About The Position

This position is within FirstEnergy’s Cyber Security Operations and reports to the Manager of TSOC Technologies. As a Cyber Security Engineer supporting the Transmission Security Operations Center (TSOC), you will serve as a subject matter expert for Security Information and Event Management (SIEM) platforms that enable enterprise-wide security monitoring, threat detection, and incident response. You will be responsible for the design, implementation, integration, optimization, administration, and support of SIEM technologies and associated security data pipelines. Additionally, you will work closely with cyber security operations, infrastructure, application, and business stakeholders, to develop solutions that improve security visibility, automate detection capabilities, and strengthen FirstEnergy's cyber defense strategy. The successful candidate will have significant hands-on experience engineering and administering enterprise SIEM platforms, including log source onboarding, use case development, correlation rule creation, platform integration, and lifecycle management. This role requires a strong engineering mindset, exceptional problem-solving skills, and the ability to architect scalable and reliable cybersecurity solutions while effectively managing projects and collaborating across multiple teams.

Requirements

  • Working knowledge and/or experience in engineering, administering, and maintaining enterprise SIEM platforms, including configuring integrations upstream and downstream for ingestion and correlation activities.
  • Experience developing, maintaining, and troubleshooting scripts in Linux and/or Windows environments to automate administrative and operational tasks.
  • Knowledge of operating systems internals, hardening, and monitoring (Windows and UNIX).
  • Experience in designing, deploying, and/or supporting enterprise-scale security solutions.
  • Experience in IT systems and/or networking infrastructure is required.
  • In-depth understanding of TCP/IP network fundamentals is required.
  • Strong troubleshooting skills are required.
  • Must compose well-written, professional documents and reports.
  • Effective business communication skills which include documentation and project status communication.

Nice To Haves

  • A bachelor’s degree in Cybersecurity, Computer Science, Cyber Analytics or similar discipline is preferred. A bachelor’s degree in another field with relevant industry experience in cyber/information security will be considered.
  • Knowledge of relevant frameworks, standards, and best practices such as NIST CSF, PCI-DSS, CIS CSCs, MITRE ATT&CK, Cyber Kill Chain, etc. are a plus
  • Experience with Compliance regulations, such as NERC CIP, is a plus.

Responsibilities

  • Engineer, implement, administer, patch, maintain, and continuously improve FirstEnergy's Security Information and Event Management (SIEM) platforms and related security monitoring capabilities.
  • Assist with evaluation, design, testing, and deployment of cybersecurity technologies, including SIEM, SOAR, threat intelligence, cloud security, and other enterprise security solutions supported by the team.
  • Perform platform lifecycle management, including architecture, implementation, upgrades, patching, optimization, performance tuning, and operational support.
  • Develop and maintain technical standards, reference architectures, configuration baselines, integration patterns, and engineering documentation.
  • Design and implement automation, orchestration, detection engineering, and response capabilities to improve security operations and incident response effectiveness.
  • Perform technical activities including requirements analysis, solution design, proof-of-concept development, testing, deployment planning, and operational transition.
  • Serve as a cybersecurity subject matter expert (SME), providing technical guidance and consultation to TSOC, Cybersecurity, IT, and business stakeholders.
  • Collaborate with architecture, infrastructure, cloud, network, endpoint, identity, operational technology, and application teams to deliver secure, scalable, and supportable solutions.
  • Participate in complex cybersecurity technology projects from requirements gathering through design, deployment, testing, operational transition, documentation, and continuous improvement.
  • Work with vendors to obtain product updates, bug fixes, support engagement, and issue resolution.
  • Create and maintain clear, accurate, and comprehensive technical and operational documentation.
  • Support and provide technical expertise during cybersecurity incidents, including investigation, containment, recovery, and post-incident improvement activities.
  • Respond to support requests that are escalated to the team.
  • Participate in an On-Call rotation to support after-hours operational issues and cybersecurity incidents.
  • Ensure compliance with applicable corporate policies, regulatory requirements, and cybersecurity standards.

Benefits

  • competitive pay plus incentive compensation
  • a company-sponsored pension plan
  • 401(k) savings plan with matching employer contribution
  • a choice of medical, prescription drug, dental, vision, and life insurance programs
  • skills development training with tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service