Cybersecurity Engineer - Level 2

Reposted 22 Days Ago
Hiring Remotely in United States
Remote
Junior
Cloud • Information Technology • Cybersecurity
Rhodian removes the complexity between businesses and people through Technology, Cybersecurity, and Compliance.
The Role
Monitor, triage, and investigate security alerts from SIEM/EDR; perform incident response, root-cause analysis, threat hunting, SIEM tuning, documentation, and escalate complex incidents to senior teams.
Summary Generated by Built In

About Rhodian Group

Rhodian Group helps businesses build and manage their network environments with predictably priced managed IT services so they can focus on their core strengths and growth initiatives. They also help businesses identify and reduce cybersecurity and non-compliance risks. Their combination of IT, cybersecurity, and compliance services helps businesses operate safely, while complying with industry mandates and regulatory requirements.

Role Overview 

The Cybersecurity Level 2 Engineer plays a critical role in the Security Operations Center (SOC), responsible for monitoring, investigating, and responding to security alerts and incidents across client or enterprise environments. This role requires hands-on experience with SIEM platforms, endpoint security tools, and incident response processes, with the ability to escalate and remediate threats effectively. 


Key Responsibilities 

  • Monitor and triage security alerts generated by SIEM, EDR, and security monitoring tools 
  • Investigate security incidents including phishing, malware, endpoint compromise, and unauthorized access 
  • Perform root-cause analysis and document incident findings and remediation actions 
  • Tune SIEM detection rules, alerts, and dashboards to reduce false positives and improve fidelity 
  • Conduct threat hunting activities using logs from endpoints, networks, cloud platforms, and identity providers 
  • Respond to security incidents in accordance with established incident response playbooks and SLAs 
  • Escalate complex or high-risk incidents to Level 3 or Incident Response teams with detailed context and evidence 
  • Assist with vulnerability management findings and validation of remediation 
  • Support log ingestion, parsing, normalization, and retention requirements for SIEM platforms 
  • Maintain accurate case notes, incident reports, and security documentation 
  • Collaborate with IT, engineering, and security teams to improve overall security posture 


Required Qualifications 

  • 2+ years of hands-on experience in a SOC, cybersecurity, or security operations role 
  • Practical experience working with SIEM platforms (Splunk, Microsoft Sentinel, LogRhythm, QRadar, Elastic) 
  • Experience analyzing logs from endpoints, firewalls, IDS/IPS, cloud, and identity systems 
  • Familiarity with EDR tools (CrowdStrike, SentinelOne, Microsoft Defender, Datto EDR) 
  • Understanding of the incident response lifecycle and security alert triage 
  • Working knowledge of common attack techniques and indicators of compromise (IOCs) 
  • Experience with the MITRE ATT&CK framework 
  • Strong documentation and communication skills 


Preferred Qualifications 

  • Experience in an MSP or multi-tenant SOC environment 
  • Familiarity with SOAR tools and automation workflows 
  • Exposure to cloud security logging (Azure, AWS, Microsoft 365) 
  • Experience with vulnerability scanning tools (Qualys, Nessus, Rapid7) 
  • Basic scripting or query experience (KQL, SPL, SQL, PowerShell, Python) 
  • Relevant certifications: Security+, CySA+, SC-200, Splunk Core Certified User 


What Success Looks Like 

  • Security alerts are investigated accurately and efficiently 
  • Incidents are escalated with high-quality analysis and evidence 
  • SIEM detections improve over time through tuning and feedback 
  • Threats are identified early, contained effectively, and documented clearly 
  • Strong collaboration with SOC peers and senior security engineers 

Skills Required

  • 2+ years of hands-on experience in a SOC, cybersecurity, or security operations role
  • Practical experience working with SIEM platforms (Splunk, Microsoft Sentinel, LogRhythm, QRadar, Elastic)
  • Experience analyzing logs from endpoints, firewalls, IDS/IPS, cloud, and identity systems
  • Familiarity with EDR tools (CrowdStrike, SentinelOne, Microsoft Defender, Datto EDR)
  • Understanding of the incident response lifecycle and security alert triage
  • Working knowledge of common attack techniques and indicators of compromise (IOCs)
  • Experience with the MITRE ATT&CK framework
  • Strong documentation and communication skills
  • Experience in an MSP or multi-tenant SOC environment
  • Familiarity with SOAR tools and automation workflows
  • Exposure to cloud security logging (Azure, AWS, Microsoft 365)
  • Experience with vulnerability scanning tools (Qualys, Nessus, Rapid7)
  • Basic scripting or query experience (KQL, SPL, SQL, PowerShell, Python)
  • Relevant certifications: Security+, CySA+, SC-200, Splunk Core Certified User
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
49 Employees
Year Founded: 2005

What We Do

Rhodian Group helps businesses build and manage their network environments with predictably priced managed IT services so they can focus on their core strengths and growth initiatives. They also help businesses identify and reduce cybersecurity and non-compliance risks. Their combination of IT, cybersecurity, and compliance services helps businesses operate safely, while complying with industry mandates and regulatory requirements.

Similar Jobs

PwC Logo PwC

AI Solutions Engineering Delivery Lead

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
66 Locations
370000 Employees
123K-123K Annually

Superhuman Logo Superhuman

Group Manager, Acquisition Marketing

Artificial Intelligence • Information Technology • Machine Learning • Natural Language Processing • Productivity • Software • Generative AI
Remote or Hybrid
United States
1500 Employees
167K-255K Annually

Webflow Logo Webflow

Director, Analytics Engineering

Artificial Intelligence • Enterprise Web • Software • Design • Generative AI
Easy Apply
Remote
U.S.
800 Employees
250K-355K Annually

Atlassian Logo Atlassian

Architect

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
San Francisco, CA, USA
11000 Employees
172K-270K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account