Cyber Defense Detection and Automation Engineer
Crane NXT is looking for experienced professionals to join the Crane NXT Global Information Security Team. We have an exciting opportunity on our Cyber Defense team for an experienced security analyst/incident responder who wants to take the next step in their career as part of a global cybersecurity team. You are passionate about threat hunting, have a clear vision about next-gen SOCs and SOAR, and enjoy digging deep to find the bad guys as part of a growing global team.
Crane NXT’s Global Information Security team utilizes world-class tools and processes, and this role will provide opportunities to work in an important function joining our global security operations and incident response program. The ideal candidate will have solid proficiency in security incident and event management solutions, using modern IR approaches and tools, and experience with implementing and honing detective and preventive controls in an enterprise setting.
About the Role
The Cyber Defense Detection & Automation Engineer (SOC) is a hands-on technical role within the SOC, reporting to the Director of Security Operations and Incident Response. This position is responsible for engineering and improving detection capabilities across the SIEM & EDR, managing and enhancing SOAR-driven automation, and advancing the maturity of the SOC threat hunting program. The role works closely with SOC analysts to continuously improve alert quality, reduce noise, and strengthen the organization’s ability to detect and respond to threats.
In addition to core SOC engineering functions, this position supports acquisition integrations through SIEM onboarding, contributes to penetration testing activities, and plays an active role in incident response. The engineer also partners with business stakeholders to coordinate SOC initiatives and ensure effective communication and follow-through on escalations and improvements.
Responsibilities
- Develop and maintain SOAR automated playbooks for triage, enrichment, and response
- Manage SOAR integration of security tools and data sources using APIs and orchestration workflows
- Support ongoing SOAR platform health, reliability, and operational support
- Design, develop, and maintain SIEM detection content, including correlation rules, alert logic, and enrichment strategies
- Continuously tune and optimize detections based on SOC feedback, incident learnings, and threat intelligence to improve signal quality and reduce false positives
- Document detection logic, playbooks, processes, and improvements to ensure consistency, auditability, and scalability
- Coordinate and execute the SOC threat hunting program, including defining hypotheses, guiding hunts, and operationalizing validated findings into detections
- Collaborate daily with SOC analysts to refine detections, improve triage workflows, and address gaps in visibility or response
- Support onboarding of log sources and monitoring capabilities for newly acquired entities, including validating data quality and detection coverage
- Assist in planning and execution of annual penetration testing, including detection validation and tracking remediation of identified gaps
- Contribute to incident response activities by providing detection expertise, building rapid-use queries/playbooks, and supporting investigations
- Engage with business stakeholders to coordinate SOC initiatives, communicate risks and progress, and manage escalations through to resolution
- Participate in a scheduled on-call rotation, including weekend coverage, to support timely response to security incidents, escalations, and critical operational needs
Requirements
- 5+ years of experience in a security operations environment performing investigations and supporting incident response
- 3+ years of technical experience developing automation, orchestration, or response solutions (e.g., SOAR, scripting, integrations)
- 3+ years of hands-on experience with SIEM platforms, including query languages and log onboarding/integration
- Experience applying detection/content engineering best practices, including lifecycle management, testing, and tuning
Skills
- Strong understanding of detection engineering concepts and security telemetry (endpoint, identity, network, cloud, email, etc.)
- Experience building and maintaining automated workflows and integrations using APIs or scripting
- Strong proficiency with Python for automation, data parsing, enrichment, and security workflow development
- Strong proficiency with PowerShell for scripting, systems interaction, automation, and investigative support across enterprise environments
- Ability to analyze and troubleshoot data ingestion, parsing, and alerting issues across security tools
- Familiarity with threat hunting methodologies and incident response processes
- Ability to clearly communicate complex technical concepts to both technical teams and business stakeholders
- Experience working cross-functionally with SOC analysts, IT teams, and business units
- Strong organizational skills with the ability to manage multiple initiatives and drive outcomes
Attributes
- Analytical mindset with a focus on improving detection quality and operational efficiency
- Self-driven with a strong sense of ownership and accountability
- Comfortable operating in a fast-paced, evolving SOC environment
- Willingness and ability to support weekend on-call responsibilities as part of a team rotation