Sr. Cybersecurity Engineer, Detection & Response
On.energy
ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software, ON.energy develops projects worldwide that set new benchmarks for resilience.
ON.energy is hiring a Sr. Cybersecurity Engineer to run detection and response across the corporate security stack: the SIEM, the Defender suite, SaaS applications, and the data moving through them. A growing energy business generates significant signal across these four surfaces, and most of it currently goes unread. This is a SecOps role focused on detection ownership, response speed, and incident resolution. The underlying platforms that generate the telemetry are built and governed by other functions. This role owns turning that signal into alerts that matter and incidents that get closed.
Key Responsibilities
Detection Engineering & Incident Response
- SIEM (Microsoft Sentinel): Deploy and own Sentinel in the Defender portal, data connectors across Entra, Defender XDR, M365, AWS, and SaaS sources, plus the retention and tiering decisions that keep ingestion cost defensible.
- Detection Engineering: Write and tune analytics rules and custom detections in KQL, mapped to MITRE ATT&CK. Run the tuning board; every rule requires a documented reason to exist, and noisy rules get fixed or killed.
- Incident Response: Own the IR lifecycle end to end for anything surfaced through Sentinel: triage, containment, eradication, and written post-incident review. Maintain playbooks for top scenarios (BEC, ransomware, credential compromise, third-party breach, DLP/insider risk escalation), run tabletops with IT, Legal, and Operations leadership, and lead the corporate side of any incident that crosses into OT.
Endpoint, Email, App & Data Security
- Endpoint & Email (Defender): Own triage and response for Defender for Endpoint and Defender for Office 365 alerts: investigate, contain, and close the loop back into Sentinel detections. Does not own EDR policy architecture, ASR baselines, or the Intune device compliance program; that build sits with Endpoint/IT Engineering. Consumes their telemetry and detects against it.
- App Security (Defender for Cloud Apps): Own detection logic for risky OAuth grants, shadow IT, and anomalous app behavior, fed into Sentinel as first-class detections. Does not run the SaaS app approval and governance program itself; that's a GRC/IT governance function this role feeds, not owns.
- Data Security (Purview): Own detection and response for DLP and insider risk alerts flowing into Sentinel: investigate matches, determine real exposure, and drive the incident through to close. Does not design label taxonomy or author insider risk policy; that's a data governance function partnered with Legal and HR. Responds to what it produces.
Governance, Risk & Compliance
- Control Frameworks & Audit Support: Supply technical evidence and control-operation proof for SOC 2, ISO 27001, and NIST CSF 2.0 audits, and answer technical questions in customer security questionnaires, as directed by GRC. Does not own the audit relationship, the control framework, or the risk register; that sits with GRC. Proves the controls operated actually work.
Cloud Security
- Consume AWS GuardDuty findings into Sentinel and write detections against them. AWS security architecture and IAM least-privilege design belong to DevOps; this role owns the telemetry pipeline into the SIEM, not that surface.
Requirements
- 5+ years of hands-on security operations and detection engineering experience, with real depth in at least two of: endpoint, email, SaaS, or data security telemetry, and hands-on ownership of incident response.
Technical Stack Proficiency:
- Microsoft Sentinel: Hands-on deployment, data connectors, and detections written in KQL. Comfortable tuning for signal quality and managing ingestion cost.
- Defender suite: Working knowledge of Defender for Endpoint, Office 365, and Cloud Apps from a triage/response and detection-tuning angle, not policy architecture.
- Purview: Experience investigating DLP and insider risk alerts and translating them into incident response, not building the DLP program.
- Entra ID: Comfortable reading sign-in logs and Identity Protection risk signals for detection purposes, at a light touch. Deep Conditional Access/PIM architecture experience is not required.
- Automation: KQL, PowerShell, Graph API, or Python; sufficient to automate triage rather than perform it manually.
Required Background:
- Detection & Response Ownership: Demonstrated accountability for detection engineering and incident response outcomes across more than one telemetry source, beyond working a queue inside someone else's program.
- Incident Response: Experience leading real incidents through post-incident review, including briefing non-technical leadership.
- Compliance Support: Experience supplying technical evidence for a control framework audit (SOC 2, ISO 27001, NIST CSF, or similar) as the technical operator, without necessarily owning the audit relationship.
Core Traits:
- Hands-on: Prefers writing the KQL that proves an alert is real over describing how to write it.
- Signal-disciplined: Every rule shipped has a documented reason to exist and gets tuned or killed when it stops earning its alert volume.
- Evidence-disciplined: Documents while building, shaped by experience on the wrong side of an audit sample where the control worked but the proof did not exist.
- Clear about lanes: Able to redirect an out-of-scope request to the correct owner without stalling the incident.
Preferred:
- Experience running SecOps in a hybrid Microsoft-and-AWS environment.
- Background in energy, utilities, industrial, or another operationally critical sector, with enough IT/OT context to partner with an OT security engineer.
- Certifications: SC-200 (Security Operations Analyst), CISSP, GCIH, GCIA, or GCDA.
For US-based roles - What you’ll get:
- Competitive salary + annual performance-based bonus eligibility
- Medical, dental, and vision insurance
- 401(k) with company match
- Paid time off and company holidays
For Mexico-based roles - What you’ll get:
- Competitive salary + annual performance bonus eligibility
- Christmas Bonus (Aguinaldo): 30 days
- Major medical expenses and life insurance
- Paid time off and holidays (per local policy)
For all roles:
- Professional development and growth opportunities
- Opportunity to grow with a mission-driven team shaping the future of clean energy
- Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
- Accommodations: If you need an accommodation during the application process, email View email address on jobs.jobcopilot.com
- Benefits vary by role and location and are subject to change.
Agency Notice: ON.energy does not accept unsolicited resumes from staffing agencies, search firms, or third-party recruiters. Resumes submitted without a fully executed Master Services Agreement (MSA) and a written request from an authorized member of our Talent Acquisition team will be considered the property of ON.energy. No placement fees or compensation will be paid for unsolicited candidate submissions.
$90.4k - $168.2k
...Senior Associate, Content Development, Detection Engineering & Automation to join our Enterprise Security Services organization.Responsibilities:Execute the end-to-end engineering... ...threat intelligence enrichment, and other cybersecurity functions to drive down Mean Time to...SeniorH1bLocal area- ...The position plays a hands-on role in threat detection, incident response, vulnerability management, and SIEM engineering, while partnering with IT and application... ...security. Familiarity with gaming commission cybersecurity requirements or other regulated industry...SeniorRemote workVisa sponsorshipWork visa
$134.5k - $265.1k
...opportunities businesses face in cybersecurity. Deloitte’s Cyber team helps... ...As a Cyber Forward Deployed Engineer (FDE) Manager, you will lead... ..., GPT-4o, Assistants API, Responses API, OpenAI Agents... ..., cloud security, identity, detection engineering).Experience with...SeniorLocal areaVisa sponsorship$105.4k - $207.8k
...Cisco Network Security Engineer/ Senior Consultant, Strategy... ...opportunities businesses face in cybersecurity. Join our team to deliver powerful... ...the Cyber team, you will be responsible for…Designing, deploying,... ...with Cisco Extended Detection and Response (XDR), Cisco SecureX...SeniorWork experience placementLocal areaVisa sponsorship- Job Posting: Sr Cybersecurity TechnologistJob DescriptionComplete Logistical Services is excited to announce an opening for a Sr Cybersecurity... ...-person collaboration and immediate availability for crisis response and secure operations management. This is not a remote job,...SeniorContract workTemporary workImmediate start
- ...& Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the... ...to-control mapping, attestation drafting, drift detection, and audit-package assembly.This position belongs...SeniorFull timeLocal area
$105.4k - $207.8k
...Palo Alto Networks Security Engineer/ Senior Consultant, Strategy... ...opportunities businesses face in cybersecurity. Join our team to deliver... ...Security team, you will be responsible for…Designing, deploying,... ...prevention system/intrusion detection system (IPS/IDS), Anti-Spyware...SeniorWork experience placementLocal areaRemote work$168k - $195k
...highly skilledSenior Cyber Security Engineer - SIEM and Automation to lead and enhance our detection engineering capabilities. This role is responsible for developing high-fidelity use... ...QualificationsTechnical RequirementsBachelor’s degree in Cybersecurity, Computer Science, or related field...SeniorFull timeWork at officeLocal areaImmediate startRemote workRelocation- ...more sustainable future. For more information, please visit fluenceenergy.com.Job Description:Role OverviewThe Senior Cybersecurity Engineer is responsible for implementing and advancing cybersecurity engineering practices across Fluence software products, operational...SeniorFull timeVisa sponsorshipWork visa
- ...enterprise systems across corporate and manufacturing environments. This hands-on role emphasizes security monitoring, threat detection, and incident response while aligning IT, OT, and business teams to strengthen security posture. The Senior Analyst will implement controls,...Senior
- ...Rdc in Houston, Texas, is looking for a cybersecurity professional to manage threats and... ...involves analyzing alerts, providing incident detection, and maintaining documentation.... ...in IT, with 5 years focused on Incident Response, along with relevant security certifications...SeniorWork at office
$134.5k - $265.1k
...12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Cyber Defense... ...Management (CTEM) team, you will be responsible for…Leading day-to-day forward... ...Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information...SeniorLocal area$136.1k - $170.3k
...safer and shorter in duration; they add cybersecurity, automation, and communication. They... .... As a Senior Power Systems Consulting Engineer in Engineering Services, you’ll provide... ...and operation of engineered solutions.Responsible for environmental, health and safety leadership...SeniorFull timeApprenticeshipWorldwideFlexible hours- Complete Logistical Services is seeking a Sr Cybersecurity Technologist for an on-site, contract role. The specialist will lead security operations, configure Palo Alto NGFWs, and drive incident response initiatives to protect critical networks. Responsibilities include...SeniorContract work
- ...Sr. Controls EngineerQuaise Energy is unlocking Earth's deep heat to deliver clean... ...everywhere.The Senior Controls Engineer will be responsible for control and instrumentation design... ...implement robust interlock, safety, and fault-detection systems for high-power and high-...SeniorWork at office
$105.4k - $207.8k
...challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful... ...ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Deloitte Cyber team, you will be responsible for:Supporting the design and...SeniorLocal areaVisa sponsorship- ...readiness. Patriot is seeking an experienced Cybersecurity Analyst / Engineer to build, operate, and mature the organization'... ...Conditional Access policies, tuning Sentinel detection rules, or leading an incident response tabletop. They bring a government contractor...Full timeContract workFor contractors
$134.5k - $265.1k
...practice as a Forward Deployed Security Engineer and help organizations secure their... ...the Cloud Cyber Risk team, you will be responsible for:Embed directly with client cloud and... ...years of experience in cloud security, cybersecurity, technology risk, or technology consulting...SeniorVisa sponsorship- Reliability Engineering Design, implement, and operate scalable, resilient, and highly available... ...access-control practices. Partner with cybersecurity and identity teams to ensure... ...service restoration, and lead incident response when appropriate. Facilitate blameless...SeniorRemote work
$124k - $280k
...SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance -... ...professional and technical standards.Responsibilities- Leading the development and... ...complex regulatory landscapes- Managing cybersecurity risk management initiatives to protect...SeniorFull timeH1b- ...ENTRUST’s Power Generation group as a part-time or full-time Sr. Consulting Engineer focused on supporting generator engineering activities.... ...conceptual design through operation and maintenance. Responsibilities:In this role, you will serve as a subject matter expert and...SeniorFull timePart timeWork at officeRemote workWork from homeFlexible hours
$120k - $150k
Join ENTRUST's Power Generation group as a fulltime-Sr. Consulting Engineer focused on supporting steam turbines engineering activities. This... ...conceptual design through operations and maintenance.Responsibilities:As a key member of our, you will serve as the subject matter...SeniorFull timeWork at officeRemote workWork from homeFlexible hours- ...exciting time to join our team of employee-owners. This opportunity entails being responsible for the production and modification of design calculations, technical reports, engineering plans and specifications for assigned projects. This position consults with the project...SeniorFull time
$77k - $202k
...Description & SummaryAt PwC, our people in cybersecurity focus on protecting organisations from... ...In cloud security at PwC, you will be responsible for designing, implementing and... ...You Apart- Master's Degree in Computer Engineering, Computer Programming, Computer Science...SeniorFull timeH1b- ...Lead Energy Storage Cybersecurity Engineer / Cybersecurity Architect Location: FULLY... ...Executive Leadership Team..and more. RESPONSIBILITIES: Drive the cybersecurity... ...operations: Create repeatable frameworks to detect events, quantify feasibility,...Full timeRemote workFlexible hours
- ...you have a passion for solving complex engineering challenges and developing world-class turbomachinery... ...solutions? Air Products is seeking a Sr PrincipalMechanical Engineer to join... ...teams. To learn more, visit .Key Job Responsibilities:Perform various turbomachinery design...SeniorFull timeWork at officeImmediate startRemote workWorldwide
- Primoris Engineering is currently seeking a licensed Senior Mechanical Engineer to join our Houston-based team! In this dynamic role... ...production pads, gathering pipelines and tank batteries.Typical Job Responsibilities Rotating and Static Equipment- Sizing Calculations for...SeniorFull timeWork at office
- ...Working as part of a collaborative engineering team, this individual will contribute... ...lunar exploration initiatives. Key Responsibilities Support the design, development, and... ...navigation, image processing, feature detection, or optical navigation techniques....Senior
- Title:Sr. Mechanical Engineer (Flight Hardware Development)Belong. Connect. Grow. with KBR! Around here, we define the future.We are a company... ...dreamers. But we all share one goal: to improve the world responsibly and safely.The Senior Mechanical Engineer will participate...SeniorFull timeContract workFor contractorsWork experience placementLocal areaFlexible hours
- The Senior Systems Engineer - Predictive Fleet Intelligence is the engineering authority responsible for defining how fleet health is monitored, how developing equipment failures are detected, and how engineering knowledge is transformed into scalable digital solutions...SeniorRemote workNight shiftWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Cybersecurity Engineer, Detection & Response. Be the first to apply!
- senior maintenance supervisor Houston, TX
- senior lead project manager Houston, TX
- senior robotics software engineer Houston, TX
- senior firewall engineer Houston, TX
- senior devops engineer remote Houston, TX
- senior sas administrator Houston, TX
- senior IT manager Houston, TX
- senior director of client services Houston, TX
- senior contracts analyst Houston, TX
- senior implementation consultant Houston, TX



