Cyber Fusion Center Platform Integration Lead
Role details
Job location
Tech stack
Job description
We are seeking a dynamic and technically skilled Cyber Fusion Center Platform Integration Lead to drive the automation, integration and optimization of enterprise cybersecurity operations platforms. This role is ideal for a cybersecurity professional with a strong foundation in automation, scripting and security operations, who is excited to build scalable and resilient security capabilities across multiple domains of security operations.
This role will support the enhancement and stabilization of Data Loss Prevention (DLP) capabilities, with a focus on improving platform performance and operational effectiveness. As part of the Cyber Fusion Center, the position will also support automation and integration efforts across security operations, including SOC and EVM workflows, driving scalable and unified security capabilities.
The ideal candidate will bring a blend of hands-on engineering expertise with a background in cybersecurity automation, vulnerability research and security operations. This role emphasizes platform orchestration, workflow automation, API-driven integration, and software engineering principles to enhance detection, response, and overall cyber defense maturity., Lead configuration, integration, and continuous improvement of DLP platforms including Microsoft Purview, Microsoft Suite of tools (O365 and other Microsoft Security Stack), Zscaler, and related technologies.
Partner with DLP analysts to streamline and automate investigation workflows.
Design, implement, and refine DLP policies across endpoints, cloud services, and collaboration platforms.
Design and implement automation workflows and scripts (e.g., PowerShell, Python, C#) to streamline alert triage, enrichment, incident response, and reporting across SOC, DLP, and EVM.
Coordinate integration of tools and data sources across SOC, threat intelligence, endpoint, cloud and identity platforms to enable unified visibility and automated response capabilities for SOC, DLP and EVM teams.
Partner with SOC and Threat Detection teams to develop, tune and automate detection use cases for Incident Response and Data Loss Protection teams to improve detection times.
Leverage platform telemetry and security data to identify trends, improve detection capabilities and build dashboards that enhance situational awareness for risk visibility.
Work with security engineering, IT, cloud and risk/compliance teams to ensure platforms are aligned with enterprise architecture and security strategy.
Develop and maintain technical documentation, runbooks, and automation playbooks and contribute to internal training and knowledge sharing for CFC upskilling.
Requirements
Bachelor's degree in computer science, Cybersecurity, or a related field.
5+ years of experience in cybersecurity, automation engineering or security platform engineering.
Proficiency in scripting and automation tools (e.g. PowerShell, Python, C#).
Experience integrating operating tools such as SIEM, EDR, secure web gateways and cloud security platforms.
Understanding of security operations, including SOC workflows, DLP investigations, threat detection and incident response.
Familiarity with API integrations, workflow automation, and Infrastructure-as-Code concepts.
Excellent communication skills and ability to work cross-functionally
Preferred Qualifications:
Experience in building or supporting Security Orchestration, Automation, and Response (SOAR) capabilities.
Background in detection development, incident response and digital forensics.
Experience in regulated industries such as healthcare or pharmaceuticals.
Security certifications such as CISSP, GSEC or similar GIAC certifications.
Familiarity with cloud security architecture and Microsoft 365 capabilities., Amazon S3, Cloud Access Security Broker (CASB), Collaborative Development, Cyber Threat Intelligence, Data Loss Prevention (DLP), Digital Forensics, Endpoint Detection and Response, Information Security, Information Technology Trends, Intellectual Property, Non-Disclosure Agreements, Penetration Testing, Security Incident Management, Security Operations, SLA Management, SOC Operations, Technical Writing, Technical Writing Documentation, Vulnerability Scanning
Benefits & conditions
We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another's thinking and approach problems collectively.
Learn more about your rights, including under California, Colorado and other US State Acts (https://www.msdprivacy.com/us/en/CCPA-notice/)
The salary range for this role is
$117,000.00 - $184,200.00