Cyber Defense Platforms Staff Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+10 more
Job description
- Own the deployment, configuration, administration, and lifecycle of defense platforms including SIEM, SOAR, EDR, DLP, email security, and phishing
- Define the platform roadmap: evaluate, deploy, integrate, and rationalize security technologies to maximize defensive coverage and operational efficiency
- Engineer and maintain security data pipelines across the enterprise: log source onboarding, normalization, enrichment, retention, and cost management
- Own the detection content lifecycle end-to-end: development, testing, tuning, versioning, and retirement of rules and analytics across all platforms
- Establish detection-as-code practices, including version control, peer review, CI/CD deployment, and automated validation of content
- Map detection coverage to MITRE ATT&CK, identify gaps, and partner with threat intel, IR, and offensive security to convert findings into durable detections
- Design and build SOAR playbooks and workflow automation that reduce manual analyst effort and accelerate triage and response, including automated handling of user-reported phishing
- Build internal tooling, integrations, and APIs that connect security platforms to each other and to enterprise systems
- Set the standards for how Cyber Defense builds, deploys, and operates its technology, and serve as the technical authority for the defense technology domain
- Lead cross-functional technical initiatives across IT, infrastructure, and engineering teams, and mentor engineers and analysts across the broader team
Requirements
- 8+ years of progressive experience in security engineering, security operations, or detection engineering, with demonstrated ownership of defense and security platforms
- Deep hands-on expertise architecting and administering: SIEM, SOAR, EDR, DLP, or email security and anti-phishing platforms
- Strong software engineering skills in a language commonly used for security automation (e.g., Python, Go, PowerShell), with experience building production-quality integrations and tooling
- Proven experience building and managing detection content at scale, measured against frameworks like MITRE ATT&CK
- Track record of delivering measurable operational improvements through automation, such as reduced response times or expanded capacity without added headcount
- Ability to operate autonomously in a build-from-zero environment and drive technical work across teams you don’t manage
- Experience standing up or modernizing a security operations stack (SIEM migration, SOAR implementation, EDR rollout) from early maturity
- Cloud security experience, particularly AWS-native security services
- Experience in regulated industries (pharma, biotech, healthcare, financial services)
- Relevant certifications (e.g., GIAC GCDA/GDAT/GCIA, CISSP) or equivalent expertise
LI-MH1 #LI-Hybrid
Benefits & conditions
$174,300.00 - $235,700.00
The pay range reflects the full-time base salary range we expect to pay for this role at the time of posting. Base pay will be determined based on a number of factors including, but not limited to, relevant experience, skills, and education. This role is eligible for an annual short-term incentive award (e.g., bonus or sales incentive) and an annual long-term incentive award (e.g., equity).
Alnylam’s robust Total Rewards package is designed to support your overall health and well-being. We offer comprehensive benefits including medical, dental, and vision coverage, life and disability insurance, a lifestyle reimbursement program, flexible spending and health savings accounts and a 401(k)with a generous company match. Eligible employees enjoy paid time off, wellness days, holidays, and two company-wide recharge breaks. We also offer generous family resources and leave. Our commitment to your well-being reflects our belief that caring for our people fuels the impact we create together.
Learn more about these and additional benefits offered by Alnylam by visiting the Benefits section of the Careers website: https://www.alnylam.com/careers
AboutAlnylam
We are the leader in RNAi therapeutics- a revolutionaryapproach with the potential to transform the lives of people with rare and common diseases. Built on Nobel Prize-winning science, Alnylam has delivered the breakthroughs that made RNAi therapeutics possibleand are just at the beginning of what’s possible. Our deep pipeline, late-stage programs, and bold vision reflect our core values: fierce innovation, passion for excellence, purposeful urgency, open culture and commitment to people. We’re proud to be a globally recognized top employer, wherean authentic, inclusive culture and breakthrough thinkingfuel one another.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Why Upskilling And Reskilling is Important For Developers
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again