Cybersecurity Senior Engineer (Customer Cyber Threat Response)

Cox Enterprises | North Hills, NY

Posted Date 1/25/2025
Description

We are seeking a skilled and detail-oriented Cybersecurity Senior Security engineer, who will be focused on customer-related security operations and incident response. This role is critical in detecting, analyzing, and responding to security incidents impacting our customers and products. The ideal candidate will leverage their expertise in Security Operations (SecOps), Incident Response (IR), and threat detection to ensure mitigation and resolution of security threats.

Security Operations

  • Conducts threat analysis and alert triage using various security tools (e.g., SIEM, EDR, Intelligence platforms).
  • Investigates and responds to escalations involving phishing, account takeovers, data breaches, and other security issues.
  • Performs threat hunting to proactively identify malicious and fraudulent activity.
  • Analyzes threat intelligence to identify and mitigate emerging threats to businesses and customers.
  • Creates investigation workflows and steps, aligned to threat resolution.
  • Continuously improves and maintains investigation workflows, achieving process optimization and improved threat detection.
  • Collaborates with various teams and MSS, continuously improving cybersecurity capabilities (prevention, detection, response).
  • Supports customer-facing teams and relevant business stakeholders for various security issues.
  • Proposes and helps review security plans and policies to improve organizational security posture.
  • Provides off-hour support as needed for security administration, detection, and response activities.

Incident Response

  • Investigates and responds to customer impacting security incidents (e.g., Denial of Service, data breaches).
  • Investigates tactics, techniques, and procedures (TTPs) used by threat actors conducting malicious activity.
  • Correlates incident data to identify threat trends and specific vulnerabilities.
  • Conducts root cause analysis and develops remediation strategies to prevent incident recurrence.
  • Documents response activities and mitigation measures for internal and external stakeholders.
  • Plans, implements, and maintains incident handling procedures, continuously improving response effectiveness.

Service Desk and Incident Management

  • Supports investigations and resolution of customer-based security issues.

Project Responsibilities

  • Partners with teams, designs, implements, and refines customer-focused detection rules and processes.
  • Defines KPIs, builds dashboards, and reports on detection and response performance.

Professional Technology Skills (the professional technology skills you need to be able to do the job)

Ability to:

  • Work with technical teams along with external MSSPs, for security monitoring of DDoS Protection, Email systems, Application logs, Intelligence platforms, and Endpoint security technologies.
  • Perform data analytics, security event correlation, and issue triage.
  • Apply security Threat Intelligence to respond appropriately to security events.
  • Work on projects to improve security monitoring and response capabilities.
  • Demonstrate a strong understanding of Zero Trust and security best practices.
  • Demonstrate a strong security engineering and architecture background.
  • Demonstrate effective communication of security issues to management and peers.
  • Maintain security monitoring guidelines and standards.
  • Perform incident response and forensic activities for internal and external threats.
  • Work with internal teams (IT, business), MSSPs, and external forensic services while responding to incidents.
  • Ensure all identified incidents are promptly and thoroughly investigated and remediated.
  • Ensure security incidents are documented accurately and thoroughly.

Knowledge, Experience & Qualifications

Essential

  • Bachelor’s degree in Computer Science and 4+ years of industry related professional experience and education.
  • Multi-cloud security experience AWS, Azure, GCP
  • Expert level knowledge on WAF, Web Security, DDoS protection, data analytics, and Bot Mgmt.
  • Working experience with Information Security, Network Security, Security Monitoring and Incident Response.
  • Working experience with industry standard security technologies and services including Threat Intelligence, IPS, Endpoint Security, SIEM/SOAR.
  • Strong ability in investigative skills and problem solving.

Desirable

  • GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA certification(s).
  • Dev Ops / Engineering / Network / System Administration experience.
  • Experience with various querying and scripting languages.

About Cox

Cox empowers employees to build a better future and has been doing so for over 120 years. With exciting investments and innovations across transportation, communications, cleantech and healthcare, our family of businesses – which includes Cox Automotive and Cox Communications – is forging a better future for us all. Ready to make your mark? Join us today!

------------

Benefits of working at Cox may include health care insurance (medical, dental, vision), retirement planning (401(k)), and paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO). For more details on what benefits you may be offered, visit our benefits page.

Cox is an Equal Employment Opportunity employer - All qualified applicants/employees will receive consideration for employment without regard to that individual’s age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law.

Type
Full-time

Share this job