CyberSecurity & Identity Protection Engineer (Tier 3)
BlackCloak
- Location
- United States
- Workplace
- Remote
- Employment
- Full Time
- Salary
- USD 110,000–130,000/yr
Posted 2mo ago
The employer’s full description could not be read from their board. This is a summary of the posting — follow the apply link for the original.
Responsibilities
- Deploy and configure Endpoint Detection and Response (EDR) agents
- Customize detection policies to minimize false positives
- Analyze EDR telemetry to detect attacks
- Monitor client endpoints for malicious indicators
- Isolate compromised devices and communicate incident scope
- Generate monthly executive summaries for clients
- Schedule and run vulnerability scans
- Execute penetration tests
- Review scan results with clients and prioritize patches
- Monitor for threats and vulnerabilities specific to Smart Home and IoT devices
- Alert impacted clients and assist in hardening home networks
- Proactively monitor the Dark Web and criminal forums
- Work with cross-functional teams to alert clients of leaked data
- Manage the credit monitoring platform and alert clients to changes
- Serve as the dedicated case manager for confirmed identity theft incidents
- Handle end-to-end resolution process for identity theft
- Assist in the restoration of compromised accounts
- Hunt for client PII on people-search sites and data broker databases
- Manage the opt-out and removal process for PII
- Identify repetitive manual tasks and build SOAR playbooks or scripts
- Evaluate and implement AI-driven tools to enhance threat detection
- Utilize Machine Learning features to reduce alert fatigue
- Continuously assess toolset architecture
- Optimize API integrations between Identity platforms, EDR, and ticketing systems
- Conduct Post-Mortem reviews after incidents
- Recognize and codify attacker tools, tactics, and procedures
- Develop custom scripts, tools, or methodologies to enhance IR processes
- Develop comprehensive reports of forensic findings and IR activities
- Participate in on-call rotation and escalation team
- Participate in knowledge transfer sessions, product training
- Maintain working knowledge of BlackCloak’s solutions
- Mentor and support Client Success and Security Team Members
- Work closely with engineering and product teams
- Perform research and development on cyber security trends
- Work with the sales team for technical demonstrations
Requirements
- 3-5+ years of experience in Cybersecurity, Fraud Analysis, or Security Engineering
- Experience in deploying, managing, and optimizing EDR tools
- Experience developing detection alerting using automation
- Experience orchestrating detection logic to trigger responses
- Experience developing efficient security workflows
- Experience with client service
- Experience communicating complex technical concepts
- Strong analytical mind required
- Technical knowledge of operating systems such as Windows, macOS, iOS, Android, Linux
- Solid understanding of the US Credit System (Bureaus, FICO, FCRA rights)
- Experience managing identity monitoring platforms (alerts on Credit, SSN, PII)
- Operate independently and efficiently to manage multiple tasks and priorities
- High degree of interpersonal communication skills and discretion for client privacy
- Familiarity in EDR solutions, including CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, and Sophos Intercept X
- Experience with vulnerability assessments
- Experience with identity monitoring platforms
- Experience with SOAR and AI to streamline workflows
- Experience with Python/PowerShell scripting
- Experience with Machine Learning features
- Experience with API integrations
- Experience with Incident Response processes
- Experience developing reports of forensic findings and Incident Response activities
- Experience with client incidents, emergency onboardings and issues
- Experience with technical demonstrations
Preferred
- College degree in an Information Technology (IT/CS/CE) related discipline is a plus, with equivalent experience also considered
- Industry recognized information security certifications a plus: CISSP, CCSP, CFCE, GIAC, OSCP, OSCE, Security+, CEH
- Privacy and identity theft risk management certifications a plus: CIPP, CIPA
- Penetration and vulnerability testing experience
- Windows and macOS forensic investigation and vulnerability management experience
Skills
- CrowdStrike Falcon
- SentinelOne
- Microsoft Defender for Endpoint
- Carbon Black
- Sophos Intercept X
- Python
- PowerShell
- SOAR
- AI
- Machine Learning
- CISSP
- CCSP
- CFCE
- GIAC
- OSCP
- OSCE
- Security+
- CEH
- CIPP
- CIPA
Similar roles
IT Support Lead
Nadia Care · Philadelphia, Pennsylvania, United States · USD 70–80/hr · today
Cloud Infrastructure Engineer -Dallas, TX
Photon · United States · today
Network Engineer
Delart · Austin, TX · today
Computing Undergraduate Student Intern: DevOps Internship Program - Summer 2027
Llnl · Livermore, CA, United States · USD 23–32/hr · today
IT Support Assistant (Onsite - Phoenix, AZ)
Intelligent Technical Solutions · Phoenix, AZ · USD 15–16/hr · today
Senior Cloud Infrastructure Engineer
Anduril Industries · Washington · District of Columbia · United States · USD 146,000–194,000/yr · today