Senior Cyber Security Engineer
oakridge staffingNew York (NY)
About the role
Global retailer is looking for a Senior Cyber Security Engineer for their NYC headquarters. This position is hybrid. We are looking for a Senior SOC Engineer, within the Cyber Incident Response team to be an L2: This is a professional responsible for protecting computer systems, networks, and sensitive data from cyber-attacks, hacking attempts, and other security threats with past experience working in a SOC.The role collaborates with other security and IT teams, leveraging available technology and systems to provide Incident Response services. In addition, the role contributes to other activities, such as participating in Group projects and initiatives with implications on IR services.
Responsibilities:
Investigate and respond to cybersecurity incidents in real-time, including handling more complex and high-severity cases. Work with a team of analysts to determine the scope, root cause, attack techniques, and impact of attacks. Perform detailed analysis across endpoint, network, identity, and cloud data sources, including log analysis, process activity, and authentication events. Support basic forensic investigations, including evidence collection, timeline reconstruction, and analysis of suspicious files or activities. Develop, implement, and maintain incident response plans, playbooks, and SOPs to contain and mitigate cybersecurity incidents. Develop and enhance incident detections and triggers, aligned with the evolving threat landscape and leveraging available technology (e.g., SIEM correlation, EDR detections).Operate with various systems in real-time to investigate, maintain, and track incidents across their lifecycle. Perform deeper analysis and correlation across multiple data sources to identify threats and potential lateral movement. Collaborate with other teams, including IT, security risk, forensics, and legal, to ensure a coordinated response to incidents. Communicate security incidents, findings, and recommendations to management, stakeholders, and relevant parties.
Qualifications:
Strong knowledge of networking, systems, identity, and cloud environments, including investigation and troubleshooting. Strong understanding of cybersecurity principles, including threat intelligence, incident response, forensics, vulnerability management, and cyber awareness. Practical experience in log analysis, endpoint investigation, and understanding attacker techniques (e.g., lateral movement, persistence, privilege escalation).Experience with security tools such as SOAR, SIEM, IDS/IPS, EDR, mail gateway, and other relevant technologies. Ability to handle complex incidents in a fast-paced environment and manage multiple tasks simultaneously. Excellent proficiency in English. Fluency in additional languages is a strong asset. Industry-recognized security certifications, including but not limited to: CISSP, CEH, CISA, GSEC, GCIA, GCIH, GCFA, GCFE, GPEN, GWAPT, GMOB, GREM, GASF, GCTI or equivalent certifications, are a strong asset.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
