- Company Name
- Travelport
- Job Title
- Cyber Security Engineer I
- Job Description
-
**Job Title**
Cyber Security Engineer I
**Role Summary**
Support a global security operations team by monitoring, triaging, and responding to security alerts across endpoints, servers, and cloud environments. Collaborate with the Cyber Incident Response Team (CIRT) on detection, containment, and recovery of incidents, and maintain security tools such as EDR, SIEM, and SOAR.
**Expectations**
- 0‑2 years of cybersecurity or related IT/security experience (internships, academic projects, or certifications included).
- Keen interest in threat detection, incident response, and security operations.
- Detail‑oriented, proactive, and able to communicate clearly with technical and non‑technical stakeholders.
- Comfortable working in a fast‑moving, global environment and eager to learn new tools and techniques.
**Key Responsibilities**
- Monitor, triage, and respond to security alerts on endpoints, servers, and cloud services.
- Assist the CIRT with detection, containment, and recovery during active incidents.
- Perform log analysis and basic malware investigations; escalating complex cases to senior engineers.
- Configure and maintain security solutions (EDR, SIEM, SOAR).
- Document incidents, investigations, and remediation steps per established procedures.
- Collaborate with internal teams and external MSSP partners to track and resolve security issues.
- Contribute to developing and refining Standard Operating Procedures (SOPs).
- Build and maintain dashboards; collect and analyze metrics for reporting.
- Participate in tabletop exercises, training sessions, and simulations to improve incident response readiness.
- Stay updated on emerging threats and vulnerabilities; evaluate their relevance.
- Provide general support for audits, compliance efforts, and security reviews.
**Required Skills**
- Knowledge of endpoint detection and response (EDR), security information and event management (SIEM), and security orchestration, automation, and response (SOAR).
- Basic familiarity with log analysis, malware analysis, and incident response workflows.
- Strong analytical and problem‑solving abilities.
- Excellent written and verbal communication skills.
- Ability to work independently and as part of a distributed team.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
- Certifications such as CompTIA Security+, CEH, or similar are advantageous.