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR). • Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases. • Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production. • Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation. • Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations. • Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams. • Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments. • Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements. • Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness. • Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness. • Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC. Qualifications • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience • 7+ years of combined experience across security operations, incident response, and software engineering • Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered • Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing • Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks • Experience with SOAR/automation and detection engineering (detection-as-code) • Data engineering skills, including working with large security datasets, APIs, and pipelines • Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL • Cloud security and cloud-platform experience • Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10 • Ability to translate fluently between security and engineering stakeholders. Preferred Qualifications • MLOps experience deploying and maintaining models in production • Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops. If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity. All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company's discretion based on business necessity. We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law. The Company collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state and local law. Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details. Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100,246.00 - $164,689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity. We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time, we do not provide visa sponsorship for employment.
09/26/2026
Full time
Are you looking to Optimize your life? Start your exciting path to a rewarding career today! We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities. If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you! Job Summary As a Senior SOC Engineer (AI & Automation), you will design, build, and operate the AI, automation, and detection-engineering capabilities that power our Security Operations Center. Bridging security operations and software engineering, you will develop AI-driven detection, triage, and response tooling, integrate large language model (LLM) and agentic workflows into analyst operations, and ensure those capabilities are accurate, safe, measurable, and continuously improved. As a senior member of the team, you will also serve as a technical leader during major security incidents, leading investigations and turning lessons learned into stronger detections, automations, and playbooks. Responsibilities • Design, build, and maintain AI/ML- and automation-driven capabilities for alert enrichment, correlation, summarization, triage, and prioritization. • Develop and maintain SOAR automations and detection-as-code pipelines that are version-controlled, tested, and peer-reviewed. • Integrate LLM and agentic AI tooling into SOC workflows (copilots, auto-triage agents); engineer prompts, guardrails, and evaluation harnesses. • Evaluate, benchmark, and tune AI models and tools for security use cases, measuring precision and recall, false-positive reduction, and impact on mean time to detect and respond (MTTD/MTTR). • Build data pipelines and feature engineering from security telemetry to support detection and machine-learning use cases. • Apply MLOps practices, including model versioning, monitoring, drift detection, and retraining, to security models running in production. • Ensure responsible and secure AI use, including data governance, prompt-injection and model-abuse defenses, privacy, and output validation. • Partner with detection engineers, SOC analysts, and incident responders to operationalize tooling and feed lessons learned back into models and automations. • Serve as a senior escalation point and incident commander for complex and major incidents, coordinating cross-functional response and directing technical workstreams. • Lead investigations and forensic analysis for escalated incidents and provide hands-on incident response support across on-premises and cloud environments. • Own post-incident reviews and root cause analyses, translating lessons learned into new detections, automations, and playbook improvements. • Develop, run, and mature incident-response playbooks and tabletop exercises (TTX) to validate and improve organizational readiness. • Define and report detection and incident-response metrics (e.g., MTTD, MTTR) to measure and continuously improve SOC effectiveness. • Mentor analysts and engineers, fostering a culture of continuous learning across AI-augmented and incident-response workflows, and promote an AI-first operating model across the SOC. Qualifications • Bachelor's degree in Computer Science, Engineering, or related field, or equivalent years of experience • 7+ years of combined experience across security operations, incident response, and software engineering • Hands-on incident response and digital forensics experience, including leading or coordinating response to complex and major incidents preffered • Strong programming skills (e.g., Python) and sound software-engineering practices, including version control, CI/CD, and automated testing • Hands-on experience building with AI/ML, including large language models, prompt engineering, retrieval-augmented generation (RAG), and/or agentic frameworks • Experience with SOAR/automation and detection engineering (detection-as-code) • Data engineering skills, including working with large security datasets, APIs, and pipelines • Working knowledge of SOC operations and the incident lifecycle, including the MITRE ATT&CK framework, the NIST incident response lifecycle (NIST SP 800-61), the Cyber Kill Chain, and SANS PICERL • Cloud security and cloud-platform experience • Awareness of AI and LLM security risks, such as prompt injection and the OWASP LLM Top 10 • Ability to translate fluently between security and engineering stakeholders. Preferred Qualifications • MLOps experience deploying and maintaining models in production • Relevant security and/or AI/ML certifications, including incident-response and forensics credentials (e.g., GCIH, GCFA, GCFE, GNFA) or CISSP/CISM At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What's Right, Drive One Optimum, and Make It Happen. These aren't just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It's all part of the bigger picture of "Be The Difference" where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops. If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity. All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company's discretion based on business necessity. We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law. The Company collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state and local law. Applicants for employment with The Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details. Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $100,246.00 - $164,689.00 / year. The rate/range provided herein is the anticipated pay at the time of hire, and does not reflect future job opportunity. We appreciate your interest in this opportunity. Applicants must be authorized to work for ANY employer in the U.S. Please note that at this time, we do not provide visa sponsorship for employment.
Senior Threat Hunter
Brown Brothers Harriman Boston, Massachusetts
At BBH, Partnership is more than a form of ownership-it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what's next, this is the right place to build a fulfilling career. Job Description As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization's ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies. You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization's detection and response capabilities. Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have strong hands-on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements. Duties and Responsibilities Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree Strong SOC experience investigating security alerts, performing incident response, and log analysis Hands-on experience working with SIEM, EDR, and other enterprise security monitoring tools Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis Excellent collaboration and communication skills, particularly in high-stress situations Ability to produce clear technical and operational reporting for both technical teams and leadership Strong analytical skills and priority management Nice to Have Master's degree in Cybersecurity, Computer Science, Information Technology, or related field Hands-on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF) Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate Salary Range NJ & MA: $110,000 to $160,000 base salary + annual bonus target BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being. We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply. About BBH: Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development-so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice-creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often-pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours. Go to to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially. . click apply for full job details
09/26/2026
Full time
At BBH, Partnership is more than a form of ownership-it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what's next, this is the right place to build a fulfilling career. Job Description As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization's ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies. You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization's detection and response capabilities. Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have strong hands-on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements. Duties and Responsibilities Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree Strong SOC experience investigating security alerts, performing incident response, and log analysis Hands-on experience working with SIEM, EDR, and other enterprise security monitoring tools Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis Excellent collaboration and communication skills, particularly in high-stress situations Ability to produce clear technical and operational reporting for both technical teams and leadership Strong analytical skills and priority management Nice to Have Master's degree in Cybersecurity, Computer Science, Information Technology, or related field Hands-on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF) Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate Salary Range NJ & MA: $110,000 to $160,000 base salary + annual bonus target BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being. We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply. About BBH: Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development-so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice-creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often-pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours. Go to to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially. . click apply for full job details
Senior Threat Hunter
Brown Brothers Harriman Philadelphia, Pennsylvania
At BBH, Partnership is more than a form of ownership-it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what's next, this is the right place to build a fulfilling career. Job Description As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization's ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies. You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization's detection and response capabilities. Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have strong hands-on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements. Duties and Responsibilities Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree Strong SOC experience investigating security alerts, performing incident response, and log analysis Hands-on experience working with SIEM, EDR, and other enterprise security monitoring tools Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis Excellent collaboration and communication skills, particularly in high-stress situations Ability to produce clear technical and operational reporting for both technical teams and leadership Strong analytical skills and priority management Nice to Have Master's degree in Cybersecurity, Computer Science, Information Technology, or related field Hands-on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF) Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate Salary Range NJ & MA: $110,000 to $160,000 base salary + annual bonus target BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being. We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply. About BBH: Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development-so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice-creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often-pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours. Go to to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially. . click apply for full job details
09/26/2026
Full time
At BBH, Partnership is more than a form of ownership-it's our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what's next, this is the right place to build a fulfilling career. Job Description As a Senior Threat Hunter within our Cyber Threat Monitoring Team, you will play a critical role in strengthening the organization's ability to proactively identify, investigate, and respond to advanced cyber threats. This role emphasizes technical threat hunting, advanced SOC investigations, incident response escalation support, and intelligence-driven detection improvement, while leveraging Cyber Threat Intelligence (CTI) to guide proactive defense strategies. You will serve as a senior escalation resource for complex and high-priority investigations, proactively hunt for adversary activity across enterprise security telemetry, and work closely with SOC analysts, detection engineers, incident response partners, and security leadership to improve the organization's detection and response capabilities. Collaborating with cross-functional teams and organizational leaders, you will help develop and mature threat hunting, detection, and response capabilities that protect our networks, systems, data, employees, and clients. The ideal candidate will have strong hands-on SOC or incident response experience, an analytical mindset, a passion for continuous learning, and the ability to translate threat intelligence and investigative findings into actionable detection and response improvements. Duties and Responsibilities Lead and support advanced SOC investigations, incident response activities, and Tier-3 escalations, providing deep technical analysis of security alerts, anomalous behavior, and suspected malicious activity Perform proactive threat hunting activities across enterprise security telemetry including SIEM, EDR, identity, network, and cloud logs to identify previously undetected or emerging threats Analyze attacker behaviors and intrusion patterns to develop threat hunting hypotheses and detection strategies aligned with the MITRE ATT&CK framework Investigate complex security alerts and incidents, performing log analysis, endpoint analysis, and timeline reconstruction to determine root cause, scope, and impact Leverage internal telemetry, alerts, and IOC trends to identify threat patterns targeting the organization and opportunities for improved detection coverage Enhance threat detection and response capabilities by supporting the development and improvement of SOC detection logic, response procedures, escalation playbooks, and analyst decision trees Conduct proactive analysis of alert trends to identify gaps in detection coverage and recommend new or improved monitoring capabilities Utilize Cyber Threat Intelligence (CTI) sources to contextualize incidents, inform threat hunting efforts, and prioritize investigations Monitor open-source, closed-source, and vendor-provided threat intelligence to stay abreast of emerging threats, vulnerabilities, and adversary tactics relevant to the organization Develop and maintain profiles of relevant threat actors, including tactics, techniques, and procedures (TTPs), and incorporate those insights into threat hunting and detection strategies Assist in SOC and Incident Response escalations, providing technical expertise and investigative support during security incidents Conduct threat, risk, and vulnerability assessments to provide actionable remediation and security control improvement guidance Collaborate with the Red Team and Cyber Incident Management to support red team exercises, incident response training, tabletop exercises, and detection validation Perform targeted access reviews and anomaly analysis across enterprise systems (Windows, Linux, databases, network infrastructure, cloud platforms) to identify suspicious activity Collaborate with DLP and other security teams on insider risk investigations and monitoring initiatives Contribute to the development and improvement of SOC procedures, threat hunting methodologies, and intelligence-driven detection processes Collaborate with relevant stakeholders on security awareness messaging and threat awareness related communications Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field 5+ years of experience in Security Operations, Incident Response, Threat Hunting, Detection Engineering, and/or related cybersecurity roles Significant relevant experience (e.g., military cyber operations) may be considered in lieu of a degree Strong SOC experience investigating security alerts, performing incident response, and log analysis Hands-on experience working with SIEM, EDR, and other enterprise security monitoring tools Familiarity with the MITRE ATT&CK Framework and attacker TTP analysis Excellent collaboration and communication skills, particularly in high-stress situations Ability to produce clear technical and operational reporting for both technical teams and leadership Strong analytical skills and priority management Nice to Have Master's degree in Cybersecurity, Computer Science, Information Technology, or related field Hands-on experience in two or more of the following areas: Threat Hunting, Security Operations, Incident Response, Detection Engineering, Cyber Threat Intelligence, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Network Security Management, Cyber Risk Management, Cloud Security, Vulnerability Management, Malware Analysis Experience in the financial services sector and familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NYDFS, FFIEC, NIST CSF, ISO 27001, SWIFT CSF) Experience developing detection logic and threat hunting queries using Splunk SPL, Microsoft KQL, or similar query languages Experience with endpoint, identity, and network monitoring technologies such as EDR, IDS/IPS, Firewalls, WAF, DLP, UEBA, email security gateways, and sandboxing technologies Experience with Microsoft Sentinel and Defender (MDE, MDI, Defender for Cloud Apps) as well as other Microsoft security ecosystem tools Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GSEC, GCTI, CTIA, Security+, Microsoft Security Operations Analyst Associate Salary Range NJ & MA: $110,000 to $160,000 base salary + annual bonus target BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being. We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply. About BBH: Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development-so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice-creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often-pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours. Go to to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially. . click apply for full job details
Senior Technical Leader - Systems Security Engineering
GE Aerospace Grand Rapids, Michigan
Job Description Summary Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. The Advanced Technology Organization (ATO) - Emerging Technologies Team focuses on early-stage pursuits and new technology introduction (NTI) in the areas of sensing, autonomy, artificial intelligence (AI)/machine learning (ML), cybersecurity, and advanced edge hardware. This role requires collaborating within a highly diverse technical team and directly interfacing with the business facing team and product managers to develop a technology strategy aligned with emerging market opportunities. The ATO Systems Security Engineering Technical Leader is expected to provide technical prowess, strategic collaboration, and visionary leadership to the technical team. The ATO Emerging Technologies Team is enabling mission management and multi-domain operations at the edge and is looking for a Technical Leader that can provide a holistic understanding of cybersecurity and electromagnetic spectrum operations (EMSO) strategies to provide a robust mission capability. Working closely with peers in the Emerging Technologies Team as well as product managers and key stakeholders across the ATO and Avionics organization, this individual will facilitate in bringing the strategic vision to reality and provide technical expertise in edge systems security engineering, emerging cybersecurity threats, and EMSO. Job Description Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. Essential Responsibilities: More specifically, the individual will: Provide expertise in systems security engineering, particularly for edge devices and embedded platforms. Provide expertise in attack techniques, common and emerging threats, and develop defensive mitigation strategies at the logical and physical component level. Provide expertise in electronic warfare for RF spectrum dominance such as wireless communication, radar, and GPS-denied environments. Understand and apply industry standards and methodologies such as the Risk Management Framework (RMF). Security certifications such as Certified Embedded & Device Security Engineer (CEDSE). CISSP, Security+, Certified Ethical Hacker (CEH) or equivalent as per the DoD Directive 8140 or current DoD 8570 guidelines. Design, develop, and implement cybersecurity solutions in complex heterogeneous compute systems. Knowledge of low-level firmware and real-time software for embedded systems, including hardware-software integration, interfacing, and performance optimization. Develop quantitative risk assessments and analyze cybersecurity vulnerabilities. Support early-stage pursuit and capture strategies including customer engagement, defining/shaping requirements, proposal writing, and writing white papers. Collaborate directly with diverse technical teams, business teams, and product managers to co-develop a strategy that facilitates the transition of new technology into the Avionics product portfolio. Collaborate with subject matter experts (SMEs) and engineers to provide complete and holistic solutions to unique and dynamic customer requirements. Introduce and network with members of the customer community with GE's strategic leaders and sales representatives. Maintain a mindset of continuous learning, and be open to changing technical approaches as state-of-the-art technologies evolve. Develop transition plans such that new technologies developed have a clear path towards successfully fulfilling mission requirements and a continued plan for maturity and productization. Qualifications/Requirements: Bachelor's degree in Engineering, Physics, Mathematics, Computer Science, or related field from an accredited university or college (additional relevant work experience may qualify in lieu of degree). Minimum of 10 years of related experience in systems security engineering, threat intelligence and response, vulnerability assessment, and electronic attacks. Excellent communication, presentation, and technical writing skills tailored to broad variety of audiences. Willingness to travel ( 25%). This position requires U.S. citizenship status. The ability to obtain US Security Clearance. Desired Characteristics: Master's degree or Ph.D. in Engineering, Physics, Mathematics, Computer Science, or related field from an accredited university or college. Active U.S. Security Clearance. Knowledge of ISR, SIGINT, MASINT, and ELINT. Experience modeling, simulating, and analyzing emerging threats. Experience with scripting languages and modeling tools (e.g., Python, MATLAB, C/C++, AFSIM). Experience with intrusion detection, protection, and mitigation techniques. Knowledge of electronic attack methodologies such as signal spoofing and jamming, and associated mitigation strategies. Knowledge of attacks on machine learning algorithms and autonomous systems, and associated mitigation strategies. Knowledge of system engineering concepts and best practices Knowledge of digital signal processing (DSP), sensor deployment, and data acquisition. Proven track record of transitioning applied research to fieldable platforms. Experience applying the latest advancements in AI/ML to increase cyber resiliency. Strategic experience working through early-stage pursuits and customer engagement. Experience with aviation and defense products. Experience in project leadership and execution. Experience working with U.S. Government Sponsors. Experience working on research and development programs and developing rapid-reaction prototypes. Demonstrated capability to constructively partner and drive alignment across matrixed organization. Knowledge of avionics interfaces, military standards, and open architecture standards. The base pay range for this position is $167,000.00 - $223,000.00. The specific pay offered may be influenced by a variety of factors, including the candidate's experience, education, and skill set. This position is also eligible for an annual discretionary bonus based on a percentage of your base salary/ commission based on the plan. This posting is expected to close on 10/31/26. GE Aerospace offers comprehensive benefits and programs to support your health and, along with programs like HealthAhead, your physical, emotional, financial and social wellbeing. Healthcare benefits include medical, dental, vision, and prescription drug coverage; access to a Health Coach from GE Aerospace; and the Employee Assistance Program, which provides 24/7 confidential assessment, counseling and referral services. Retirement benefits include the GE Aerospace Retirement Savings Plan, a 401(k) savings plan with company matching contributions and company retirement contributions, as well as access to Fidelity resources and planning consultants. Other benefits include tuition assistance, adoption assistance, paid parental leave, disability insurance, life insurance, and paid time-off for vacation or illness. GE Aerospace (General Electric Company or the Company) and its affiliates each sponsor certain employee benefit plans or programs (i.e., is a "Sponsor"). Each Sponsor reserves the right to terminate, amend, suspend, replace or modify its benefit plans and programs at any time and for any reason, in its sole discretion. No individual has a vested right to any benefit under a Sponsor's welfare benefit plan or program. This document does not create a contract of employment with any individual. Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. This role requires access to U.S. export-controlled information. Therefore, employment will be contingent upon the ability to prove that you meet the status of a U.S. Person as one of the following: U.S. lawful permanent resident, U.S. Citizen, have been granted asylee or refugee status (i.e., a protected individual under the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3 . Additional Information GE Aerospace offers a great work environment, professional development, challenging careers, and competitive compensation. GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law. GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable). Employees may also be subject to random and reasonable-suspicion drug and alcohol testing. Relocation Assistance Provided: Yes
09/26/2026
Full time
Job Description Summary Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. The Advanced Technology Organization (ATO) - Emerging Technologies Team focuses on early-stage pursuits and new technology introduction (NTI) in the areas of sensing, autonomy, artificial intelligence (AI)/machine learning (ML), cybersecurity, and advanced edge hardware. This role requires collaborating within a highly diverse technical team and directly interfacing with the business facing team and product managers to develop a technology strategy aligned with emerging market opportunities. The ATO Systems Security Engineering Technical Leader is expected to provide technical prowess, strategic collaboration, and visionary leadership to the technical team. The ATO Emerging Technologies Team is enabling mission management and multi-domain operations at the edge and is looking for a Technical Leader that can provide a holistic understanding of cybersecurity and electromagnetic spectrum operations (EMSO) strategies to provide a robust mission capability. Working closely with peers in the Emerging Technologies Team as well as product managers and key stakeholders across the ATO and Avionics organization, this individual will facilitate in bringing the strategic vision to reality and provide technical expertise in edge systems security engineering, emerging cybersecurity threats, and EMSO. Job Description Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. Essential Responsibilities: More specifically, the individual will: Provide expertise in systems security engineering, particularly for edge devices and embedded platforms. Provide expertise in attack techniques, common and emerging threats, and develop defensive mitigation strategies at the logical and physical component level. Provide expertise in electronic warfare for RF spectrum dominance such as wireless communication, radar, and GPS-denied environments. Understand and apply industry standards and methodologies such as the Risk Management Framework (RMF). Security certifications such as Certified Embedded & Device Security Engineer (CEDSE). CISSP, Security+, Certified Ethical Hacker (CEH) or equivalent as per the DoD Directive 8140 or current DoD 8570 guidelines. Design, develop, and implement cybersecurity solutions in complex heterogeneous compute systems. Knowledge of low-level firmware and real-time software for embedded systems, including hardware-software integration, interfacing, and performance optimization. Develop quantitative risk assessments and analyze cybersecurity vulnerabilities. Support early-stage pursuit and capture strategies including customer engagement, defining/shaping requirements, proposal writing, and writing white papers. Collaborate directly with diverse technical teams, business teams, and product managers to co-develop a strategy that facilitates the transition of new technology into the Avionics product portfolio. Collaborate with subject matter experts (SMEs) and engineers to provide complete and holistic solutions to unique and dynamic customer requirements. Introduce and network with members of the customer community with GE's strategic leaders and sales representatives. Maintain a mindset of continuous learning, and be open to changing technical approaches as state-of-the-art technologies evolve. Develop transition plans such that new technologies developed have a clear path towards successfully fulfilling mission requirements and a continued plan for maturity and productization. Qualifications/Requirements: Bachelor's degree in Engineering, Physics, Mathematics, Computer Science, or related field from an accredited university or college (additional relevant work experience may qualify in lieu of degree). Minimum of 10 years of related experience in systems security engineering, threat intelligence and response, vulnerability assessment, and electronic attacks. Excellent communication, presentation, and technical writing skills tailored to broad variety of audiences. Willingness to travel ( 25%). This position requires U.S. citizenship status. The ability to obtain US Security Clearance. Desired Characteristics: Master's degree or Ph.D. in Engineering, Physics, Mathematics, Computer Science, or related field from an accredited university or college. Active U.S. Security Clearance. Knowledge of ISR, SIGINT, MASINT, and ELINT. Experience modeling, simulating, and analyzing emerging threats. Experience with scripting languages and modeling tools (e.g., Python, MATLAB, C/C++, AFSIM). Experience with intrusion detection, protection, and mitigation techniques. Knowledge of electronic attack methodologies such as signal spoofing and jamming, and associated mitigation strategies. Knowledge of attacks on machine learning algorithms and autonomous systems, and associated mitigation strategies. Knowledge of system engineering concepts and best practices Knowledge of digital signal processing (DSP), sensor deployment, and data acquisition. Proven track record of transitioning applied research to fieldable platforms. Experience applying the latest advancements in AI/ML to increase cyber resiliency. Strategic experience working through early-stage pursuits and customer engagement. Experience with aviation and defense products. Experience in project leadership and execution. Experience working with U.S. Government Sponsors. Experience working on research and development programs and developing rapid-reaction prototypes. Demonstrated capability to constructively partner and drive alignment across matrixed organization. Knowledge of avionics interfaces, military standards, and open architecture standards. The base pay range for this position is $167,000.00 - $223,000.00. The specific pay offered may be influenced by a variety of factors, including the candidate's experience, education, and skill set. This position is also eligible for an annual discretionary bonus based on a percentage of your base salary/ commission based on the plan. This posting is expected to close on 10/31/26. GE Aerospace offers comprehensive benefits and programs to support your health and, along with programs like HealthAhead, your physical, emotional, financial and social wellbeing. Healthcare benefits include medical, dental, vision, and prescription drug coverage; access to a Health Coach from GE Aerospace; and the Employee Assistance Program, which provides 24/7 confidential assessment, counseling and referral services. Retirement benefits include the GE Aerospace Retirement Savings Plan, a 401(k) savings plan with company matching contributions and company retirement contributions, as well as access to Fidelity resources and planning consultants. Other benefits include tuition assistance, adoption assistance, paid parental leave, disability insurance, life insurance, and paid time-off for vacation or illness. GE Aerospace (General Electric Company or the Company) and its affiliates each sponsor certain employee benefit plans or programs (i.e., is a "Sponsor"). Each Sponsor reserves the right to terminate, amend, suspend, replace or modify its benefit plans and programs at any time and for any reason, in its sole discretion. No individual has a vested right to any benefit under a Sponsor's welfare benefit plan or program. This document does not create a contract of employment with any individual. Onsite role in Grand Rapids, MI - candidates must be local or willing to relocate; remote is not an option. This role requires access to U.S. export-controlled information. Therefore, employment will be contingent upon the ability to prove that you meet the status of a U.S. Person as one of the following: U.S. lawful permanent resident, U.S. Citizen, have been granted asylee or refugee status (i.e., a protected individual under the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3 . Additional Information GE Aerospace offers a great work environment, professional development, challenging careers, and competitive compensation. GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law. GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable). Employees may also be subject to random and reasonable-suspicion drug and alcohol testing. Relocation Assistance Provided: Yes
Cyber Security Engineer
Neros Technologies Torrance, California
Who we are Neros is a defense technology company rebuilding America's drone industrial base. We design and manufacture high-performance unmanned systems that are tested in combat, iterated at startup speed, and built at massive scale. Our team culture is fast, hands-on, and obsessed with closing the gap between design and deployment. As drones transform the character of warfare, Neros is delivering the systems the West needs to compete on the modern battlefield and deter the adversaries of democracy. We're hiring engineers, operators, and builders who want to move fast, take on extreme ownership, and get capability into the hands of warfighters in months, not years. What you will be doing Join Neros as a Senior Cybersecurity Engineer and take ownership of the security program that protects our defense technology platforms. You'll build and mature our cybersecurity capabilities from the ground up - architecting detection and response systems, engineering security controls across cloud and endpoint environments, and ensuring compliance with NIST, ISO, and CIS frameworks. This is a high-impact, hands-on role at a fast-moving defense tech startup for a security professional who thrives as both architect and operator. Responsibilities Build and operationalize the enterprise cybersecurity program, owning security architecture, detection and response, governance, and automation Engineer and manage the security technology stack including Microsoft Defender XDR, endpoint protection platforms, SIEM/MDR solutions, and Azure/M365 security controls Lead incident response operations - containment, investigation, remediation - and coordinate with leadership and stakeholders on findings and risk posture Perform security audits, vulnerability assessments, and penetration testing to identify and remediate weaknesses across infrastructure, applications, and cloud environments Develop and enforce security policies, procedures, and compliance programs aligned to NIST 800-171 and ITAR controls. Automate security workflows and build detection logic to improve alert fidelity, operational efficiency, and coverage across the environment Establish change control processes, security baselines, and security awareness training programs You should have the following 8+ years of progressive experience in cybersecurity engineering, with demonstrated ability to build and operate security programs - not just maintain existing ones Deep hands-on expertise with the Microsoft security ecosystem including Defender XDR (Endpoint, M365, Identity, Cloud Apps), Entra ID Protection, and Azure/M365 security controls Proven experience deploying and managing MDR/SIEM solutions for 24/7 threat monitoring and SOC operations (e.g., Rapid7, Secureworks Taegis XDR, or equivalent) Strong background in incident response - containment, investigation, remediation, forensic preservation, and stakeholder communication Working knowledge of compliance frameworks including NIST 800-171, NIST CSF, CIS benchmarks, and PCI DSS, with hands-on experience performing audits and control assessments Experience conducting vulnerability assessments and penetration testing across infrastructure, applications, and cloud environments Proficiency with endpoint protection platforms, Microsoft security baseline configuration, and change control programs Demonstrated ability to automate security workflows using AI-assisted tooling, XDR automation, or scripting Strong communication skills - able to translate security risks and technical findings for non-technical leadership and cross-functional teams Relevant certifications preferred: MCSA, CISSP (in progress acceptable), CompTIA Security+/CySA+, or equivalent Nice to have Experience building a cybersecurity program from scratch at a startup or early-stage company Familiarity with ISO standards, 27001 in particular Familiarity with network segmentation tools (e.g., Illumio) and next-gen firewall administration (Palo Alto, Zscaler) Experience with security awareness platforms (KnowBe4 or equivalent) and phishing simulation programs Background in systems administration (Active Directory, Citrix, SCCM, Intune) providing depth of understanding of the environments being secured Experience with Tenable.ot or OT security in operational technology environments CISSP, SANS GIAC, or advanced Microsoft security certifications Eligibility or willingness to obtain a security clearance for potential future classified work US Salary Range $98,000 - $137,500 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are considered part of Neros' total compensation package. We're an equal opportunity employer. We welcome all applicants without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
09/25/2026
Full time
Who we are Neros is a defense technology company rebuilding America's drone industrial base. We design and manufacture high-performance unmanned systems that are tested in combat, iterated at startup speed, and built at massive scale. Our team culture is fast, hands-on, and obsessed with closing the gap between design and deployment. As drones transform the character of warfare, Neros is delivering the systems the West needs to compete on the modern battlefield and deter the adversaries of democracy. We're hiring engineers, operators, and builders who want to move fast, take on extreme ownership, and get capability into the hands of warfighters in months, not years. What you will be doing Join Neros as a Senior Cybersecurity Engineer and take ownership of the security program that protects our defense technology platforms. You'll build and mature our cybersecurity capabilities from the ground up - architecting detection and response systems, engineering security controls across cloud and endpoint environments, and ensuring compliance with NIST, ISO, and CIS frameworks. This is a high-impact, hands-on role at a fast-moving defense tech startup for a security professional who thrives as both architect and operator. Responsibilities Build and operationalize the enterprise cybersecurity program, owning security architecture, detection and response, governance, and automation Engineer and manage the security technology stack including Microsoft Defender XDR, endpoint protection platforms, SIEM/MDR solutions, and Azure/M365 security controls Lead incident response operations - containment, investigation, remediation - and coordinate with leadership and stakeholders on findings and risk posture Perform security audits, vulnerability assessments, and penetration testing to identify and remediate weaknesses across infrastructure, applications, and cloud environments Develop and enforce security policies, procedures, and compliance programs aligned to NIST 800-171 and ITAR controls. Automate security workflows and build detection logic to improve alert fidelity, operational efficiency, and coverage across the environment Establish change control processes, security baselines, and security awareness training programs You should have the following 8+ years of progressive experience in cybersecurity engineering, with demonstrated ability to build and operate security programs - not just maintain existing ones Deep hands-on expertise with the Microsoft security ecosystem including Defender XDR (Endpoint, M365, Identity, Cloud Apps), Entra ID Protection, and Azure/M365 security controls Proven experience deploying and managing MDR/SIEM solutions for 24/7 threat monitoring and SOC operations (e.g., Rapid7, Secureworks Taegis XDR, or equivalent) Strong background in incident response - containment, investigation, remediation, forensic preservation, and stakeholder communication Working knowledge of compliance frameworks including NIST 800-171, NIST CSF, CIS benchmarks, and PCI DSS, with hands-on experience performing audits and control assessments Experience conducting vulnerability assessments and penetration testing across infrastructure, applications, and cloud environments Proficiency with endpoint protection platforms, Microsoft security baseline configuration, and change control programs Demonstrated ability to automate security workflows using AI-assisted tooling, XDR automation, or scripting Strong communication skills - able to translate security risks and technical findings for non-technical leadership and cross-functional teams Relevant certifications preferred: MCSA, CISSP (in progress acceptable), CompTIA Security+/CySA+, or equivalent Nice to have Experience building a cybersecurity program from scratch at a startup or early-stage company Familiarity with ISO standards, 27001 in particular Familiarity with network segmentation tools (e.g., Illumio) and next-gen firewall administration (Palo Alto, Zscaler) Experience with security awareness platforms (KnowBe4 or equivalent) and phishing simulation programs Background in systems administration (Active Directory, Citrix, SCCM, Intune) providing depth of understanding of the environments being secured Experience with Tenable.ot or OT security in operational technology environments CISSP, SANS GIAC, or advanced Microsoft security certifications Eligibility or willingness to obtain a security clearance for potential future classified work US Salary Range $98,000 - $137,500 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are considered part of Neros' total compensation package. We're an equal opportunity employer. We welcome all applicants without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Security Response Engineer, Cyber Defense
Nscale San Francisco, California
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
09/23/2026
Full time
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
Security Response Engineer, Cyber Defense
Nscale New York, New York
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
09/23/2026
Full time
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
Security Response Engineer, Cyber Defense
Nscale Seattle, Washington
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
09/23/2026
Full time
About Nscale Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future. About the Role We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments. Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue. If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate. How this function works Read this section carefully. It is not a standard SOC, and the difference is the whole point. You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached. Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both. Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time. Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this. Follow-the-sun across hubs. Nobody works permanent nights. What you'll be doing Escalation response Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days Independently own escalations across common classes, with defensible dispositions and evidence that stands up. Ship your first solve: an engineering artifact that permanently retires a recurring alert class. Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. Review the managed provider's case quality against our standard and raise the first reconciliation findings. Judge and promote your first shadow detections to live. Take part in a threat hunt, tabletop, or recovery exercise. Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs Share of escalations permanently solved Quality and defensibility of security dispositions and evidence Containment judgement and response effectiveness Quality and actionability of engineering artifacts Managed provider quality and reconciliation About You 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. Sound judgement on containment under time pressure, including knowing where your authority ends. You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. Calm and methodical when facts are incomplete or contradict each other. Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. Detection testing, shadow-rule validation, threat hunting, or forensic readiness. Follow-the-sun, shift-based, or on-call operations. Certifications are useful, but not required. How we will assess An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why. The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked. Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build. Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it. Writing. We may ask for a redacted investigation write-up or escalation note. Where this leads Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in. This role may not be a fit if you: Want a queue to work through. There is not one. Measure success in tickets closed. Close cases without a security disposition or evidence. Forward vendor alerts without validating them. Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one. What we can offer you At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core. Highly competitive US compensation package (base + bonus + equity) . click apply for full job details
Cybersecurity Engineer - Network & Cloud Security
Delta Defense West Bend, Wisconsin
Delta Defense seeks a Cybersecurity Engineer to safeguard critical systems, data, and customer information supporting USCCA's nationwide membership platform. In this role, you will design and maintain secure network and cloud architectures, administer security tools, and lead monitoring, incident response, and vulnerability management efforts. You'll collaborate closely with IT, software, and business teams to embed security by design, refine policies, and support audits. Join a fast-growing, mission-driven organization where your expertise directly protects responsible gun owners and advances a values-driven, high-performance culture. Responsibilities Design, implement, and maintain secure network and cloud architectures to protect USCCA systems and data Monitor security events, investigate alerts, and respond to incidents to minimize risk and downtime Conduct vulnerability assessments, penetration testing, and remediation planning across applications and infrastructure Develop and maintain security policies, standards, and procedures aligned with regulatory and industry best practices Collaborate with engineering and IT teams to embed security into software development and deployment processes Manage security tools including SIEM, EDR, firewalls, IDS/IPS, and identity and access management platforms Perform security risk assessments on new technologies, vendors, and business initiatives Lead security awareness efforts, coaching teams on secure behavior and incident reporting Support audit, compliance, and documentation requirements for internal and external stakeholders Continuously evaluate emerging threats and technologies to strengthen Delta Defense's security posture Required Skills Network security engineering Cloud security (AWS, Azure, or similar) Security incident detection and response Vulnerability assessment and remediation Penetration testing basics SIEM administration and log analysis Endpoint detection and response (EDR) tools Identity and access management (IAM) Firewall, IDS/IPS configuration Security policy and documentation development
09/02/2026
Full time
Delta Defense seeks a Cybersecurity Engineer to safeguard critical systems, data, and customer information supporting USCCA's nationwide membership platform. In this role, you will design and maintain secure network and cloud architectures, administer security tools, and lead monitoring, incident response, and vulnerability management efforts. You'll collaborate closely with IT, software, and business teams to embed security by design, refine policies, and support audits. Join a fast-growing, mission-driven organization where your expertise directly protects responsible gun owners and advances a values-driven, high-performance culture. Responsibilities Design, implement, and maintain secure network and cloud architectures to protect USCCA systems and data Monitor security events, investigate alerts, and respond to incidents to minimize risk and downtime Conduct vulnerability assessments, penetration testing, and remediation planning across applications and infrastructure Develop and maintain security policies, standards, and procedures aligned with regulatory and industry best practices Collaborate with engineering and IT teams to embed security into software development and deployment processes Manage security tools including SIEM, EDR, firewalls, IDS/IPS, and identity and access management platforms Perform security risk assessments on new technologies, vendors, and business initiatives Lead security awareness efforts, coaching teams on secure behavior and incident reporting Support audit, compliance, and documentation requirements for internal and external stakeholders Continuously evaluate emerging threats and technologies to strengthen Delta Defense's security posture Required Skills Network security engineering Cloud security (AWS, Azure, or similar) Security incident detection and response Vulnerability assessment and remediation Penetration testing basics SIEM administration and log analysis Endpoint detection and response (EDR) tools Identity and access management (IAM) Firewall, IDS/IPS configuration Security policy and documentation development

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board