> Markdown version of [/jobs/ext/2103043-cybersecurity-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2103043-cybersecurity-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Operations Engineer - **Company:** PROPERTY VALUE, INC. - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, ARM Architecture, Microsoft Azure, Cloud Computing Security, Github, Identity and Access Management, Intrusion Detection and Prevention, Key Management, Zero Trust Network Access, SAP Sales and Distribution, Security Information and Event Management, Software Vulnerability Management, Google Cloud, Data Classification, Mitre Att&ck, Microsoft InTune, Palo Alto Networks, Casper Suite, Prisma Cloud Platform, Devsecops - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/ca0bbab3-b976-4026-8ed3-badedbcc8b9f ## About the Role * 7-9 years of experience in cybersecurity operations, security engineering, or senior SOC/IR roles * Hands-on MDR experience (alert triage, escalation workflows, MSSP management) * Deep expertise with CrowdStrike Falcon (EDR, detection tuning, SIEM/LogScale) * Endpoint security at scale (macOS with Jamf, Windows with Intune) * Proven incident response leadership (led incidents end-to-end) * Cloud security experience in AWS and either Google Cloud Platform or Azure (IAM, CloudTrail, GuardDuty, secrets management) * Experience leading enterprise security platform evaluations and POCs * Familiarity with SASE, CASB, or SSE architectures * Active daily use of AI and automation (100% internal AI adoption; required) * Experience in private equity, holding company, or multi-entity environments preferred, * Palo Alto Networks experience (Cortex XDR, Prisma Access, Prisma Cloud); PCNSE preferred * Jamf Protect and Jamf Connect at scale * Continuous pentesting platforms (Pentera, NodeZero, Horizon3) * DLP tooling (policy design, data classification, endpoint/cloud enforcement) * MITRE ATT&CK expertise (detection mapping, threat modeling, tabletop exercises) * CIS benchmark implementation and enterprise-scale hardening Preferred Certifications * PCNSE * GCIH * GCIA * CrowdStrike CCFA / CCFR * Or equivalent certifications Commitment to Diversity and Inclusion at Momentum ## Description * Serve as primary liaison to the MDR provider; own escalation workflows, alert triage, and SLA accountability across all entities * Act as primary incident responder, leading containment, eradication, recovery, and post-incident documentation * Maintain and test incident response playbooks aligned to MITRE ATT&CK * Lead tabletop exercises in coordination with the vCISO and drive IR maturity across portfolio companies * Lead technical evaluation of Palo Alto Cortex XSIAM, including POC design, capability assessment, and transition planning Endpoint Security & Hardening * Own endpoint security posture across ~1,400 macOS and 300 Windows devices * Eliminate local admin access across the macOS fleet (priority initiative) * Manage Jamf, Jamf Protect, and Jamf Connect; maintain CrowdStrike configurations and detection tuning * Define and implement CIS baselines and hardening standards across endpoints and servers Palo Alto Platform Evaluation * Lead POC for Cortex XDR/XSIAM: scenario design, detection validation, and operational fit * Evaluate Prisma Access (SASE: ZTNA, SWG, CASB) and Prisma Cloud (CSPM/CWPP) * Produce technical assessments covering capability gaps, integration complexity, migration risk, and total cost of ownership * Own implementation if selected Cloud Security & Vulnerability Management * Own cloud security strategy across AWS, Google Cloud Platform, and Azure * Expand CloudTrail and GuardDuty coverage across environments * Secure CI/CD pipelines (GitHub Actions), enforce secrets management and least-privilege IAM * Evaluate and implement vulnerability management platform; enforce remediation SLAs and reporting CASB, DLP & Detection Engineering * Lead CASB and DLP vendor evaluation and implementation * Maintain and improve CrowdStrike Next-Gen SIEM/LogScale detection rules * Map detection coverage to MITRE ATT&CK (focus on IAM abuse, lateral movement, data exfiltration) * Evaluate and implement continuous pentesting platforms (Pentera, NodeZero, Horizon3) Portfolio Company Engagement * Conduct technical security assessments across portfolio companies * Support DevSecOps and secure SD ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)