Senior Cybersecurity Engineer

Rogue FitnessColumbus, OH
Onsite

About The Position

We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position — you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership.

Requirements

  • Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform)
  • Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS
  • Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging
  • Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations
  • Experience with vulnerability management, penetration testing, threat hunting, and incident response
  • Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure
  • Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks
  • Strong communicator who can work independently and partner effectively with technical and business stakeholders

Nice To Haves

  • Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware
  • Python or other scripting experience for security automation, detections, and SIEM workflow development
  • Background in ethical hacking, application security, digital forensics, or OSINT
  • Familiarity with DevSecOps, IaC, containers, and cloud-native services
  • Awareness of AI security risks and secure use of generative AI
  • Security or cloud certifications are a plus but not required

Responsibilities

  • Administer and improve WAF platforms — managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives
  • Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions
  • Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications
  • Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation
  • Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future
  • Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure
  • Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix
  • Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4
  • Administer and secure Google Workspace identity — MFA, access controls, account lifecycle, least privilege — and investigate suspicious sign-ins and identity-related alerts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service