Sr. Cybersecurity Engineer, Detection & Response
at On.Energy · 101-250 employees
- Seniority
- Senior
- Location
- Houston, Texas, United States
- Posted
- 5d ago
at On.Energy · 101-250 employees
On.Energy is a Miami-headquartered independent power producer that develops, integrates and operates AI-driven battery energy storage systems across the Americas.
<div class="content-intro"><p>ON.energy<span class="Apple-converted-space"> </span>is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software,<span class="Apple-converted-space"> </span>ON.energy<span class="Apple-converted-space"> </span>develops projects worldwide that set new benchmarks for resilience.</p></div><p><span class="TextRun SCXW210981829 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SpellingErrorV2Themed SCXW210981829 BCX0">ON.energy</span><span class="NormalTextRun SCXW210981829 BCX0"> is hiring a </span></span><span class="TextRun MacChromeBold SCXW210981829 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW210981829 BCX0">Sr. Cybersecurity Engineer</span></span><span class="TextRun SCXW210981829 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW210981829 BCX0"> to run detection and response across the corporate security stack: the SIEM, the Defender suite, SaaS applications, and the data moving through them. A growing energy business generates significant </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW210981829 BCX0">signal</span><span class="NormalTextRun SCXW210981829 BCX0"> across these four surfaces, and most of it currently goes unread. This is a SecOps role focused on </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW210981829 BCX0">detection</span><span class="NormalTextRun SCXW210981829 BCX0"> ownership, response speed, and incident resolution. The underlying platforms that generate </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW210981829 BCX0">the telemetry</span><span class="NormalTextRun SCXW210981829 BCX0"> are built and governed by other functions. This role owns turning that signal into alerts that matter and incidents that get closed.</span></span><span class="EOP Selected SCXW210981829 BCX0" data-ccp-props="{"335559739":200}"> </span></p> <h3><strong><span class="EOP Selected SCXW210981829 BCX0" data-ccp-props="{"335559739":200}">Key Responsibilities</span></strong></h3> <p><span data-contrast="none"><span data-ccp-parastyle="heading 3">Detection Engineering & Incident Response</span></span><span data-ccp-props="{"335559738":200,"335559739":80}"> </span></p> <ul> <li><span data-contrast="auto">SIEM (Microsoft Sentinel): </span><span data-contrast="auto">Deploy and own Sentinel in the Defender portal, data connectors across Entra, Defender XDR, M365, AWS, and SaaS sources, plus the retention and tiering decisions that keep ingestion cost defensible.</span><span data-ccp-props="{"335559739":120}"> </span></li> <li><span data-contrast="auto">Detection Engineering: </span><span data-contrast="auto">Write and tune analytics rules and custom detections in KQL, mapped to MITRE ATT&CK. Run the tuning board; every rule requires a documented reason to exist, and noisy rules get fixed or killed.</span><span data-ccp-props="{"335559739":120}"> </span></li> <li><span data-contrast="auto">Incident Response: </span><span data-contrast="auto">Own the IR lifecycle end to end for anything surfaced through Sentinel: triage, containment, eradication, and written post-incident review. Maintain playbooks for top scenarios (BEC, ransomware, credential compromise, third-party breach, DLP/insider risk escalation), run tabletops with IT, Legal, and Operations leadership, and lead the corporate side of any incident that crosses into OT.</span><span data-ccp-props="{"335559739":120}"> </span></li> </ul> <p><span data-contrast="none"><span data-ccp-parastyle="heading 3">Endpoint, Email, App & Data Security</span></span><span data-ccp-props="{"335559738":200,"335559739":80}"> </span></p> <ul> <li><span data-contrast="auto">Endpoint & Email (Defender): </span><span data-contrast="auto">Own triage and response for Defender for Endpoint and Defender for Office 365 alerts: investigate, contain, and close the loop back into Sentinel detections. Does not own EDR policy architecture, ASR baselines, or the Intune device compliance program; that build sits with Endpoint/IT Engineering. Consumes their telemetry and detects against it.</span><span data-ccp-props="{"335559739":120}"> </span></li> <li><span data-contrast="auto">App Security (Defender for Cloud Apps): </span><span data-contrast="auto">Own detection logic for risky OAuth grants, shadow IT, and anomalous app behavior, fed into Sentinel as first-class detections. Does not run the SaaS app approval and governance program itself; that's a GRC/IT governance function this role feeds, not owns.</span><span data-ccp-props="{"335559739":120}"> </span></li> <li><span data-contrast="auto">Data Security (Purview): </span><span data-contrast="auto">Own detection and response for DLP and insider risk alerts flowing into Sentinel: investigate matches, determine real exposure, and drive the incident through to close. Does not design label taxonomy or author insider risk policy; that's a data governance function partnered with Legal and HR. Responds to what it produces.</span><span data-ccp-props="{"335559739":120}"> </span></li> </ul> <p><span data-contrast="none"><span data-ccp-parastyle="heading 3">Governance, Risk & Compliance</span></span><span data-ccp-props="{"335559738":200,"335559739":80}"> </span></p> <ul> <li><span data-contrast="auto">Control Frameworks & Audit Support: </span><span data-contrast="auto">Supply technical evidence and control-operat