594,528open jobs
27,125companies
84,688added this week
Browse all
Location
In office
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match

Job Title: Senior Cyber Security Engineer

Location: Dundalk HQ or Ireland Remote (With occasional requirement to attend Dundalk HQ)

Department: Product & Technology - Cyber Security

Reports to: Head of Cybersecurity

Job type: Full time. On-call rotation.

Role purpose

The Security Engineer in the Cyber Defence team is the senior hands-on defender working alongside the Head of Cybersecurity. They build, tune and operate the detection and response capability that protects BoyleSports against active threat. They write detections, run hunts, investigate alerts that the MSSP escalates, and stand on the bridge during incidents.

This is an engineering role inside the Cyber function. It is distinct from the Security Engineers in the CCoE, who build platform security capability. This role builds defensive capability - the rules, automations, integrations and tooling that let BoyleSports see and stop attacks.

Key responsibilities

Detection engineering

  • Design, write, test and tune detections across Cortex XDR / XSIAM, cloud telemetry (AWS CloudTrail, GuardDuty, EKS audit logs), identity telemetry (Entra ID, on-premises AD), endpoint, network and application logs.
  • Treat detections as code. Version-control rules, peer-review changes, write tests, measure coverage against MITRE ATT&CK, and retire detections that no longer earn their keep.
  • Own log onboarding and parsing for new sources. Work with platform and application engineering teams to make sure new services produce useful telemetry on day one, not retro-fitted six months later.

Threat hunting and investigation

  • Run structured threat hunts against hypotheses derived from threat intelligence, recent incidents and attacker tradecraft relevant to online gambling (account takeover, bonus abuse-adjacent fraud rings, payments-targeted intrusion, ransomware operator TTPs).
  • Lead deep-dive investigations on alerts escalated from the Palo Alto MSSP. Determine root cause and full scope before handing back for containment.
  • Document findings well enough that the next analyst, six months later, can pick up the trail.

Incident response

  • Stand on the bridge during P1 and P2 incidents. Drive containment and eradication actions personally, in concert with platform, infrastructure and product engineering teams.
  • Own the technical timeline, the indicators of compromise, the evidence trail and the artefacts needed for regulator notification and post-incident review.
  • Deputise for the Head of Cybersecurity as Incident Commander when required.

Automation and SOAR

  • Build and maintain SOAR playbooks. Automate the repetitive parts of triage, enrichment, containment and notification so the team’s attention goes to the parts that need a human.
  • Integrate detection and response tooling with the wider stack - ticketing, chat, identity, cloud control planes - using clean, supportable code.

MSSP partnership

  • Be the team’s primary technical interface to the Palo Alto managed SOC. Review their detections, challenge their analysis, give feedback that improves quality, and escalate when it doesn’t.
  • Run regular detection and response exercises with the MSSP. Make sure playbooks survive contact with reality.

Purple teaming and validation

  • Work with offensive security partners to run purple-team exercises. Translate red findings into hardened detections and tested response procedures.
  • Use breach-and-attack-simulation tooling to continuously validate detection coverage.

Experience and qualifications

Required

  • Demonstrable hands-on experience as a SOC analyst (senior / tier 3), detection engineer, threat hunter or incident responder. Candidates must be able to talk in concrete terms about detections they have written, hunts they have led, and incidents they have worked.
  • Strong working knowledge of at least one major SIEM/XDR platform and the query language behind it. Palo Alto Cortex XDR / XSIAM and XQL are ideal. Splunk, Sentinel, Elastic or Chronicle backgrounds are entirely acceptable provided the candidate can clearly cross over.
  • Practical experience investigating in AWS - CloudTrail, GuardDuty, VPC flow logs, EKS audit logs, IAM analysis. Comfortable reading JSON event data and reasoning about API-call chains.
  • Scripting competence in Python or an equivalent - enough to parse evidence, write SOAR steps, and build small tools without waiting for someone else.
  • Solid grounding in MITRE ATT&CK, the diamond model and a structured approach to investigation. Able to write a clear incident timeline.
  • Calm under pressure. Comfortable on a bridge call at 03:00.

Strongly preferred

  • Experience in online gambling, payments, financial services or another high-volume consumer environment with active fraud and account takeover pressure.
  • Exposure to retail or distributed-endpoint estates (point-of-sale-like devices, SD-WAN, Intune-managed fleets).
  • Experience working with or inside an outsourced SOC arrangement.

Certifications and education

  • Practitioner certifications such as GCIA, GCIH, GCFA, GNFA, BTL1 or equivalent are valued. Vendor certifications in the relevant detection stack are a plus.
  • A relevant degree is welcome but not required.

Company

BOYLE Sports is an international sports betting and gaming company, with an extensive online business and retail portfolio. Founded by John Boyle in 1982, the Irish family-owned firm has grown to become Ireland’s largest and most successful independently-owned bookmaker and has over 390 shops across Ireland and the UK. Its Head Office is located on the outskirts of Dundalk in the Republic of Ireland and the company currently employs over 2,700 employees across Ireland, the UK and Gibraltar. BOYLE Sports offers a world class betting and gaming experience with a ‘Customer First’ approach, committed to bringing customers closer to the action. Its mission is boosted by a rich sponsorship portfolio - the company is a proud principal sponsor of West Ham United Football Club and it stays at the heart of the action all year round by backing some of sport’s most prestigious events, including the Irish Grand National, the Irish Greyhound Derby and the World Grand Prix of Darts.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
594,528 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$91k – $192k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Toronto
Python
JavaScript
DevOps
Azure DevOps
Datadog
Azure
AWS
Management
Agile
QA
Postman
Apply
$87k – $157k per year • Remote/Hybrid • Public Trust • Full-Time • 4+ years exp • Bachelor's Degree • Gaithersburg
Python
Java
C++
Databases
Apache Kafka
AI/ML
Claude Code
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Harbor
Management
Agile
Apply
$87k – $157k per year • Remote/Hybrid • Public Trust • Full-Time • 4+ years exp • Bachelor's Degree • United States
Python
Java
C++
Databases
Apache Kafka
AI/ML
Claude Code
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Harbor
Management
Agile
Apply
$127k – $235k per year • Equity • Remote/Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Frisco • New York • Ann Arbor
Python
Python
FastAPI
Databases
PostgreSQL
AI/ML
AI Agents
LLM
RAG
OpenAI
Anthropic
LLM Guardrails
Agentic Workflows
DevOps
AWS
Vector
Apply
$82k – $152k per year • Equity • Remote • Full-Time • 3+ years exp • Frisco
Python
SQL
PowerShell
AI/ML
Copilot
Claude Code
DevOps
Terraform
GCP
GitHub Actions
CloudFormation
Datadog
Azure
CI/CD
Windows Server
AWS
Docker
Kubernetes
AWS Lambda
Amazon EC2
Amazon S3
Amazon CloudWatch
Apply
In office • Full-Time
Apply
In office • Full-Time • Dublin
Apply
In office • Part-Time
Apply
In office • Full-Time
Apply
In office • Full-Time
Apply
See all jobs
This is one of many
594,528 more open roles from verified company boards, updated every day.