EngineerJobs.io
← Back to all jobs

Job Description

The Cybersecurity Engineer will design, implement, and automate advanced security controls to strengthen Security Operations at Dutch Bros Coffee. Reporting to the Director, Cybersecurity, this onsite role in Tempe, AZ focuses on improving security monitoring, detection, and incident response across SOC, Network Security, Cloud Security, and Data Loss Prevention (DLP) programs.

What you will do

  • Manage and optimize SOC operations, tools, and workflows to support security monitoring, detection, and incident response.
  • Develop SOC processes that improve operational efficiency and enable advanced threat detection capabilities.
  • Manage and optimize EDR/XDR coverage across servers, workstations, and mobile endpoints.
  • Implement endpoint hardening controls aligned with CIS Controls, including attack surface reduction, application control, host firewall, and disk encryption.
  • Develop and maintain automated endpoint containment and remediation capabilities to reduce attacker dwell time.
  • Partner with IT and Infrastructure teams to remediate endpoint security gaps and validate control effectiveness.
  • Implement and optimize DLP policies across endpoints, email, SaaS, and cloud environments to protect sensitive and regulated data.
  • Work with Legal, GRC, and business stakeholders to establish data classification and sensitivity labeling standards.
  • Investigate DLP and insider risk alerts while tuning policies to balance security coverage and false positives.
  • Automate DLP response actions and establish metrics to measure program effectiveness and compliance.
  • Support incident response activities across identification, containment, eradication, and recovery.
  • Develop and maintain incident response playbooks and conduct simulations to strengthen organizational readiness.
  • Lead post-incident reviews and implement lessons learned to improve security controls and processes.
  • Support vulnerability assessments, prioritization, remediation, and ongoing program management.
  • Partner with IT and Development teams to drive timely patching and vulnerability mitigation.
  • Establish program metrics and communicate security risks and areas of opportunity to leadership.
  • Develop and maintain SOAR playbooks to automate enrichment, triage, and response for high-volume security alerts.
  • Apply Infrastructure as Code (IaC) and CI/CD practices to security tooling so detections, policies, and integrations are version-controlled, peer-reviewed, and repeatable.
  • Identify manual security processes and build scalable, measurable automated workflows with defined owners and success criteria.

Minimum qualifications

  • 2–4+ years of hands-on experience in security engineering roles
  • 1+ year of hands-on experience in software engineering
  • Strong understanding of security principles, software development, IAM, networking, cloud, SOAR, and security operations
  • Strong problem-solving, communication, and documentation skills
  • Proven ability to collaborate effectively with cross-functional technical teams

Additional requirements

  • Zero Trust methodologies and SSE platforms, including Cloudflare, Cisco, Microsoft, and Palo Alto Networks
  • Python, REST APIs, and data formats such as JSON, CSV, and XML
  • Security automation, including SOAR, CI/CD, and Infrastructure as Code (IaC)
  • Cloud environments, including Azure and AWS
  • IAM/PIM solutions, including Entra ID, CyberArk, Okta, and Auth0
  • Linux and Windows administration
  • SIEM platforms, including Microsoft Sentinel, Splunk, and Rapid7
  • DevOps methodologies and principles
  • Next-Generation Firewalls, including Palo Alto, Fortinet, Sophos, and Check Point
  • Compliance frameworks, including PCI DSS, SOX, NIST, and CIS Controls
  • EDR platforms, including Microsoft, CrowdStrike, and SentinelOne
  • DLP solutions, including Microsoft Purview, Symantec, and Trellix
  • Large Language Models (LLMs) and prompt engineering concepts
  • Certifications: CISSP, CCSP, or OSCP
  • AWS Certified Solutions Architect – Associate
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate
  • CCNA
  • HashiCorp Certified: Terraform Associate

Location and work schedule

  • Tempe, Arizona
  • In office 4 days per week (Mon–Thurs); Fridays are optional remote work days

Compensation

DOE

Technologies

Python, REST APIs, JSON, CSV, XML, SOAR, CI/CD, Infrastructure as Code (IaC), Azure, AWS, Entra ID, CyberArk, Okta, Auth0, Linux, Windows, Microsoft Sentinel, Splunk, Rapid7, Cloudflare, Cisco, Palo Alto Networks, Next-Generation Firewalls, Palo Alto, Fortinet, Sophos, Check Point, EDR, Microsoft, CrowdStrike, SentinelOne, Microsoft Purview, Symantec, Trellix, Large Language Models (LLMs), Terraform, CIS Controls, Microsoft Entra ID

Similar Jobs