Skip to content
โ† Back to job listings

Cybersecurity Engineer

Evolution Cloud Services (EVOCS) ยท Remote, United States

CybersecurityRemoteExternal listingfull-timeabout 2 hours ago

About The Role

EVOCS OVERVIEW

EVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.

As an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.

Today, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.

Cybersecurity Engineer

Full-time, permanent | Remote, United States | Reports to the Director of Cybersecurity

๐ŸŽฏ Role Overview

You'll join a team that's still building -- hands-on work across detection, telemetry, and vulnerability analysis on live client environments, with findings that hold up under review.

You will be responsible for the work behind the work: tuning detections, onboarding log sources, analyzing telemetry and configurations at scale, and turning scanner output and evidence into findings a client's security leadership can act on.

๐Ÿงฉ What You Will Do

  • Log source onboarding. Connect, parse, and validate telemetry sources into a SIEM. Confirm what is actually arriving, in what fidelity, and what is silently missing.
  • Telemetry and configuration analysis. Extract and analyze firewall configurations, log data, and device state at fleet scale to support security assessments, and pull the evidence that sits behind a finding.
  • Detection engineering. Write and tune detection logic, cut false positives on noisy rules, and build content for coverage gaps found during engagements. Platforms vary by client, so what matters is that you have done this somewhere, not that you have done it in one product.
  • Vulnerability analysis. Turn scanner output into a prioritized picture using exploitability and asset criticality rather than raw CVSS, and track remediation to closure.
  • Evidence and documentation. Assemble the evidence behind findings so each one is traceable and defensible under review.
  • First drafts. Draft findings, report sections, and weekly status reports to a standard that needs review rather than rewriting.
  • Automation. Build playbooks, scripts, and tooling that take repetitive work out of engagements.
  • Research. Advisory and CVE analysis, platform and tooling comparisons, and technical research that feeds client recommendations.

๐Ÿง  What You Will Bring

  • 3 to 5 years hands-on in cybersecurity: SOC, detection engineering, security engineering, or an MSSP delivery team. Hands on keyboard, not coordination.
  • Real SIEM and SOAR experience on any platform, commercial or open source. Splunk, Sentinel, Elastic, Wazuh, Security Onion, Graylog, TheHive, Shuffle: we do not care which. We care that you have built and tuned detections in it, not only watched its dashboards.
  • Detection logic you can write from scratch. KQL, SPL, EQL, Lucene, Sigma, or equivalent. You should be able to walk through a rule you wrote, why you wrote it that way, and what it missed.
  • Blue team background. Alert triage and investigation experience, and MITRE ATT&CK as something you have applied rather than read about.
  • Network literacy. You can read a firewall configuration and rule base and understand zones, segmentation, and what a rule actually permits. You do not need to be a firewall engineer; you need to not be lost in the data.
  • Enterprise or data center IT experience: a real production environment with change control and uptime pressure, not only a lab.
  • Scripting for analysis and automation (Python, Bash, PowerShell, or equivalent).
  • Writing that survives light review. Much of your output becomes material a client's security leadership reads.
  • Willingness to say what the data does not support. Overstating a conclusion is the one habit that does not work here.

๐Ÿ› ๏ธ Show Us What You Build

The strongest people in this field tinker. If security is something you work on outside work hours, that counts here as much as anything on your resume, and at this experience level it often counts more.

  • A home lab: a SIEM you stood up yourself, a detection lab, an attack range, anything you broke and rebuilt.
  • A GitHub profile: scripts, parsers, detection rules, automation, tools you wrote because something annoyed you.
  • Published detection content, Sigma rules, or contributions to open-source security projects.
  • CTFs, HackTheBox, TryHackMe, or writeups and talks explaining something technical to other people.
  • Send links. A good repo will get you further with us than another certification.
  • โญ What Will Make You Stand Out
  • Certifications: SC-200, AZ-500, CySA+, or GIAC or any other relevant cert.
  • Microsoft security stack experience (Defender, Entra, Azure security), which appears frequently in our client environments.
  • Fortinet exposure (FortiGate, FortiManager, FortiAnalyzer) or equivalent enterprise firewall platform experience.
  • Vulnerability management tooling (Tenable, Rapid7, Qualys).
  • Data center, colocation, critical infrastructure, or OT-adjacent environments.
  • Threat hunting, SOAR, or automation development.

๐Ÿค How We Will Work Together

You will not be sent into client meetings alone or handed an engagement to run before you are ready. Scope, severity calls, and client communication sit with the Director of Cybersecurity. Your work goes through review, and that review is where you will learn fastest. As your judgment develops, you take on more, including leading pieces of engagements outright.

You will move between detection work, assessment analysis, and vulnerability work in the same week, across several client engagements at once. If you want to sit inside one platform doing one thing, this is the wrong role.

#LI-Remote

Pay Range for jobs in the US.

Pay Range

$80,000 — $100,000 USD

๐Ÿ‘ฅ Our Values

We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.

The values we live by

  • Customer-centric Solutions
  • Innovation & Excellence
  • Integrity & Transparency
  • Data-driven Decision Making

๐Ÿ“ Need to Know

The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing