Jobs and Careers
ON

Sr. Cybersecurity Engineer, Detection & Response

ON.energy
United Statesfull_timeVerifiedPosted 19 Aug 2026

About the role

ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software, ON.energy develops projects worldwide that set new benchmarks for resilience.

ON.energy is hiring a Sr. Cybersecurity Engineer to run detection and response across the corporate security stack: the SIEM, the Defender suite, SaaS applications, and the data moving through them. A growing energy business generates significant signal across these four surfaces, and most of it currently goes unread. This is a SecOps role focused on detection ownership, response speed, and incident resolution. The underlying platforms that generate the telemetry are built and governed by other functions. This role owns turning that signal into alerts that matter and incidents that get closed. 

Key Responsibilities

Detection Engineering & Incident Response 

  • SIEM (Microsoft Sentinel): Deploy and own Sentinel in the Defender portal, data connectors across Entra, Defender XDR, M365, AWS, and SaaS sources, plus the retention and tiering decisions that keep ingestion cost defensible. 
  • Detection Engineering: Write and tune analytics rules and custom detections in KQL, mapped to MITRE ATT&CK. Run the tuning board; every rule requires a documented reason to exist, and noisy rules get fixed or killed. 
  • Incident Response: Own the IR lifecycle end to end for anything surfaced through Sentinel: triage, containment, eradication, and written post-incident review. Maintain playbooks for top scenarios (BEC, ransomware, credential compromise, third-party breach, DLP/insider risk escalation), run tabletops with IT, Legal, and Operations leadership, and lead the corporate side of any incident that crosses into OT. 

Endpoint, Email, App & Data Security 

  • Endpoint & Email (Defender): Own triage and response for Defender for Endpoint and Defender for Office 365 alerts: investigate, contain, and close the loop back into Sentinel detections. Does not own EDR policy architecture, ASR baselines, or the Intune device compliance program; that build sits with Endpoint/IT Engineering. Consumes their telemetry and detects against it. 
  • App Security (Defender for Cloud Apps): Own detection logic for risky OAuth grants, shadow IT, and anomalous app behavior, fed into Sentinel as first-class detections. Does not run the SaaS app approval and governance program itself; that's a GRC/IT governance function this role feeds, not owns. 
  • Data Security (Purview): Own detection and response for DLP and insider risk alerts flowing into Sentinel: investigate matches, determine real exposure, and drive the incident through to close. Does not design label taxonomy or author insider risk policy; that's a data governance function partnered with Legal and HR. Responds to what it produces. 

Governance, Risk & Compliance 

  • Control Frameworks & Audit Support: Supply technical evidence and control-operation proof for SOC 2, ISO 27001, and NIST CSF 2.0 audits, and answer technical questions in customer security questionnaires, as directed by GRC. Does not own the audit relationship, the control framework, or the risk register; that sits with GRC. Proves the controls operated actually work. 

Cloud Security 

  • Consume AWS GuardDuty findings into Sentinel and write detections against them. AWS security architecture and IAM least-privilege design belong to DevOps; this role owns the telemetry pipeline into the SIEM, not that surface. 

Requirements

  • 5+ years of hands-on security operations and detection engineering experience, with real depth in

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ON.energy

View company profile →