Security Engineer
Position SummaryAs a Security Engineer within Neptune's Security Operations Center (SOC), you will design, implement, administer, and optimize Neptune's cybersecurity technologies while serving as a technical leader within the SOC. This role combines security engineering with operational security by supporting incident detection, investigation, response, and remediation while continuously improving Neptune's security capabilities through automation, tool integration, detection engineering, and process enhancement.The Security Engineer partners closely with SOC Analysts, IT Operations, Infrastructure, Cloud, and Engineering teams to implement and maintain security solutions, tune detections, develop response playbooks, support vulnerability management, and enhance security monitoring across the enterprise — providing advanced technical expertise during cybersecurity incidents and driving continuous improvements to strengthen Neptune's overall security posture.Responsibilities:Security Engineering & Tool AdministrationDesign, configure, implement, and maintain security platforms including SIEM, EDR/XDR, SOAR, Identity and Access Management (IAM), Data Loss Prevention (DLP), Vulnerability Management, and Cloud Security solutionsEvaluate, test, and deploy new security technologies, including Proof of Concept (POC) evaluationsDevelop automation and orchestration workflows to improve operational efficiencySupport cloud security and Zero Trust initiatives across the enterpriseDetection Engineering & Threat HuntingDevelop and tune security detections, correlation rules, and dashboards to improve threat detection capabilities and reduce false positivesPerform proactive threat hunting and analyze security telemetry across endpoint, network, identity, cloud, and SIEM platformsIdentify opportunities to improve detection and response capabilities across the environmentMonitor emerging threats, vulnerabilities, and industry best practices to inform detection strategyIncident Response & InvestigationProvide technical leadership during investigation, containment, eradication, and recovery for complex and escalated security incidentsInvestigate advanced cyber threats and complex security alertsCollect and analyze forensic artifacts, logs, and endpoint telemetry during investigationsParticipate in the on-call rotation and provide advanced technical support during critical security incidentsSupport root cause analysis and post-incident reviewsVulnerability Management & RemediationValidate vulnerability findings and coordinate remediation activities with IT Operations, Infrastructure, and Engineering teamsImplement security controls to address identified risksTrack and support remediation efforts across the vulnerability management programSecurity Operations, Mentorship & DocumentationPartner with SOC Analysts, IT Operations, Infrastructure, Cloud, and Engineering teams to implement and maintain security solutionsDevelop response playbooks, engineering standards, and operational proceduresProvide mentorship and technical guidance to SOC AnalystsCreate and maintain technical documentation supporting SOC operationsCollaborate with Neptune's MSSP and third-party security partners on engineering and investigation initiativesCompliance & Governance SupportSupport compliance initiatives aligned with NIST CSF, CIS Controls, ISO 27001, and Roper Cybersecurity requirementsRecommend improvements that strengthen Neptune's security posture, resilience, and complianceAssist with audit requests, evidence collection, and security documentationRelevant Platforms (experience with several expected):CrowdStrike FalconGoogle SecOps (Chronicle)Microsoft DefenderSIEM PlatformsEndpoint Detection and Response (EDR) PlatformsSecurity Orchestration, Automation, and Response (SOAR)Identity and Access Management (IAM) / Microsoft Entra IDData Loss Prevention (DLP)Cloud Security Platforms (AWS, Azure)Vulnerability Management PlatformsMinimum Qualifications:Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)2–5 years of experience in cybersecurity, security operations, incident response, or related technical fieldExperience investigating security alerts, detections, and cybersecurity incidentsExperience working in a Security Operations Center (SOC) environmentExperience with SIEM and EDR platformsUnderstanding of security engineering concepts, including detection engineering, automation, and security tool administrationStrong analytical, troubleshooting, and problem-solving skillsStrong written and verbal communication skillsPreferred Qualifications:Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field2–5 years of experience in Security Operations, Cybersecurity, Incident Response, Vulnerability Management, or Information TechnologyExperience with SIEM platforms such as Google SecOps, Chronicle, Splunk, QRadar, Microsoft Sentinel, or similar technologiesExperience with Endpoint Detection and Response (EDR) platforms such as CrowdStrike Falcon or Microsoft DefenderFamiliarity with the MITRE ATT&CK Framework, threat hunting, and threat intelligence methodologiesExperience supporting vulnerability management programs and remediation activitiesKnowledge of Windows, Active Directory, Microsoft Entra ID, networking fundamentals, and cloud security conceptsExperience working with AWS and/or Azure environmentsFamiliarity with NIST Cybersecurity Framework, CIS Controls, ISO 27001, and security best practicesExperience with scripting or automation using PowerShell, Python, or similar languagesCertifications (One or More Preferred):Security+CySA+GSECGCIHGCIAGCEDCISSP (Associate or Full)SC-200SC-100CrowdStrike CertificationsGoogle SecOps CertificationsAWS or Azure Security CertificationsYears of Experience (IT, Security & Compliance)2–5 years of Information Technology, Cybersecurity, Security Operations, Compliance, or Incident Response experienceEducationBachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field preferredEquivalent military, technical, or professional experience will be consideredTravel Requirements: Typically requires overnight travel less than 10% of the time.Location: Duluth, GA, Tallassee, AL#HP1Equal Opportunity Employer/Protected Veterans/Individuals with DisabilitiesThis employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.