Search Open Jobs
All GTN W2 consultants get full benefits. Learn more.
Cyber Defense Engineer
Irving, TX US
Job Description
Location: Onsite –Irving, TX
Employment Type: Full-Time
Compensation: Based on experience
Position Overview
We are seeking a skilled Cyber Defense Engineer to join our Cybersecurity team. Reporting to the Director of Cyber Defense within the Office of the CISO, this position plays a critical role in architecting and implementing advanced security solutions that enhance threat detection, response automation, and overall security monitoring capabilities. The ideal candidate is a technically driven professional with deep knowledge of Microsoft’s security ecosystem and a passion for building efficient, automated solutions that support Security Operations Center (SOC) workflows.
Key Responsibilities
-
Develop and deploy custom threat detections and automation workflows in the SIEM/SOAR platform.
-
Integrate security tools to create a robust and cohesive security monitoring ecosystem.
-
Partner with cyber defense operations to analyze threat intelligence and operational gaps, recommending and implementing advanced technical defenses.
-
Build and refine security analytics to improve detection of evolving cyber threats.
-
Automate alert enrichment, triage, and response actions to reduce manual effort and improve incident response times.
-
Collaborate with infrastructure and application teams to ensure logging, telemetry, and monitoring coverage across key systems.
-
Manage and optimize security monitoring frameworks within an enterprise SOC environment.
-
Maintain documentation and participate in continuous improvement of security engineering practices.
Qualifications
-
Bachelor’s degree in Computer Science, Information Security, or a related discipline.
-
3+ years of experience in a cybersecurity engineering or security operations role.
-
Hands-on experience with SIEM and SOAR platforms (e.G., Sentinel, Splunk, QRadar).
-
Expertise with Microsoft security technologies (Defender, Sentinel, Purview, etc.).
-
Proficiency with scripting and automation languages such as KQL, PowerShell, and Python.
-
Familiarity with API development and integration of disparate security tools.
-
Experience with log ingestion strategies and centralized monitoring.
-
Exposure to multi-tenant or MSP-style environments is a plus.
-
Strong communication skills and a proactive, self-directed work style.
Work Eligibility
Applicants must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.
