> Markdown version of [/jobs/ext/3014083-cyber-defense-specialist](https://www.wearedevelopers.com/jobs/ext/3014083-cyber-defense-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Specialist - **Company:** LUMA Energy - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Bash Shell, CompTIA Security+, Cyber Security, Computer Networks, Linux, Digital Forensics, Monitoring of Systems, Intelligence Analysis, Intrusion Detection Systems, Python (Programming Language), Windows PowerShell, Remote Access Technology, Security Information and Event Management, TCP/IP, Traffic Analysis, Scripting, Mitre Att&ck, Malware, Firewalls (Computer Science), Information Technology, Sumo Logic (Software), Cyber Warfare, Vulnerability Analysis - **Published:** September 20, 2026 - **Apply:** https://www.dice.com/job-detail/992990c1-2f5e-487c-846b-1f214ca48d2f ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Assurance, or related field., * 5 years of relevant cybersecurity experience, preferably in a SOC, cyber defense operations, or incident analysis role. * Hands-on experience with SIEM platforms (Sumo Logic or equivalent), EDR (CrowdStrike or equivalent), and security monitoring tools. Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role: * Associate's degree in Cybersecurity, Computer Science, Information Technology, Information Assurance may substitute when accompanied by a minimum of 8 years of experience performing similar functions and at least 3 years of experience performing a previous position as Specialist role. * High School or equivalent (GED) when accompanied by a minimum of 10 years of experience performing similar functions described and at least 5 years of experience performing a previous Specialist role. Competencies (Skills) * Networking & Traffic Analysis: Demonstrates strong understanding of TCP/IP, common protocols, firewall and VPN technologies, IDS/IPS systems, and the ability to analyze logs, review network traffic, and correlate security events. * Operating Systems, Scripting & Forensics: Applies working knowledge of Windows and Linux OS environments, basic scripting in Python, PowerShell, or Bash, and foundational malware and digital forensics concepts. * Cybersecurity Frameworks: Understands and applies cybersecurity frameworks such as NIST CSF, MITRE ATT&CK, and ISO 27001, along with defense-in-depth principles. * Event Analysis & Security Monitoring: Possesses the ability to analyze logs, correlate events, and identify suspicious activity using technical knowledge and monitoring techniques. * Analytical & Communication Skills: Demonstrates strong analytical and problem-solving abilities, clear written and verbal communication in Spanish and English, attention to detail, teamwork, and high ethical standards under pressure. Licenses/Certifications At least one professional certification (or demonstrable equivalent): * CompTIA Security+ (or higher). * CySA+, or equivalent. * CISSP, CEH, GCIA, GCIH, or GSEC is strongly valued. ## Description Supports the protection of critical IT and OT environments by triaging alerts, investigating threats, and enhancing defensive capabilities that uphold confidentiality, integrity, and availability standards. Ensures continuous operational readiness through coordinated incident response and proactive threat hunting, driving measurable improvements in the organization's overall security posture., * Triage security alerts to determine root cause and prioritize incident handling, ensuring timely and accurate escalation aligned with SOC response standards. * Investigates suspicious activity across SIEM, email, and network telemetry to validate threats and produce evidence-based findings that support rapid containment. * Collaborates with cross-functional cybersecurity teams to coordinate incident response actions and achieve complete resolution and documented lessons learned in accordance with established protocols. * Conducts proactive threat hunting and intelligence analysis to identify emerging risks and deliver actionable reports that strengthen LUMA's preventive security posture. * Supports vulnerability assessment and defense architecture reviews to recommend improvements that ensure alignment with critical infrastructure protection standards. * Maintains and enhances operational playbooks, detection rules, and SOPs to ensure consistent, compliant, and up-to-date defensive capabilities across the organization. * Participates in on-call and rotating coverage to ensure continuous SOC operational readiness and consistent 24/7 incident response support. * Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations. * Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services. * Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)