> Markdown version of [/jobs/ext/2243467-cyber-defense-platforms-staff-engineer](https://www.wearedevelopers.com/jobs/ext/2243467-cyber-defense-platforms-staff-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Platforms Staff Engineer - **Company:** Alnylam Pharmaceuticals, Inc. - **Location:** Cambridge, MA, United States - **Experience:** Expert - **Salary:** $174,300.0 - $235,700.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Integration, Intrusion Detection and Prevention, Python (Programming Language), Performance Tuning, Windows PowerShell, Phishing, Security Information and Event Management, Software Engineering, Management of Software Versions, Enterprise Software Applications, Mitre Att&ck, Cyber Threat Analysis, Build Management, Cyber Warfare, Software Version Control, Data Pipelines, Security Orchestration, Automation & Response, Golang - **Published:** August 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88148193/1 ## About the Role * 8+ years of progressive experience in security engineering, security operations, or detection engineering, with demonstrated ownership of defense and security platforms * Deep hands-on expertise architecting and administering: SIEM, SOAR, EDR, DLP, or email security and anti-phishing platforms * Strong software engineering skills in a language commonly used for security automation (e.g., Python, Go, PowerShell), with experience building production-quality integrations and tooling * Proven experience building and managing detection content at scale, measured against frameworks like MITRE ATT&CK * Track record of delivering measurable operational improvements through automation, such as reduced response times or expanded capacity without added headcount * Ability to operate autonomously in a build-from-zero environment and drive technical work across teams you don't manage * Experience standing up or modernizing a security operations stack (SIEM migration, SOAR implementation, EDR rollout) from early maturity * Cloud security experience, particularly AWS-native security services * Experience in regulated industries (pharma, biotech, healthcare, financial services) * Relevant certifications (e.g., GIAC GCDA/GDAT/GCIA, CISSP) or equivalent expertise #LI-MH1 #LI-Hybrid ## Description * Own the deployment, configuration, administration, and lifecycle of defense platforms including SIEM, SOAR, EDR, DLP, email security, and phishing * Define the platform roadmap: evaluate, deploy, integrate, and rationalize security technologies to maximize defensive coverage and operational efficiency * Engineer and maintain security data pipelines across the enterprise: log source onboarding, normalization, enrichment, retention, and cost management * Own the detection content lifecycle end-to-end: development, testing, tuning, versioning, and retirement of rules and analytics across all platforms * Establish detection-as-code practices, including version control, peer review, CI/CD deployment, and automated validation of content * Map detection coverage to MITRE ATT&CK, identify gaps, and partner with threat intel, IR, and offensive security to convert findings into durable detections * Design and build SOAR playbooks and workflow automation that reduce manual analyst effort and accelerate triage and response, including automated handling of user-reported phishing * Build internal tooling, integrations, and APIs that connect security platforms to each other and to enterprise systems * Set the standards for how Cyber Defense builds, deploys, and operates its technology, and serve as the technical authority for the defense technology domain * Lead cross-functional technical initiatives across IT, infrastructure, and engineering teams, and mentor engineers and analysts across the broader team ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)