1

Cyber Defense Engineer Jobs (NOW HIRING)

WI · On-site

$80 - $100/hr

... of cyber defense functions, including Kraken's Security Operations Center (SOC), threat intelligence, detection engineering, incident response, and continuous improvement of our detection and ...

New

Senior Cyber Defense AI Analyst

Albany, NY · On-site

$99K - $128K/yr

The Senior Cyber Defense Engineer / Analyst is a senior technical role within the Cyber Defense function. This position is responsible for selecting, engineering, maintaining, tuning, and optimizing ...

Senior Cyber Defense AI Analyst

Albany, NY · On-site

$99K - $128K/yr

The Senior Cyber Defense Engineer / Analyst is a senior technical role within the Cyber Defense function. This position is responsible for selecting, engineering, maintaining, tuning, and optimizing ...

next page

Showing results 1-20

Cyber Defense Engineer information

See salary details

$29.5K

$122.1K

$197.5K

How much do cyber defense engineer jobs pay per year?

As of Sep 9, 2026, the average yearly pay for cyber defense engineer in the United States is $122,108.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,500.00 and $149,500.00 per year, depending on experience, location, and employer.

What is a cyber defense engineer?

Cyber Defense Engineers are IT professionals who design, implement, and maintain security measures to protect an organization's computer systems and networks from cyber threats. They analyze security risks, develop strategies to safeguard sensitive information, and respond to security incidents. Their work is essential to preventing data breaches, minimizing vulnerabilities, and ensuring compliance with cybersecurity standards. Cyber Defense Engineers often collaborate with other IT and security teams to create a robust defense against evolving cyberattacks.

What are some common challenges cyber defense engineers face when responding to security incidents?

Cyber Defense Engineers often encounter challenges such as identifying the root cause of complex security breaches, managing multiple simultaneous incidents, and ensuring clear communication with stakeholders under pressure. They must balance swift response with thorough investigation to prevent data loss and minimize downtime. Collaboration with IT, legal, and executive teams is crucial, as is staying updated on emerging threats and tools to adapt defenses effectively.

What are the key skills and qualifications needed to thrive as a cyber defense engineer, and why are they important?

To thrive as a Cyber Defense Engineer, you need expertise in network security, threat analysis, intrusion detection, and a background in information technology or cybersecurity, often supported by a bachelor’s degree. Experience with security tools like SIEM platforms, firewalls, IDS/IPS systems, and certifications such as CISSP or CEH are commonly required. Strong problem-solving abilities, attention to detail, and effective communication are crucial soft skills for success in this role. These skills and qualities are vital to proactively identify, mitigate, and communicate security threats, ensuring robust protection of organizational assets.

What are popular job titles related to Cyber Defense Engineer jobs?

For Cyber Defense Engineer jobs, the most frequently searched job titles are:

Infographic showing various Cyber Defense Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $122,108 per year, or $58.7 per hour.

Cyber Defense Engineer - SIEM

Manhattan, NY • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 26 days ago


Job description

Cyber Defense Engineer – SIEM

Reports to the Director of Cyber Defense and operates within the Office of the CISO. This role is responsible for architecting, developing, and implementing advanced security solutions that enhance cyber defense investigations and incident response capabilities. The position places a strong emphasis on AI‑driven security engineering, including the development of intelligent detection systems, automation pipelines, and data‑driven defense mechanisms.

Responsibilities
  • Design, develop, and deploy AI‑enhanced detections and automations within the SIEM/SOAR platform to improve signal‑to‑noise ratio and reduce alert fatigue.
  • Engineer and optimize SIEM pipelines using AI/ML techniques for anomaly detection, behavioral analytics, and threat correlation.
  • Integrate SIEM with security tools and data sources to build a context‑rich, intelligence‑driven monitoring ecosystem.
  • Develop and implement AI‑assisted threat detection models, including user/entity behavior analytics (UEBA) and predictive analytics.
  • Collaborate with cyber defense operations to identify emerging threats and capability gaps, leveraging AI to proactively strengthen defenses.
  • Build and maintain automated response orchestration and intelligent playbooks that adapt based on threat context.
  • Design automation for alert enrichment, triage, and response using both rule‑based and AI‑assisted decisioning frameworks.
  • Partner with IT and engineering teams to ensure comprehensive telemetry collection and high‑quality data pipelines.
  • Continuously improve SIEM engineering practices, including data normalization, enrichment strategies, and AI model tuning.
  • Support SOC operations by enhancing detection engineering, incident response workflows, and operational metrics through AI augmentation.
Requirements
  • Bachelor’s degree in computer science, information security, or a related field.
  • 4–6+ years of experience in cybersecurity engineering, SOC engineering, or insider threat.
  • Demonstrated expertise in SIEM engineering and security monitoring at scale.
  • Experience integrating or developing AI/ML capabilities within security operations or detection engineering.
  • Strong understanding of the Microsoft security stack (e.g., Sentinel, Defender suite).
  • Proficiency with automation tooling and scripting languages (KQL, Python, PowerShell).
  • Proficiency in API development with the goal of integrating security tooling.
  • Familiarity with various log ingestion methodologies into a SIEM environment.
  • Experience in multi‑tenant or MSP‑like environments is a plus.
  • Highly motivated self‑starter who thrives on positively influencing the environment.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Benefits & Perks
  • Company‑Paid Lunch Stipend: Lunch is provided via GrubHub.
  • Company‑Paid Benefits: 100% Employer‑Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families.
  • 16 weeks of Paid Parental Leave.
  • Employee Assistance Program.
  • Life insurance.
  • Short‑Term and Long‑Term Disability.
  • 401(k): Company will match 100% of contributions up to 6%.
  • Optional Employee‑Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub, and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays.

EQUAL OPPORTUNITY EMPLOYER
NorthMark Strategies LLC is an equal employment opportunity employer. The company's policy is not to discriminate against any applicant or employee based on race, color, religion, national origin, gender, age, sexual orientation, gender identity or expression, marital status, mental or physical disability, or genetic information, or any other basis protected by applicable law. The firm also prohibits harassment of applicants or employees based on any of these protected categories.

#J-18808-Ljbffr