Rhodian Group Logo

Rhodian Group

Cybersecurity Engineer - Level 2

Reposted 25 Days Ago
Remote
Hiring Remotely in United States
Junior
Remote
Hiring Remotely in United States
Junior
Monitor, triage, and investigate security alerts from SIEM/EDR; perform incident response, root-cause analysis, threat hunting, SIEM tuning, documentation, and escalate complex incidents to senior teams.
The summary above was generated by AI

About Rhodian Group

Rhodian Group helps businesses build and manage their network environments with predictably priced managed IT services so they can focus on their core strengths and growth initiatives. They also help businesses identify and reduce cybersecurity and non-compliance risks. Their combination of IT, cybersecurity, and compliance services helps businesses operate safely, while complying with industry mandates and regulatory requirements.

Role Overview 

The Cybersecurity Level 2 Engineer plays a critical role in the Security Operations Center (SOC), responsible for monitoring, investigating, and responding to security alerts and incidents across client or enterprise environments. This role requires hands-on experience with SIEM platforms, endpoint security tools, and incident response processes, with the ability to escalate and remediate threats effectively. 


Key Responsibilities 

  • Monitor and triage security alerts generated by SIEM, EDR, and security monitoring tools 
  • Investigate security incidents including phishing, malware, endpoint compromise, and unauthorized access 
  • Perform root-cause analysis and document incident findings and remediation actions 
  • Tune SIEM detection rules, alerts, and dashboards to reduce false positives and improve fidelity 
  • Conduct threat hunting activities using logs from endpoints, networks, cloud platforms, and identity providers 
  • Respond to security incidents in accordance with established incident response playbooks and SLAs 
  • Escalate complex or high-risk incidents to Level 3 or Incident Response teams with detailed context and evidence 
  • Assist with vulnerability management findings and validation of remediation 
  • Support log ingestion, parsing, normalization, and retention requirements for SIEM platforms 
  • Maintain accurate case notes, incident reports, and security documentation 
  • Collaborate with IT, engineering, and security teams to improve overall security posture 


Required Qualifications 

  • 2+ years of hands-on experience in a SOC, cybersecurity, or security operations role 
  • Practical experience working with SIEM platforms (Splunk, Microsoft Sentinel, LogRhythm, QRadar, Elastic) 
  • Experience analyzing logs from endpoints, firewalls, IDS/IPS, cloud, and identity systems 
  • Familiarity with EDR tools (CrowdStrike, SentinelOne, Microsoft Defender, Datto EDR) 
  • Understanding of the incident response lifecycle and security alert triage 
  • Working knowledge of common attack techniques and indicators of compromise (IOCs) 
  • Experience with the MITRE ATT&CK framework 
  • Strong documentation and communication skills 


Preferred Qualifications 

  • Experience in an MSP or multi-tenant SOC environment 
  • Familiarity with SOAR tools and automation workflows 
  • Exposure to cloud security logging (Azure, AWS, Microsoft 365) 
  • Experience with vulnerability scanning tools (Qualys, Nessus, Rapid7) 
  • Basic scripting or query experience (KQL, SPL, SQL, PowerShell, Python) 
  • Relevant certifications: Security+, CySA+, SC-200, Splunk Core Certified User 


What Success Looks Like 

  • Security alerts are investigated accurately and efficiently 
  • Incidents are escalated with high-quality analysis and evidence 
  • SIEM detections improve over time through tuning and feedback 
  • Threats are identified early, contained effectively, and documented clearly 
  • Strong collaboration with SOC peers and senior security engineers 
HQ

Rhodian Group New York, New York, USA Office

New York, NY, United States

Similar Jobs

20 Minutes Ago
Easy Apply
Remote or Hybrid
Easy Apply
102K-128K Annually
Junior
102K-128K Annually
Junior
Cloud • Information Technology • Security • Software • Cybersecurity
Drive automation-first reliability for a global, multi-cloud platform: build scalable infra (AWS/GCP/bare-metal), write automation (Python/Go), implement observability (Prometheus/Grafana/OpenTelemetry), lead incident response/on-call, define SLIs/SLOs, and partner on operability reviews and post-incident analysis.
Top Skills: AnsibleAWSAzureBgpC/C++DnsGCPGoGrafanaGreHaproxyHelmIpsecItilLinuxOpentelemetryPrometheusPythonRhelTemporalTerraform
26 Minutes Ago
Remote or Hybrid
118K-201K Annually
Senior level
118K-201K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Lead supplier quality for Printed Wiring Boards: audit suppliers, perform source and first-article inspections, drive root-cause analysis and corrective actions, implement process improvements, and ensure compliance with PWB and aerospace standards to deliver first-time quality.
Top Skills: ApqpAs9100As9102Asme Y14.5Asme Y15.1Black BeltControl PlanFirst Article InspectionGreen BeltIpc-6012Ipc-6013Ipc-6018Ipc-A-600Ipc-A-610Ipc-Tm-650Lean Six SigmaMil-Prf-31032Mil-Prf-38534Mil-Prf-55110Mil-Std-883PfmeaPpapSource Inspection
26 Minutes Ago
Remote or Hybrid
District of Columbia, USA
127K-215K Annually
Mid level
127K-215K Annually
Mid level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Support and maintain complex applications and infrastructure for a government customer: monitor and triage events, troubleshoot Linux/Windows servers, deploy and integrate software (AWS, CloudFormation, RDS), use Salt for configuration management, work with databases (Oracle, MongoDB, PostgreSQL, MySQL), write SOPs, manage security groups, and support after-hours deployments. Requires strong communication and collaboration with developers and vendors.
Top Skills: AWSCloudFormationElasticsearchJavaScriptLinuxMongoDBMySQLOraclePostgresPythonRdsSaltstackWindows Server

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account