Cyber Security Engineer

Posted Yesterday
Be an Early Applicant
Livermore, CA, USA
Hybrid
146K-223K Annually
Mid level
Information Technology • Security • Energy • Defense
The Role
Respond to and investigate security incidents, perform threat hunting, analyze IDS/SIEM and logs, conduct host/network/malware forensics, provide containment and remediation, support recovery, document findings, and improve incident response processes. At senior level, develop automation, advanced tools, and mentor incident response team members.
Summary Generated by Built In
Company Description

Join us and make YOUR mark on the World!

Are you interested in joining some of the brightest talent in the world to strengthen the United States’ security? Come join Lawrence Livermore National Laboratory (LLNL) where our employees apply their expertise to create solutions for BIG ideas that make our world a better place.

We are looking for individuals that demonstrate an understanding of working in partnership with team peers, who engage, advocate, and contribute to building an inclusive culture, and provide expertise to solve challenging problems.

Job Description

We have an opening for a Cybersecurity Engineer to independently and collaboratively perform a wide range of activities associated with supporting the Cyber Security Operations Center (CSOC) Incident Response team. This position is within the Information Technology Solutions Division (ITSD) of the Computing Directorate and matrixed to the Cyber Security Program (CSP), in support of the Livermore Information Technology (LivIT) Program.

This position offers a hybrid schedule, blending in-person and virtual presence. You will have the flexibility to work from home one or more days per week.

This position will be filled at either level based on knowledge and related experience as assessed by the hiring team. Additional job responsibilities (outlined below) will be assigned if hired at the higher level. 

You will

  • Protect enterprise systems and information by promptly responding to security threats and incidents, acting individually and as part of a team.
  • Proactively hunt for cyber threats and enact identification, containment and eradication measures while supporting recovery efforts.
  • Perform analysis on LLNL intrusion detection systems.
  • Provide security monitoring and incident response support including troubleshooting and resolution of issues.
  • Create and manage processes, systems, and tools exercising a high degree of responsibility.
  • Serve as an incident response technical point of contact and interact with internal and external personnel.
  • Perform technical assessments, document actions, findings, and make remediation recommendations.
  • Promote and support plans to promote diversity, equity and inclusion within the program. 
  • Perform other duties as assigned.

Additional job responsibilities, at the SES.3 level 

  • Manage multiple complex parallel tasks and priorities of customers and stakeholders, ensuring deadlines are met, while leveraging team member skills.
  • Develop advanced methods, tools, and procedures to improve incident response capabilities and automate various complex tasks.
  • Mentor and provide technical guidance to team members in incident response best practices and procedures.

Qualifications

  • Ability to obtain and maintain a US DOE Q-level security clearance which requires U.S. Citizenship. 
  • Bachelor’s degree in Computer Science, Computer Engineering or related field, or the equivalent combination of education and related experience.
  • Broad experience with SIEM, log aggregation, packet analysis, or other cybersecurity tools.
  • Experience conducting host forensics, network forensics, log analysis, or malware analysis in support of incident response investigations.
  • Proficient written and verbal communication, strong interpersonal skills, ability to collaborate in a multi-disciplinary team environment and to interact with all levels of management and staff.
  • Ability to effectively manage concurrent technical tasks with conflicting priorities, to approach difficult problems with enthusiasm and creativity and to change focus when necessary, with experience working independently.
  • Ability to work off-hours and on-call to respond to incidents (intermittently, either as-needed or as part of a rotation).

Additional qualifications at the SES.3 level 

  • Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management.
  • Significant experience with log analysis, event correlation, or incident management procedures.
  • Advanced ability to provide innovative approaches and apply new technologies to tasks and projects that may not be well defined.

Qualifications We Desire

  • Master’s degree in Computer Science, Computer Engineering, or a related field, or equivalent level of knowledge.                                                     
  • Significant incident response experience, including experience with cloud services such as AWS/Azure, and experience leading teams.
  • Experience with programming or scripting languages such as C, C#, Python, Java, PowerShell and PHP.
  • Current industry specific certifications including but not limited to Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Global Information Assurance Certification (GIAC).

Pay Range

$146,340 - $222,564 Annually

$146,340 - $185,544  at the SES.2 level

$175,530 - $222,564  at the SES.3 level

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting; pay will not be below any applicable local minimum wage.  An employee’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, and business or organizational needs.

Additional Information

#LI-Hybrid

Position Information

This is a Flexible Term appointment, which is for a definite period not to exceed six years.  If final candidate is a Career Indefinite employee, Career Indefinite status may be maintained (should funding allow).

Why Lawrence Livermore National Laboratory?

  • Included in 2026 Best Places to Work by Glassdoor!
  • Flexible Benefits Package
  • 401(k)
  • Relocation Assistance
  • Education Reimbursement Program
  • Flexible schedules (*depending on project needs)
  • Our values - visit https://www.llnl.gov/inclusion/our-values

Security Clearance

This position requires a Department of Energy (DOE) Q-level clearance.  If you are selected, we will initiate a Federal background investigation to determine if you meet eligibility requirements for access to classified information or matter. Also, all L or Q cleared employees are subject to random drug testing.  Q-level clearance requires U.S. citizenship. 

Pre-Employment Drug Test

External applicant(s) selected for this position must pass a post-offer, pre-employment drug test. This includes testing for use of marijuana as Federal Law applies to us as a Federal Contractor.

Wireless and Medical Devices

Per the Department of Energy (DOE), Lawrence Livermore National Laboratory must meet certain restrictions with the use and/or possession of mobile devices in Limited Areas. Depending on your job duties, you may be required to work in a Limited Area where you are not permitted to have a personal and/or laboratory mobile device in your possession.  This includes, but not limited to cell phones, tablets, fitness devices, wireless headphones, and other Bluetooth/wireless enabled devices.  

If you use a medical device, which pairs with a mobile device, you must still follow the rules concerning the mobile device in individual sections within Limited Areas.  Sensitive Compartmented Information Facilities require separate approval. Hearing aids without wireless capabilities or wireless that has been disabled are allowed in Limited Areas, Secure Space and Transit/Buffer Space within buildings.

How to identify fake job advertisements

Please be aware of recruitment scams where people or entities are misusing the name of Lawrence Livermore National Laboratory (LLNL) to post fake job advertisements. LLNL never extends an offer without a personal interview and will never charge a fee for joining our company. All current job openings are displayed on the Career Page under “Find Your Job” of our website. If you have encountered a job posting or have been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond.

To learn more about recruitment scams: https://www.llnl.gov/sites/www/files/2023-05/LLNL-Job-Fraud-Statement-Updated-4.26.23.pdf

Equal Employment Opportunity

We are an equal opportunity employer that is committed to providing all with a work environment free of discrimination and harassment. All qualified applicants will receive consideration for employment without regard to race, color, religion, marital status, national origin, ancestry, sex, sexual orientation, gender identity, disability, medical condition, pregnancy, protected veteran status, age, citizenship, or any other characteristic protected by applicable laws.

Reasonable Accommodation

Our goal is to create an accessible and inclusive experience for all candidates applying and interviewing at the Laboratory.  If you need a reasonable accommodation during the application or the recruiting process, please use our online form to submit a request. 

California Privacy Notice

The California Consumer Privacy Act (CCPA) grants privacy rights to all California residents. The law also entitles job applicants, employees, and non-employee workers to be notified of what personal information LLNL collects and for what purpose. The Employee Privacy Notice can be accessed here.

Skills Required

  • Ability to obtain and maintain a US DOE Q-level security clearance (requires U.S. citizenship).
  • Bachelor's degree in Computer Science, Computer Engineering, or related field, or equivalent combination of education and related experience.
  • Broad experience with SIEM, log aggregation, packet analysis, or other cybersecurity tools.
  • Experience conducting host forensics, network forensics, log analysis, or malware analysis in support of incident response investigations.
  • Proficient written and verbal communication and strong interpersonal skills; ability to collaborate in multidisciplinary teams.
  • Ability to effectively manage concurrent technical tasks with conflicting priorities and work independently.
  • Ability to work off-hours and on-call to respond to incidents intermittently or as part of a rotation.
  • Significant knowledge of SIEM solutions, threat hunting, incident response, or incident management (SES.3 level).
  • Significant experience with log analysis, event correlation, or incident management procedures (SES.3 level).
  • Master's degree in Computer Science, Computer Engineering, or related field.
  • Incident response experience with cloud services such as AWS/Azure and experience leading teams.
  • Experience with programming or scripting languages such as C, C#, Python, Java, PowerShell, and PHP.
  • Current industry certifications such as CISSP, CISM, or GIAC.

Lawrence Livermore National Laboratory Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Lawrence Livermore National Laboratory and has not been reviewed or approved by Lawrence Livermore National Laboratory.

  • Retirement Support A 401(k) with dollar-for-dollar match up to 6% plus additional employer contributions and immediate vesting strengthens total rewards. Clear plan tracks (TCP1/TCP2) and service-based contributions add predictability and long-term value.
  • Healthcare Strength Multiple medical, dental, and vision options, alongside FSAs and an Employee Assistance Program, provide comprehensive coverage. Ongoing open-enrollment updates and published plan details signal active plan management.
  • Leave & Time Off Breadth Paid time off includes vacation, sick leave, and up to 12 holidays, with a paid parental leave program for bonding. Flexibility is reinforced by leave advances and a catastrophic leave-sharing program for serious needs.

Lawrence Livermore National Laboratory Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
9,757 Employees
Year Founded: 1952

What We Do

Lawrence Livermore National Laboratory (LLNL) applies science and technology to make the world a safer place, focusing on national security missions such as nuclear deterrence, nonproliferation, energy security, defense, and intelligence.

Similar Jobs

ServiceNow Logo ServiceNow

Security Engineer

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Santa Clara, CA, USA
29000 Employees
221K-387K Annually

Northrop Grumman Logo Northrop Grumman

Principal Engineer

Aerospace • Logistics • Security • Software • Cybersecurity
In-Office
San Diego, CA, USA
85636 Employees
142K-213K Annually

Sandisk Corporation Logo Sandisk Corporation

Security Engineer

Hardware • Information Technology • Semiconductor • Manufacturing
In-Office
Milpitas, CA, USA
11000 Employees
In-Office or Remote
2 Locations
10000 Employees
142K-178K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account