Security Engineer

Neptune and Company, Incorporated
Duluth, GA, United States
24 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$80,000.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Information Systems Information Leak Prevention Identity and Access Management Information Technology Operations Intrusion Detection and Prevention Python (Programming Language)
+16 more
Networking Basics Windows PowerShell Azure Active Directory Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Scripting Mitre Att&ck QRadar Cyber Threat Analysis Information Technology Cybercrime Microsoft Sentinel CIS Benchmarks Splunk Security Orchestration, Automation & Response

Job description

As a Security Engineer within Neptune’s Security Operations Center (SOC), you will design, implement, administer, and optimize Neptune’s cybersecurity technologies while serving as a technical leader within the SOC. This role combines security engineering with operational security by supporting incident detection, investigation, response, and remediation while continuously improving Neptune’s security capabilities through automation, tool integration, detection engineering, and process enhancement.

The Security Engineer partners closely with SOC Analysts, IT Operations, Infrastructure, Cloud, and Engineering teams to implement and maintain security solutions, tune detections, develop response playbooks, support vulnerability management, and enhance security monitoring across the enterprise - providing advanced technical expertise during cybersecurity incidents and driving continuous improvements to strengthen Neptune’s overall security posture.

Responsibilities:

Security Engineering & Tool Administration

  • Design, configure, implement, and maintain security platforms including SIEM, EDR/XDR, SOAR, Identity and Access Management (IAM), Data Loss Prevention (DLP), Vulnerability Management, and Cloud Security solutions
  • Evaluate, test, and deploy new security technologies, including Proof of Concept (POC) evaluations
  • Develop automation and orchestration workflows to improve operational efficiency
  • Support cloud security and Zero Trust initiatives across the enterprise

Detection Engineering & Threat Hunting

  • Develop and tune security detections, correlation rules, and dashboards to improve threat detection capabilities and reduce false positives
  • Perform proactive threat hunting and analyze security telemetry across endpoint, network, identity, cloud, and SIEM platforms
  • Identify opportunities to improve detection and response capabilities across the environment
  • Monitor emerging threats, vulnerabilities, and industry best practices to inform detection strategy

Incident Response & Investigation

  • Provide technical leadership during investigation, containment, eradication, and recovery for complex and escalated security incidents
  • Investigate advanced cyber threats and complex security alerts
  • Collect and analyze forensic artifacts, logs, and endpoint telemetry during investigations
  • Participate in the on-call rotation and provide advanced technical support during critical security incidents
  • Support root cause analysis and post-incident reviews

Vulnerability Management & Remediation

  • Validate vulnerability findings and coordinate remediation activities with IT Operations, Infrastructure, and Engineering teams
  • Implement security controls to address identified risks
  • Track and support remediation efforts across the vulnerability management program

Security Operations, Mentorship & Documentation

  • Partner with SOC Analysts, IT Operations, Infrastructure, Cloud, and Engineering teams to implement and maintain security solutions
  • Develop response playbooks, engineering standards, and operational procedures
  • Provide mentorship and technical guidance to SOC Analysts
  • Create and maintain technical documentation supporting SOC operations
  • Collaborate with Neptune’s MSSP and third-party security partners on engineering and investigation initiatives

Compliance & Governance Support

  • Support compliance initiatives aligned with NIST CSF, CIS Controls, ISO 27001, and Roper Cybersecurity requirements
  • Recommend improvements that strengthen Neptune’s security posture, resilience, and compliance
  • Assist with audit requests, evidence collection, and security documentation

Relevant Platforms (experience with several expected):

  • CrowdStrike Falcon
  • Google SecOps (Chronicle)
  • Microsoft Defender
  • SIEM Platforms
  • Endpoint Detection and Response (EDR) Platforms
  • Security Orchestration, Automation, and Response (SOAR)
  • Identity and Access Management (IAM) / Microsoft Entra ID
  • Data Loss Prevention (DLP)
  • Cloud Security Platforms (AWS, Azure)
  • Vulnerability Management Platforms

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
  • 2-5 years of experience in cybersecurity, security operations, incident response, or related technical field
  • Experience investigating security alerts, detections, and cybersecurity incidents
  • Experience working in a Security Operations Center (SOC) environment
  • Experience with SIEM and EDR platforms
  • Understanding of security engineering concepts, including detection engineering, automation, and security tool administration
  • Strong analytical, troubleshooting, and problem-solving skills
  • Strong written and verbal communication skills, * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field
  • 2-5 years of experience in Security Operations, Cybersecurity, Incident Response, Vulnerability Management, or Information Technology
  • Experience with SIEM platforms such as Google SecOps, Chronicle, Splunk, QRadar, Microsoft Sentinel, or similar technologies
  • Experience with Endpoint Detection and Response (EDR) platforms such as CrowdStrike Falcon or Microsoft Defender
  • Familiarity with the MITRE ATT&CK Framework, threat hunting, and threat intelligence methodologies
  • Experience supporting vulnerability management programs and remediation activities
  • Knowledge of Windows, Active Directory, Microsoft Entra ID, networking fundamentals, and cloud security concepts
  • Experience working with AWS and/or Azure environments
  • Familiarity with NIST Cybersecurity Framework, CIS Controls, ISO 27001, and security best practices
  • Experience with scripting or automation using PowerShell, Python, or similar languages

Certifications (One or More Preferred):

  • Security+
  • CySA+
  • GSEC
  • GCIH
  • GCIA
  • GCED
  • CISSP (Associate or Full)
  • SC-200
  • SC-100
  • CrowdStrike Certifications
  • Google SecOps Certifications
  • AWS or Azure Security Certifications

Years of Experience (IT, Security & Compliance)

  • 2-5 years of Information Technology, Cybersecurity, Security Operations, Compliance, or Incident Response experience

Education

  • Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field preferred
  • Equivalent military, technical, or professional experience will be considered

Travel Requirements: Typically requires overnight travel less than 10% of the time.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all