> Markdown version of [/jobs/ext/1237357-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/1237357-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Neros Technologies - **Location:** Torrance, CA, United States - **Experience:** Expert - **Salary:** $86,500.0 - $121,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Application Firewall, Software System Penetration Testing, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, Microsoft Security Essentials, System Center Configuration Manager, Network Segmentation, Citrix Systems, PCI Data Security Standards, Phishing, Security Information and Event Management, Cloud Platform System, Microsoft InTune, CIS Benchmarks, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2c3f0203956c3c9c ## About the Role * 8+ years of progressive experience in cybersecurity engineering, with demonstrated ability to build and operate security programs - not just maintain existing ones * Deep hands-on expertise with the Microsoft security ecosystem including Defender XDR (Endpoint, M365, Identity, Cloud Apps), Entra ID Protection, and Azure/M365 security controls * Proven experience deploying and managing MDR/SIEM solutions for 24/7 threat monitoring and SOC operations (e.g., Rapid7, Secureworks Taegis XDR, or equivalent) * Strong background in incident response - containment, investigation, remediation, forensic preservation, and stakeholder communication * Working knowledge of compliance frameworks including NIST 800-171, NIST CSF, CIS benchmarks, and PCI DSS, with hands-on experience performing audits and control assessments * Experience conducting vulnerability assessments and penetration testing across infrastructure, applications, and cloud environments * Proficiency with endpoint protection platforms, Microsoft security baseline configuration, and change control programs * Demonstrated ability to automate security workflows using AI-assisted tooling, XDR automation, or scripting * Strong communication skills - able to translate security risks and technical findings for non-technical leadership and cross-functional teams * Relevant certifications preferred: MCSA, CISSP (in progress acceptable), CompTIA Security+/CySA+, or equivalent Nice to have * Experience building a cybersecurity program from scratch at a startup or early-stage company * Familiarity with ISO standards, 27001 in particular * Familiarity with network segmentation tools (e.g., Illumio) and next-gen firewall administration (Palo Alto, Zscaler) * Experience with security awareness platforms (KnowBe4 or equivalent) and phishing simulation programs * Background in systems administration (Active Directory, Citrix, SCCM, Intune) providing depth of understanding of the environments being secured * Experience with Tenable.ot or OT security in operational technology environments * CISSP, SANS GIAC, or advanced Microsoft security certifications * Eligibility or willingness to obtain a security clearance for potential future classified work ## Description Join Neros as a Senior Cybersecurity Engineer and take ownership of the security program that protects our defense technology platforms. You'll build and mature our cybersecurity capabilities from the ground up - architecting detection and response systems, engineering security controls across cloud and endpoint environments, and ensuring compliance with NIST, ISO, and CIS frameworks. This is a high-impact, hands-on role at a fast-moving defense tech startup for a security professional who thrives as both architect and operator., * Build and operationalize the enterprise cybersecurity program, owning security architecture, detection and response, governance, and automation * Engineer and manage the security technology stack including Microsoft Defender XDR, endpoint protection platforms, SIEM/MDR solutions, and Azure/M365 security controls * Lead incident response operations - containment, investigation, remediation - and coordinate with leadership and stakeholders on findings and risk posture * Perform security audits, vulnerability assessments, and penetration testing to identify and remediate weaknesses across infrastructure, applications, and cloud environments * Develop and enforce security policies, procedures, and compliance programs aligned to NIST 800-171 and ITAR controls. * Automate security workflows and build detection logic to improve alert fidelity, operational efficiency, and coverage across the environment * Establish change control processes, security baselines, and security awareness training programs ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)