Jobs and Careers
RO

Senior Cybersecurity Engineer

Rogue Fitness
HQ, United States, United Statesfull_timeVerifiedPosted 30 Jul 2026

About the role

Job Description:

 

We're looking for a hands-on Senior Cybersecurity Engineer with strong experience in web application firewalls, cloud security, security operations, and infrastructure security. This is an implementation and operations role, not a pure architecture or policy position — you'll configure, troubleshoot, and run security systems daily, moving fluidly between WAF tuning, cloud controls, SIEM investigations, endpoint incidents, and network troubleshooting. The ideal candidate is a self-starter who spots gaps, proposes practical fixes, and owns them through implementation, while partnering closely with developers, infrastructure teams, auditors, and leadership.

The Senior Cybersecurity Engineer is a fully onsite role in Columbus, Ohio. Remote work is not available. Applicants must be authorized to work in the United States for any employer.

Responsibilities

  • Administer and improve WAF platforms — managed/custom rules, rate limiting, bot and API protections, and DDoS controls; investigate blocked requests, attacks, and false positives

  • Implement and maintain security controls across GCP, Azure, and other cloud platforms, including identity, network, storage, and logging configurations; identify and remediate misconfigurations and excessive permissions

  • Support application security and DevSecOps practices across the development and deployment lifecycle, including risk review of APIs, SaaS, and AI-enabled applications

  • Manage EDR (CrowdStrike) and anti-ransomware (Halcyon) protections; operate SIEM/SOAR (Google SecOps), building alerts, detections, dashboards, and response automation

  • Lead incident investigation, containment, remediation, and recovery; maintain IR playbooks; perform threat hunting, forensics, and root cause analysis; manage threat intel via Recorded Future

  • Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure

  • Administer Zscaler in support of the zero trust model; configure and troubleshoot firewalls, segmentation, VPN, and remote access; co-manage VMware and Linux server environments; monitor via Zabbix

  • Maintain compliance with PCI DSS, GDPR, and related frameworks; support audit prep and evidence gathering; own the Risk Register; translate compliance requirements into technical controls; run security awareness training via KnowBe4

  • Administer and secure Google Workspace identity — MFA, access controls, account lifecycle, least privilege — and investigate suspicious sign-ins and identity-related alerts

Qualifications

  • Hands-on experience administering a web application firewall (e.g., Cloudflare or similar enterprise platform)

  • Strong understanding of web security fundamentals: HTTP/HTTPS, DNS, TLS, APIs, OWASP risks, bot activity, rate limiting, and DDoS

  • Experience implementing security controls in GCP, Azure, or another public cloud, including identity, network, storage, and logging

  • Experience with EDR/XDR platforms (e.g., CrowdStrike) and operating SIEM/SOAR tools for security investigations

  • Experience with vulnerability management, penetration testing, threat hunting, and incident response

  • Working knowledge of Linux and Windows administration, networking, firewalls, and zero trust/hybrid infrastructure

  • Experience supporting PCI DSS, GDPR, or similar compliance and privacy frameworks

  • Strong communicator who can work independently and partner effectively with technical and business stakeholders

Preferred Experience

  • Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future, Zscaler, Zabbix, KnowBe4, or VMware

  • Python or other scripting experience for security automation, detections, and SIEM workflow development

  • Background in ethical hacking, application security, digital forensics, or OSINT

  • Familiarity with DevSecOps, IaC, containers, and cloud-native services

  • Awareness of AI security risks and secure use of generative AI

  • Security or cloud certifications are a plus but not required

By applying to Rogue, regardless of the platform you choose to use, you are agreeing to Rogue's preferred methods of

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Rogue Fitness

View company profile →