Cyber Operations Engineer
Eir Business Talent View all jobs
- Dublin
- Permanent
- Full-time
The Cyber Operations Engineer is responsible for the continuous improvement, governance, and operational effectiveness of the Cyber security tooling, configurations, and control implementations, focused on strengthening cyber defences by ensuring the cyber tools are configured and performing optimally, across the airline landscape.
Reporting into the Senior Manager of Cyber Defence, this role will work closely with the SOC, Cyber Engineering & Architecture, and IT Technology teams to ensure security tools are correctly configured, governed, and operating as intended. The Cyber Operations Engineer acts as a key bridge between detection/response, engineering design, and day‑to‑day technology operations, and supporting processes to translate threat intelligence, threat actor techniques and recurring incident causes into tangible cyber tooling improvements.Initial Success factors
- Establish a baseline of current tooling performance, controls coverage and effectiveness
- Identify opportunities for removing manual configuration management and cyber control changes, to improve incident response and remediation effort.
- Maintain and continuously improve the configuration and effectiveness of cyber security tools and platforms across
- Email security controls
- Endpoint and device security (EDR/MDR, hardening)
- Data, Identity and access security controls
- Cloud security controls and native security services
- Network security & Application security tooling (where applicable)
- Collaborating with Threat Intelligence & Hunting team, Vulnerability team and Cyber Engineering & Architecture to
- Identify current tooling and/or control gaps and weaknesses
- Recommend and implement configuration or policy improvements
- Design and implement preventive and detective control improvements based on incident learnings.
- Partner with the SOC to
- Improve detection coverage and fidelity
- Reduce false positives and alert fatigue
- Ensure controls align with real‑world attack techniques
- Support governance and oversight of security tooling by
- Ensuring configurations align with approved standards and policies
- Maintaining documentation of control intent and configuration rationale
- Support Cyber Engineering & Architecture with insights and contributions on cyber tooling selection, control design decisions and effectiveness of cyber platforms.
- Contribute to the development and maintenance of security configuration standards, baseline cyber standards and operational runbooks
- Assist in the roll-out of new cyber tooling, to transition into operational and support management, with supporting third parties.
- Support audits and assessments by providing evidence of control configurations and operational procedures
- Extensive experience in cybersecurity and/or IT industry experience, with at least 4 years hands on experience in relevant roles (security operations, security engineering, infrastructure or cloud engineering)
- Demonstrable experience configuring, operating, and improving enterprise‑scale security controls
- Experience working in close partnership with SOC and IT operations teams
- Practical experience with cyber platforms such Crowdstrike, Microsoft Purview, Palo Alto
- Relevant Cyber qualifications e.g. CISSP, GCIH, Cloud Security certs, Security+, or similar relevant qualifications
- This role is not entry‑level and assumes prior hands‑on experience configuring and tuning IT and/or security tooling across multiple cyber domains (network, cloud, endpoint, email, identity).
- Strong understanding of modern enterprise security controls and how they fail in practice
- Comfortable working with configuration management, change control, and operational governance processes.
- Working knowledge of at least one scripting or programming language (e.g. Python, Bash, PowerShell)
- Familiarity with MITRE ATT&CK framework and modern attacker techniques.