> Markdown version of [/jobs/ext/2573332-senior-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2573332-senior-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer - **Company:** The Rogue - **Location:** Columbus, OH, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Application Firewall, Software System Penetration Testing, Microsoft Azure, Botnet, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Digital Forensics, Domain Name System (DNS), Virtual Private Networks (VPN), Python (Programming Language), Network Troubleshooting, Linux Servers, Open Source Intelligence, Open Web Application Security, PCI Data Security Standards, Remote Access Technology, Zero Trust Network Access, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Web Applications, Zabbix, Data Logging, Scripting, Transport Layer Security, Software Security, Firewalls (Computer Science), Rate Limiting, Cybercrime, Cloudflare, Gsuite, Ddos, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Vmware - **Published:** August 1, 2026 - **Apply:** https://www.careerjet.com/job/us809aaf34c8a9e28fdf87b0e965ae2f86/eaa ## About the Role We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position - you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership. The Senior Cybersecurity Engineer is a fully onsite role in Columbus, Ohio. Remote work is not available. Applicants must be authorized to work in the United States for any employer., Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform) Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations Experience with vulnerability management, penetration testing, threat hunting, and incident response Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks Strong communicator who can work independently and partner effectively with technical and business stakeholders Preferred Experience Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware Python or other scripting experience for security automation, detections, and SIEM workflow development Background in ethical hacking, application security, digital forensics, or OSINT Familiarity with DevSecOps, IaC, containers, and cloud-native services Awareness of AI security risks and secure use of generative AI Security or cloud certifications are a plus but not required By applying to Rogue, regardless of the platform you choose to use, you are agreeing to Rogue's preferred methods of communication (i.e. text message). Submitting an application, through whatever online forum is ultimately used, constitutes a knowing and voluntary agreement to send and receive text messages during the recruitment process. ## Description Administer and improve WAF platforms - managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4 Administer and secure Google Workspace identity - MFA, access controls, account lifecycle, least privilege - and investigate suspicious sign-ins and identity-related alerts ## Related Videos - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)