Job Openings Senior Security Engineer – XDR and Automation

About the job Senior Security Engineer – XDR and Automation

Full-Time | Location: Hybrid – Massachusetts (On-site 1x/week required)

About the Company

CyberTrust Massachusetts is a non-profit committed to growing and diversifying the cyber workforce, creating new and innovative opportunities for education and employment, and hardening the security posture of under-resourced local entities. CyberTrust enhances cyber education programs with hands-on, experiential learning, both through our state-of-the-art cyber range and by placing students in a live security operations center (SOC) that serves local governments, nonprofits and small businesses. CyberTrust SOC provides local governments with Advisory and Operational cybersecurity services, with student interns serving in key delivery roles. Advisory services include cyber assessments and scanning, program planning, and policy development. Operational services include real-time monitoring and response delivered from our four SOC locations across the Commonwealth.

Position Summary

We are seeking an experienced and highly skilled Senior Security Engineer to join our Security Operations team. This role is central to the administration, optimization, and expansion of our SentinelOne EDR/XDR platform across a diverse multi-tenant client environment. The ideal candidate brings hands-on, recent SentinelOne expertise — including Hyper-automation, XDR integrations, and API-driven workflows — and thrives in a fast-paced MSSP setting where precision, automation, and cross-platform visibility are paramount. This is a hybrid position requiring in-state residency (Massachusetts) and the ability to be on-site at least one day per week.

Key Responsibilities

SentinelOne Platform Administration

  • Serve as a primary technical owner for the SentinelOne EDR and XDR platform across all managed client environments
  • Manage multi-tenant console configurations, policies, agent deployments, and platform health across municipal and institutional clients
  • Monitor platform performance, conduct tuning, and implement changes to reduce noise while improving detection fidelity

XDR Integrations & API Development

  • Design, build, and maintain XDR integrations with third-party data sources via API, including Microsoft Entra ID / Microsoft 365, Google Workspace (GWS), and other security telemetry sources in a multi-tenancy environment
  • Evaluate new integration opportunities to strengthen cross-platform detection and response capabilities

Hyper-automation & Playbook Engineering

  • Create, maintain, and optimize SentinelOne Hyper-automation playbooks to automate response actions, alert enrichment, and workflow orchestration
  • Translate repeatable analyst workflows into scalable automated processes that improve MTTR and reduce manual effort across the SOC team
  • Continuously review and refine automation logic based on evolving threat patterns and client environment changes

Custom Log Parsers

  • Develop and maintain custom log parsers to normalize and structure telemetry from diverse client environments and third-party security tools
  • Ensure consistent and accurate data ingestion into the XDR platform to support detection engineering and reporting

Documentation & Runbooks

  • Create and maintain thorough documentation including runbooks, integration guides, playbook logic, parser specifications, and operational procedures
  • Ensure documentation is current, accessible, and supports team scalability and onboarding
  • U.S Citizenship or permanent resident and must reside in or near Massachusetts and be available for on-site presence one day per week
  • 5+ years of hands-on experience in security engineering, with recent SentinelOne platform experience
  • Demonstrated expertise with SentinelOne XDR, including third-party integrations, API configuration, and multi-tenant management
  • Proven experience building and managing SentinelOne Hyper-automation playbooks in a production environment
  • Experience developing custom log parsers for security data normalization
  • Strong proficiency with REST API integration and Python for security automation
  • Experience with SIEM platforms and correlation rule development
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering
  • Experience working in an MSSP or multi-tenant managed security environment

Required Skills and Qualifications

Why Join Us

This role offers the opportunity to make a tangible impact protecting the public-sector organizations that communities depend on — from local governments and schools to rural health clinics. You'll work with a dedicated team, have meaningful ownership of critical security services, and help shape how modern MSSP security engineering is delivered at scale.

To apply please send resume and cover letter to careers@cybertrustmass.org