We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security Engineer II - Security Operations Center (SOC)

CSX Corporation
United States, Florida, Jacksonville
Aug 31, 2026

Job Summary

The Security Engineer II - Security Operations Center (SOC) is responsible for monitoring, detecting, analyzing, investigating, and responding to cybersecurity threats impacting CSX systems, networks, applications, and data. This role serves as a technical contributor within the Security Operations Center and collaborates with infrastructure, engineering, application, and business teams to protect critical railroad operations and corporate assets.

The Security Engineer II leverages advanced security technologies, threat intelligence, automation, and incident response methodologies to identify and mitigate security risks while supporting continuous improvement of CSX's cybersecurity posture.

Primary Responsibilities

Security Monitoring and Incident Response

  • Monitor security alerts and events generated by SIEM, EDR, email security, cloud security, and network security platforms.

  • Investigate and respond to cybersecurity incidents including malware, phishing, ransomware, unauthorized access, data loss, insider threats, and advanced persistent threats.

  • Conduct analysis of endpoint, network, cloud, identity, and application security events.

  • Perform incident triage, containment, eradication, recovery, and post-incident documentation.

  • Participate in major incident response activities and cyber crisis management efforts.

Threat Detection and Threat Hunting

  • Conduct proactive threat hunting activities across enterprise environments.

  • Research emerging threats, adversary tactics, and attack techniques using threat intelligence sources.

  • Develop and tune detection use cases aligned with the MITRE ATT&CK framework.

  • Analyze indicators of compromise and indicators of attack.

  • Recommend improvements to detection capabilities and monitoring coverage.

Security Engineering and Operations

  • Administer and support security technologies, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Entra ID, Azure security services, email security platforms, vulnerability management solutions, and network security monitoring tools.

  • Develop and maintain security monitoring rules, analytics, dashboards, and alerting mechanisms.

  • Support the implementation, integration, testing, and operationalization of new security technologies.

Automation and Process Improvement

  • Develop and maintain security automation workflows and incident response playbooks.

  • Leverage Power Automate, Logic Apps, SOAR technologies, scripting, and AI-enabled solutions to improve operational efficiency.

  • Identify opportunities to reduce manual effort, improve alert quality, and shorten response times.

  • Contribute to SOC process optimization and continuous improvement initiatives.

Compliance and Reporting

  • Support cybersecurity compliance activities related to SOX, applicable FRA and CISA requirements, internal policies, and security standards.

  • Create accurate technical reports, executive summaries, metrics, and incident documentation.

  • Maintain evidence and records required for audits, investigations, and regulatory reporting.

Collaboration and Knowledge Sharing

  • Partner with infrastructure, cloud, network, identity, application, legal, and business teams to resolve security findings and incidents.

  • Participate in cybersecurity tabletop exercises, simulations, and readiness activities.

  • Provide mentoring and technical guidance to junior analysts and engineers.

  • Contribute to SOC procedures, runbooks, knowledge articles, and response documentation.

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.

  • 3 or more years of cybersecurity experience.

  • 2 years of experience in a Security Operations Center, incident response, security engineering, or a related security role.

  • Experience investigating security incidents across enterprise environments.

  • Experience with Microsoft security technologies and cloud security solutions

Equivalent Minimum Qualifications

  • High School Diploma/GED

  • 8 or more years of cybersecurity experience, a Security Operations Center, incident response, security engineering, or a related security role.

Preferred Qualifications

5 or more years of cybersecurity experience.

One or more of the following certifications is preferred:

  • CISSP

  • GIAC certifications such as GCIH, GCIA, or GCFA

  • Microsoft security certifications, including SC-200 or SC-100

  • CompTIA Security+ or CySA+

  • Experience in the following is preferred:

    • Railroad, transportation, critical infrastructure, or industrial environments.

    • MITRE ATT&CK-based detection engineering and threat hunting programs.

    • Security orchestration, automation, and response platforms.

    • Vulnerability management and cloud security operations.

Knowledge and Skills

  • Security Information and Event Management platforms and security analytics.

  • Endpoint Detection and Response technologies.

  • Microsoft Sentinel, Microsoft Defender XDR, Azure, and Microsoft Entra ID security.

  • Threat hunting, threat intelligence analysis, and incident response.

  • Working knowledge of Windows and Linux operating systems.

  • Networking concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, and firewalls.

  • Security automation and scripting; PowerShell, Python, and KQL are preferred.

  • Digital forensics and evidence-handling fundamentals.

  • Ability to work independently or collaboratively

  • Technical agility and strong analytical skills

Job Requirements

This position may participate in an on-call rotation and provide support during cybersecurity incidents impacting CSX operations, systems, or critical business functions.

Applied = 0

(web-665cd84569-qjw9l)