AVP Cyber Security Engineer

Company: Nicoll Curtin
Apply for the AVP Cyber Security Engineer
Location:
Job Description:

Overview

In this role you will strengthen the organisation’s security posture by building proactive defense capabilities across on-premise and cloud environments. You will work within the Proactive Security function to develop threat models, implement automation, and lead detection engineering and incident response efforts. You’ll collaborate with infrastructure, cloud, and security operations teams to translate threat intel into practical monitoring and safeguards. This is a hands-on position in a mature security environment with enterprise-scale impact.

Responsibilities

  • Develop and maintain threat models for critical systems and services; assess risks and propose design and implementation controls
  • Drive proactive detection, configuration monitoring, and automated remediation, including security tooling integrations and orchestration
  • Lead and enhance SOAR capabilities and identity-based threat detection, PAM, and session monitoring
  • Design, implement, and maintain SIEM workspaces, data connectors, analytics rules, dashboards, and playbooks; develop advanced threat-hunting queries
  • Onboard and optimise security log sources across on-premise and cloud (Azure/AWS/GCP); tune detections and data quality
  • Design and deploy advanced detection use cases and translate threat intel into monitoring capabilities; conduct proactive threat hunting
  • Provide expert guidance on application and infrastructure security; evaluate emerging security technologies; act as subject matter expert across cyber initiatives
  • Collaborate with cross-functional teams and stakeholders to drive security operations improvements

Key requirements

  • 5+ years in Security Engineering, Security Operations, Security Automation, or related cyber security discipline
  • Strong hands-on experience with SIEM platforms, EDR solutions, and detection engineering
  • Experience developing and supporting SOAR capabilities
  • Solid understanding of Active Directory security and Windows event logging
  • Proficiency with PowerShell and/or Python scripting
  • Good grasp of networking concepts (firewalls, VPNs, proxies, security protocols)
  • Experience securing Azure, AWS, or GCP environments
  • Knowledge of NIST, MITRE ATT&CK, and Cyber Kill Chain frameworks
  • Excellent communication and stakeholder management skills
  • communication
  • stakeholder management
  • collaboration
  • SIEM engineering
  • EDR
  • SOAR

…

Posted: October 1st, 2026