Job Description:
We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position — you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership.
The Senior Cybersecurity Engineer is a fully onsite role in Columbus, Ohio. Remote work is not available. Applicants must be authorized to work in the United States for any employer.
Responsibilities
Administer and improve WAF platforms — managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives
Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions
Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications
Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation
Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future
Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure
Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix
Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4
Administer and secure Google Workspace identity — MFA, access controls, account lifecycle, least privilege — and investigate suspicious sign-ins and identity-related alerts
Qualifications
Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform)
Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS
Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging
Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations
Experience with vulnerability management, penetration testing, threat hunting, and incident response
Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure
Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks
Strong communicator who can work independently and partner effectively with technical and business stakeholders
Preferred Experience
Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware
Python or other scripting experience for security automation, detections, and SIEM workflow development
Background in ethical hacking, application security, digital forensics, or OSINT
Familiarity with DevSecOps, IaC, containers, and cloud-native services
Awareness of AI security risks and secure use of generative AI
Security or cloud certifications are a plus but not required
By applying to Rogue, regardless of the platform you choose to use, you are agreeing to Rogue's preferred methods of communication (i.e. text message). Submitting an application, through whatever online forum is ultimately used, constitutes a knowing and voluntary agreement to send and receive text messages during the recruitment process.
Discover exciting opportunities in biotechnology. Join innovative companies that are advancing healthcare and life sciences through cutting-edge research and development.
Interested in building your career at Rogue Fitness? Get future opportunities sent straight to your email.
Create AlertDiscover similar positions that might interest you
Rogue Fitness
Rogue Fitness
Rogue Fitness
Rogue Fitness
Rogue Fitness
Rogue Fitness