> Markdown version of [/jobs/ext/2694228-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/2694228-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** NLR, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $84,000.0 - $181,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Software Applications, Systems Engineering, Bash Shell, Command-Line Interface, Cyber Security, Information Systems, Computer Programming, Intrusion Detection Systems, Python (Programming Language), Linux Servers, Packet Analyzer, Network Protocols, Security Information and Event Management, In-Plane Switching (IPS), Information Technology, Cortex XSOAR Platform, Splunk, Security Orchestration, Automation & Response - **Published:** September 3, 2026 - **Apply:** https://nrel.wd5.myworkdayjobs.com/NLR/job/Remote-Site/Cybersecurity-Engineer_R14355 ## About the Role Basic QualificationsRelevant Bachelor's Degree and 9 or more years of experience or equivalent relevant education/experience. Or, relevant Master's Degree and 7 or more years of experience or equivalent relevant education/experience. Or, relevant PhD and 4 or more years of experience or equivalent relevant education/experience. Applies extensive IS expertise in specific field and has full knowledge of related disciplines. Evaluates new hardware, software, systems tools and applications and makes procurement recommendations. Excellent leadership and project management skills. Skilled in analytical techniques, practices and problem solving. Extensive programming and architecture abilities with various computer software programs and information systems. * Must meet educational requirements prior to employment start date. Additional Required Qualifications Training specific experience or training/certifications with Splunk administration is required. DOE L/Q Clearance: Must be able to obtain and maintain a DOE L/Q Security Clearance. Eligibility requirements: To obtain a clearance, an individual must be at least 18 years of age; U.S. citizenship is required except in very limited circumstances. See DOE O 472.2A for additional information. Preferred Qualifications * Experience includes at least seven years in an Information Technology role working specifically in security engineering, or a role that includes significant time performing security engineering (tool selection, installation, and maintenance) * One or more professional security and/or systems engineering certifications, such as GIAC (SANS) certifications, Security+, CISSP, or training evidencing effort to attain future certification * Technical background in multiple disciplines, including experience with: Windows and Linux server and workstation system administration; TCP/IP networking concepts, Bash command-line expertise, network protocols and architecture; security measures/defense-in-depth * Experience managing, and troubleshooting both network- and host-based security tools and significant infrastructure (ex. SIEM, IDS, IPS, full packet capture) in a production (live) environment * Subject matter expertise in cybersecurity engineering; understands how to select and tune tools to provide analysts with best value visibility and response * Experience dealing with common cyber security concepts and threats and describing them to others * Intermediate scripting/programming ability with various languages, preferably Python, in support of security orchestration and automation * Technology-specific experience or training/certifications with Splunk SIEM and Cortex XSOAR (formerly Demisto) is a plus * Understanding of cloud security architecture, event collection and aggregation a plus, The anticipated closing window for application submission is up to 30 days and may be extended as needed. ## Description * Manages, troubleshoots, and tunes cybersecurity tools and sensors, such as log aggregation (SIEM), automation/orchestration (SOAR), analysis, enrichment, alerting, and forensic data retention systems. * Selects, tests, deploys, and tunes new on-premises and cloud-based technical environments that support infrastructure visibility, analysis, automation, and secure data retention. * Guides policy decisions and/or manages security policies and related configurations for distributed security tools such as firewalls, endpoint detection and response suites, vulnerability detection tools, and cloud-based monitoring, protection, and incident response tools. * Develops content that enables cybersecurity personnel to take maximum advantage of existing tool capabilities, including workflows, integrations, and automated tasks. * Leads, designs, and performs infrastructure, application, and network tests and exercises to determine the efficacy of security defense strategies and tools. * Leads Information Technology Services project teams to integrate distributed network and endpoint security products with cybersecurity enrichment and analysis platforms and system management tools. * Creates and maintains architectural documentation and operational procedures that describe the scope, purpose, configuration, use, and maintenance of the cybersecurity operations tools and environments. * Leads projects (as assigned or independently) that improve the effectiveness and efficiency of NLR's cybersecurity program, including but not limited to workflow improvements, automation expansion, management tool enhancements, program or NLR strategic initiatives, and user awareness training. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [The Software Bug All Stars - and what we can learn from them](https://www.wearedevelopers.com/videos/423-the-software-bug-all-stars-and-what-we-can-learn-from-them) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)