> Markdown version of [/jobs/ext/3049866-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3049866-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Samsung - **Location:** Austin, TX, United States - **Experience:** Experienced - **Salary:** $76,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Databases, Data Transmissions, Linux, Digital Forensics, Hard Disk Drives, Networking Hardware, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Windows Servers, Anti-Phishing, Salesforce.Com, Security Information and Event Management, Virtual Machines, Network Routers, Google Cloud, Storage Devices, Cloud Platform System, Malware, Firewalls (Computer Science), Kubernetes, Information Technology, Cybercrime, Ddos, Network Server, Servicenow - **Published:** September 24, 2026 - **Apply:** https://sec.wd3.myworkdayjobs.com/Samsung_Careers/job/12100-Samsung-Blvd-Austin-TX-USA/Cyber-Security-Engineer_R118362 ## About the Role Here's what you'll need: * Bachelor's degree in Cybersecurity, Computer Science or related field. * Security certification is a plus. * 2- 4 years of experience in Cyber Security. * Experience in, or eager to learn, system-engineering disciplines such as networking, Linux, and Windows Server administration. ## Description As a Cybersecurity Engineer, you will be responsible for implementing, and maintaining the organization's cybersecurity infrastructure, ensuring the highest levels of protection against cyber threats. Additionally, you will oversee systems that monitor, detect, and respond to security incidents. Role and Responsibilities Here's What You'll Be Responsible For: Threat Detection A Cyber Security Engineer responsible for Threat Detection focuses on identifying malicious activity as early as possible, analyzing security events, and improving an organization's ability to detect cyber threats before they cause damage. This role typically spans security monitoring, detection engineering, threat hunting, and incident response. Incident Investigation and Analysis. A Cyber Security Engineer responsible for Incident Investigation and Analysis focuses on determining what happened, how it happened, what systems were affected, and how to contain and prevent future incidents. This role requires a combination of technical analysis, digital forensics, malware analysis, and collaboration with incident response teams. -Validate whether an alert represents a true security incident. -Classify incidents (e.g., malware, phishing, insider threat, ransomware). -Determine severity and scope. -Identify affected users, systems, and data. -Escalate high-priority incidents to the incident response team. Monitoring and Alert Management. A Cyber Security Engineer responsible for Monitoring and Alert Management ensures continuous visibility into an organization's IT environment by collecting, monitoring, and analyzing security events. The goal is to detect potential threats quickly, reduce false positives, and ensure that genuine security incidents are investigated and resolved efficiently. -Endpoints (Windows, Linux, macOS) -Servers and virtual machines -Active Directory and Identity Providers -Network devices (Firewalls, Routers, Switches) -Cloud environments (AWS, Azure, Google Cloud) -Kubernetes clusters and containers -SaaS applications (Microsoft 365, Salesforce, ServiceNow) -Databases -VPN gateways -Email security systems Incident Response. A Cyber Security Engineer responsible for Incident Response focuses on preparing for, detecting, containing, eradicating, recovering from, and documenting cybersecurity incidents. The role requires collaboration across Security Operations (SOC), IT Infrastructure, Cloud, Networking, Legal, and Business teams to minimize the impact of security incidents and improve the organization's security posture. -Monitor security alerts from SIEM, EDR, IDS/IPS, firewalls, cloud platforms, and email security gateways. -Validate alerts to distinguish true positives from false positives. -Determine the scope, severity, and business impact of incidents. -Classify incidents (e.g., malware, ransomware, phishing, insider threats, data exfiltration, DDoS). -Escalate critical incidents according to the incident response plan. Documentation. A Cyber Security Engineer responsible for Documentation creates, maintains, and improves security documentation that supports security operations, incident response, compliance, governance, and technical implementations. High-quality documentation ensures that security processes are repeatable, auditable, and easily understood by technical teams, auditors, and management. Scanning external media devices for threats. A Cyber Security Engineer responsible for Scanning External Media Devices for Threats ensures that removable media (such as USB flash drives, external hard drives, CDs/DVDs, SD cards, smartphones, and other portable storage devices) are scanned, validated, and secured before they are allowed to connect to enterprise systems. This helps prevent malware infections, ransomware, unauthorized data transfer, and other threats introduced through removable media. -Define removable media security policies. -Restrict unauthorized USB devices. -Allow only approved encrypted storage devices. -Prevent unauthorized data transfers. -Enforce least-privilege access for removable media. -Maintain an inventory of approved external devices.