SonicJobs Logo
Left arrow iconBack to search

Security Engineer II - Security Operations Center (SOC)

CSX Transportation
Posted a day ago, valid for a month
Location

Jacksonville, FL, US

Salary

Competitive

Contract type

Full Time

Wellness Program

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Security Engineer II - Security Operations Center (SOC) is responsible for monitoring and responding to cybersecurity threats affecting CSX systems and networks.
  • This role requires a Bachelor's degree in Cybersecurity or a related field and a minimum of 3 years of cybersecurity experience, including 2 years in a SOC or incident response role.
  • Key responsibilities include security monitoring, incident response, threat detection, and collaboration with various teams to enhance CSX's cybersecurity posture.
  • The position offers an annual salary range based on experience and qualifications, along with an annual bonus opportunity.
  • CSX values employee development and safety, providing competitive compensation and a comprehensive benefits package to support overall well-being.

Job Summary

The Security Engineer II - Security Operations Center (SOC) is responsible for monitoring, detecting, analyzing, investigating, and responding to cybersecurity threats impacting CSX systems, networks, applications, and data. This role serves as a technical contributor within the Security Operations Center and collaborates with infrastructure, engineering, application, and business teams to protect critical railroad operations and corporate assets.

The Security Engineer II leverages advanced security technologies, threat intelligence, automation, and incident response methodologies to identify and mitigate security risks while supporting continuous improvement of CSX's cybersecurity posture.

Primary Responsibilities

Security Monitoring and Incident Response

  • Monitor security alerts and events generated by SIEM, EDR, email security, cloud security, and network security platforms.

  • Investigate and respond to cybersecurity incidents including malware, phishing, ransomware, unauthorized access, data loss, insider threats, and advanced persistent threats.

  • Conduct analysis of endpoint, network, cloud, identity, and application security events.

  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.

  • Participate in major incident response activities and cyber crisis management efforts.

 

Threat Detection and Threat Hunting

 

  • Conduct proactive threat hunting activities across enterprise environments.

  • Research emerging threats, adversary tactics, and attack techniques using threat intelligence sources.

  • Develop and tune detection use cases aligned with the MITRE ATT&CK framework.

  • Analyze indicators of compromise and indicators of attack.

  • Recommend improvements to detection capabilities and monitoring coverage.

 

Security Engineering and Operations

 

  • Administer and support security technologies, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Entra ID, Azure security services, email security platforms, vulnerability management solutions, and network security monitoring tools.

  • Develop and maintain security monitoring rules, analytics, dashboards, and alerting mechanisms.

  • Support the implementation, integration, testing, and operationalization of new security technologies.

 

Automation and Process Improvement

 

  • Develop and maintain security automation workflows and incident response playbooks.

  • Leverage Power Automate, Logic Apps, SOAR technologies, scripting, and AI-enabled solutions to improve operational efficiency.

  • Identify opportunities to reduce manual effort, improve alert quality, and shorten response times.

  • Contribute to SOC process optimization and continuous improvement initiatives.

 

Compliance and Reporting

 

  • Support cybersecurity compliance activities related to SOX, applicable FRA and CISA requirements, internal policies, and security standards.

  • Create accurate technical reports, executive summaries, metrics, and incident documentation.

  • Maintain evidence and records required for audits, investigations, and regulatory reporting.

 

Collaboration and Knowledge Sharing

 

  • Partner with infrastructure, cloud, network, identity, application, legal, and business teams to resolve security findings and incidents.

  • Participate in cybersecurity tabletop exercises, simulations, and readiness activities.

  • Provide mentoring and technical guidance to junior analysts and engineers.

  • Contribute to SOC procedures, runbooks, knowledge articles, and response documentation.

 

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.

  • 3 or more years of cybersecurity experience.

  • 2 years of experience in a Security Operations Center, incident response, security engineering, or a related security role.

  • Experience investigating security incidents across enterprise environments.

  • Experience with Microsoft security technologies and cloud security solutions

 

Equivalent Minimum Qualifications

  • High School Diploma/GED

  • 8 or more years of cybersecurity experience, a Security Operations Center, incident response, security engineering, or a related security role.

 

Preferred Qualifications

5 or more years of cybersecurity experience.

One or more of the following certifications is preferred:

  • CISSP

  • GIAC certifications such as GCIH, GCIA, or GCFA

  • Microsoft security certifications, including SC-200 or SC-100

  • CompTIA Security+ or CySA+

  • Experience in the following is preferred:

    • Railroad, transportation, critical infrastructure, or industrial environments.

    • MITRE ATT&CK-based detection engineering and threat hunting programs.

    • Security orchestration, automation, and response platforms.

    • Vulnerability management and cloud security operations.

 

Knowledge and Skills

  • Security Information and Event Management platforms and security analytics.

  • Endpoint Detection and Response technologies.

  • Microsoft Sentinel, Microsoft Defender XDR, Azure, and Microsoft Entra ID security.

  • Threat hunting, threat intelligence analysis, and incident response.

  • Working knowledge of Windows and Linux operating systems.

  • Networking concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, and firewalls.

  • Security automation and scripting; PowerShell, Python, and KQL are preferred.

  • Digital forensics and evidence-handling fundamentals.

  • Ability to work independently or collaboratively

  • Technical agility and strong analytical skills

 

Job Requirements

This position may participate in an on-call rotation and provide support during cybersecurity incidents impacting CSX operations, systems, or critical business functions.


CSX is passionate about building a workforce that reflects the values and behaviors of ONE CSX. We are nationally recognized for our commitment to diversity and engagement, as well as our support for veterans and reservists. 
CSX, based in Jacksonville, Florida, is a premier transportation company. It provides rail, intermodal and rail-to-truck transload services and solutions to customers across a broad array of markets, including energy, industrial, construction, agricultural, and consumer products. For nearly 200 years, CSX has played a critical role in the nation's economic expansion and industrial development. Its network connects every major metropolitan area in the eastern United States, where nearly two-thirds of the nation's population resides. It also links more than 230 short-line railroads and more than 70 ocean, river and lake ports with major population centers and farming towns alike. More information about CSX Corporation and its subsidiaries is available at www.csx.com. Connect with us on Facebook  X  LinkedIn  Instagram   YouTube

Closing Statement

At CSX, two of our six Guiding Principles are Valuing and Developing Employees as well as Operating Safely. We are committed to offering our team members the most competitive compensation and benefits package available, unlimited opportunities for development and growth throughout an exciting and rewarding career, and the safest work environment possible.
CSX is an Equal Opportunity Employer Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Click here to view the EEO is Law poster. 
CSX Transportation and its subsidiaries are not seeking outside assistance or accepting unsolicited resumes from staffing agencies or search firms for employment or contractor opportunities. Any resumes submitted by an outside vendor to any employee at CSX via e-mail, Internet, or directly to hiring managers without a valid written search agreement in place with the Talent Acquisition / HR department will be deemed the sole property of CSX. No placement fee will be paid in the event a candidate is hired as a result of the referral, or through other means.
This role offers an annual salary range based on experience and qualifications. In addition to base salary we provide an annual bonus opportunity. 
At CSX, we prioritize valuing and developing employees, as well as operating safely. We are committed to offering our team members competitive compensation, a comprehensive benefits package, and unlimited growth opportunities. Our benefits support financial, physical, emotional, and social well-being, with health plans, wellness programs, and customizable coverage options. Learn more about our benefits here. 



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.