Network Cyber Security Engineer
About the role
The GN&T Network Security team is looking for a highly motivated and experienced Cybersecurity Engineer to join the Network Security Defense team. The Defense teams are responsible for owning the security lifecycle and effectiveness across the Core, Edge, and Access networks, as well as all systems and network functions within GN&T. In this role, you will advance our security posture through real-time Threat Monitoring & Detection using SIEM tools like Splunk, lead Incident Response efforts during a breach, and manage the continuous Vulnerability Management lifecycle across networks and applications. The position also requires expertise in defining and implementing robust Security Architecture, including firewalls, encryption, centralized Identity and Access Management, and Multi-Factor Authentication (MFA). A strong candidate will possess advanced Threat Hunting skills, including Advanced Networking & Protocol Analysis, Endpoint & Memory Forensics, Data Science & Querying, and demonstrable experience in Automation & Scripting to enhance Cybersecurity tooling.
Responsibilities
- Identify technology gaps to lead in the design, architecture, and implementation of appropriate security solutions.
- Create formal guidelines, policies, and procedures to ensure smooth and error-free operations.
- Implement strategic solutions in a highly scalable environment.
- Partner across Operations, Engineering, and Planning organizations to embed secure design patterns into new deployments and major changes.
- Work independently on strategic technical challenges.
- Identify opportunities to mentor junior engineers, guide, and delegate technical documentation/tasks to support the team and broader organization.
- Communicate clearly and effectively, articulating complex technical concepts to diverse internal and external audiences.
- Lead network security incident response activities including triage, containment, eradication, and recovery for disruptive threats.
- Build and refine incident playbooks and response runbooks, ensuring repeatable workflows for high-impact scenarios (ransomware, phishing, insider threat, DDoS, etc).
- Serve as escalation support for security-related investigations, providing expert-level analysis and guidance during active incidents.
- Execute root cause analysis and produce clear incident reports outlining timeline, impact, evidence, and remediation recommendations.
- Conduct proactive threat hunting across identity, endpoint, and network telemetry to uncover adversary behavior and reduce dwell time.
- Create and tune threat detections using SIEM (Security Information and Event Management) to improve alert fidelity and reduce false positives.
- Drive continuous improvement of network visibility and telemetry collection to strengthen detection and response capabilities.
- Perform regular security control assessments validating configuration effectiveness and closing gaps discovered during incidents or hunts.
Requirements
You'll need to have:
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field or four or more years of work experience.
- Four or more years of relevant experience, demonstrated through one or a combination of work and/or military experience, or specialized training.
- Ability to write complex, optimized Splunk SPL (Search Processing Language) searches, including macros, data models, and lookups for efficient threat hunting and investigation.
- Knowledge of incident response lifecycles (NIST or SANS) with experience designing, testing, and maintaining automation playbooks using SOAR platforms to automate triage and response actions.
- Experience with risk-based alerting, managing notable events, asset/identity correlation, and defining/tuning correlation searches.
Qualifications
Even better if you have one or more of the following:
- Security certifications such as CompTIA Security+, CISSP, CCIP, CISM, CCSP, OSCP (Offensive Security Certified Professional), Ethical Hacking (CEH, OSCP).
- Experience with Identity and Access Management (IAM) solutions.
- Ability to build consensus and a common understanding of security objectives, goals, and execution steps.
- Experience with network protocols and information security with networking certifications such as PCNSE, CCNP, or CCNA.
- Experience with networks, 4G/5G wireless network functions, or virtualization technologies like OpenStack and Kubernetes.
- Experience with scripting languages like Python and/or automation tools like Ansible.
- Experience in UNIX or Linux systems engineering expertise with a variety of variants.
- Experience with encryption for data in transit (e.g., IPsec, or TLS) and at rest.
- Experience in conflict resolution and negotiation to ensure design, strategy, and decisions consistently support security requirements.
- Strong analytical skills and attention to detail with a proven track record of managing and delivering results.
- Effective written, interpersonal, and verbal communication skills.
Schedule
In this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Scheduled weekly hours are 40.
Pay
The annual salary range for this position based on a full-time schedule is $101,000.00 - $194,000.00. This is an incentive-based position with the potential to earn more. For part-time roles, compensation will be adjusted to reflect hours.
Benefits
- Health and wellness benefits including medical, dental, vision, short and long-term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance, and group home & auto insurance.
- Matched 401(k) savings plan.
- Up to 8 company-paid holidays per year and up to 6 personal days per year.
- Paid parental leave, adoption assistance, and tuition assistance.
- Opportunities for premium pay such as overtime, shift differential, holiday pay, and allowances.
- Newly hired employees receive up to 15 days of vacation per year, which grows with additional service.