- Company Name
- PRI Technology
- Job Title
- Principal CyberSecurity Engineer
- Job Description
-
Job Title: Principal CyberSecurity Engineer
Role Summary:
Lead advanced threat detection, investigation, and incident response for a large enterprise SOC. Responsibilities include monitoring alerts from SIEM, EDR, and network tools, performing threat analysis, coordinating containment, and improving SOC processes.
Expectations:
- 24/7 SOC shift participation.
- Maintain current knowledge of threat landscape, TTPs, and MITRE ATT&CK.
- Collaborate with IT, OT, and business units for incident validation and resolution.
- Drive continuous improvement of detection rules, playbooks, and knowledge base.
Key Responsibilities:
- Monitor and analyze security alerts (SIEM, EDR, network monitoring).
- Conduct in-depth investigations, correlate data across sources, determine impact.
- Resolve low‑to‑moderately complex incidents: containment, eradication, recovery.
- Escalate confirmed incidents to L3 teams with documentation and recommendations.
- Support containment/remediation during active incidents.
- Perform root‑cause analysis and post‑incident reviews.
- Use threat intelligence, behavioral analytics, and contextual data to enhance detection.
- Collaborate with detection engineering to develop, test, and tune detection rules.
- Perform basic malware analysis, log correlation, network traffic inspection.
- Document investigation steps, findings, and resolution actions clearly.
- Contribute to SOC process improvement, playbook updates, and knowledge base enhancement.
Required Skills:
- SOC or cybersecurity operations experience.
- Proficient in SIEM, EDR, and network monitoring tools analysis.
- Strong analytical and problem‑solving abilities.
- Effective communication and documentation skills.
- Familiarity with threat intelligence, basic malware analysis, log correlation.
- Understanding of common attack vectors, threat actor behaviors, MITRE ATT&CK.
- Ability to triage, investigate, and correlate multi‑source alerts.
- Proficiency in incident response support and root‑cause analysis.
- Commitment to continuous learning and risk mitigation.
Required Education & Certifications:
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science (completed).
- Certifications: CompTIA Security+, CySA+, or GCIH (preferred).