Rogue Fitness company logo

Rogue Fitness is hiring a Senior Cybersecurity Engineer

Get the latest jobs to your inbox!

Job Description

Job Description:

 

We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position — you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership.

The Senior Cybersecurity Engineer is a fully onsite role in Columbus, Ohio. Remote work is not available. Applicants must be authorized to work in the United States for any employer.

Responsibilities

  • Administer and improve WAF platforms — managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives

  • Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions

  • Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications

  • Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation

  • Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future

  • Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure

  • Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix

  • Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4

  • Administer and secure Google Workspace identity — MFA, access controls, account lifecycle, least privilege — and investigate suspicious sign-ins and identity-related alerts

Qualifications

  • Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform)

  • Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS

  • Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging

  • Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations

  • Experience with vulnerability management, penetration testing, threat hunting, and incident response

  • Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure

  • Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks

  • Strong communicator who can work independently and partner effectively with technical and business stakeholders

Preferred Experience

  • Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware

  • Python or other scripting experience for security automation, detections, and SIEM workflow development

  • Background in ethical hacking, application security, digital forensics, or OSINT

  • Familiarity with DevSecOps, IaC, containers, and cloud-native services

  • Awareness of AI security risks and secure use of generative AI

  • Security or cloud certifications are a plus but not required

By applying to Rogue, regardless of the platform you choose to use, you are agreeing to Rogue's preferred methods of communication (i.e. text message). Submitting an application, through whatever online forum is ultimately used, constitutes a knowing and voluntary agreement to send and receive text messages during the recruitment process.

Sponsored
⭐ Featured Partner

Explore Biotech Careers

Discover exciting opportunities in biotechnology. Join innovative companies that are advancing healthcare and life sciences through cutting-edge research and development.

Remote FriendlyCompetitive SalaryBiotech

Create a Job Alert

Interested in building your career at Rogue Fitness? Get future opportunities sent straight to your email.

Create Alert

Related Opportunities

Discover similar positions that might interest you