Sr. Cybersecurity Engineer
Atem Corp · Cambridge, MA · 1 wk ago
Information TechnologyFull-time
About the Role
This is a 6+ month contract position based in Cambridge, MA, focusing on leading threat detection, incident response, and SOC optimization within a multi-vendor security environment.
Responsibilities
- Lead end-to-end investigation of complex security incidents, including malware, phishing, lateral movement, and cloud compromise.
- Perform advanced threat hunting using SIEM, EDR, and cloud telemetry.
- Conduct deep forensic analysis of endpoints, networks, logs, and email headers.
- Design and implement high-fidelity detection rules and use cases aligned with MITRE ATT&CK.
- Develop and enhance SOC playbooks for incident response and threat detection.
- Lead implementation and optimization of security tools, including SIEM (Sentinel, Splunk, QRadar), EDR/XDR (Defender, CrowdStrike, SentinelOne), and email security (Proofpoint, Mimecast, Defender for Office).
- Manage integrations across a multi-vendor security stack.
- Develop automation playbooks (SOAR) for triage, enrichment, and response.
- Monitor and secure cloud environments (AWS/Azure) using CloudTrail, VPC Flow Logs, Defender, and Sentinel.
- Drive DevSecOps practices, including SAST, DAST, IaC scanning, and policy-as-code (OPA, Checkov).
- Perform vulnerability assessments and risk analysis to ensure alignment with frameworks such as NIST, CIS Benchmarks, GDPR, and PCI-DSS.
Requirements
- 8–12+ years of experience in cybersecurity, SOC, or threat detection roles.
- Experience in L2/L3 SOC or Security Operations leadership.
- Strong hands-on expertise in SIEM tools (Sentinel, Splunk, QRadar) and EDR/XDR platforms.
- Deep understanding of MITRE ATT&CK, threat vectors, malware behavior, and attack techniques.
- Experience with log analysis, detection engineering, correlation rules, and security automation (SOAR).
- Experience securing AWS/Azure environments and familiarity with CI/CD security (GitHub, GitLab, Jenkins) and IaC security (Terraform, CloudFormation).
Nice to Have
- Experience with email security platforms (Proofpoint, Mimecast).
- Familiarity with WAF/CDN (Akamai, Cloudflare) and threat intelligence platforms.
- Certifications such as CISM, CISSP, CEH, CHFI, or vendor-specific certifications (Microsoft Sentinel, QRadar, Splunk).