**Introduction**
At IBM Infrastructure & Technology, we design and operate the systems that keep the world running. From high-resiliency mainframes and hybrid cloud platforms to networking, automation, and site reliability. Our teams ensure the performance, security, and scalability that clients and industries depend on every day. Working in Infrastructure & Technology means tackling complex challenges with curiosity and collaboration. You’ll work with diverse technologies and colleagues worldwide to deliver resilient, future-ready solutions that power innovation. With continuous learning, career growth, and a supportive culture, IBM provides the opportunities to build expertise and shape the infrastructure that drives progress.
**Your role and responsibilities**
The CISO Remediation Team is looking to add a cybersecurity Remediation Engineer as part of the overall Cyber Defense organization. In this role, you will contribute to and, over time, drive the technical resolution of security risk across the IBM enterprise, operating at the intersection of security operations, engineering, and architecture. You will help teams recover from incidents, remediate vulnerabilities, and implement durable, scalable security improvements.
Depending on the engagement and experience level, you may remediate issues directly, partner with engineering teams to drive fixes, or design repeatable remediation patterns. This role is not a primary SOC, detection, or application security pipeline ownership role, but partners closely with those teams to drive remediation outcomes.
The ideal candidate thrives in high‑pressure environments, thinks like both an attacker and defender, and communicates clearly with technical and non‑technical stakeholders.
This role spans multiple technical domains. Candidates are not expected to be experts in all areas; strong candidates demonstrate deep expertise in one or two domains and working knowledge of adjacent areas.
Areas of specialization may include:
· Scripting, Automation & Infrastructure as Code: Python, Ansible, Terraform, or similar tooling
· Cloud & Virtualized Environments: IBM Cloud, AWS, Azure, GCP; virtualization and container platforms
· Operating Systems & Networking: Windows or Linux; network segmentation, SDN, and isolation techniques
· Security Technologies: EDR, NGFW, IDS, SIEM, SOAR, and related platforms
Key Duties:
· Support containment, recovery, and post-incident remediation by identifying root causes and implementing technical fixes that reduce recurrence.
· Partner with product, engineering, and infrastructure teams to embed security within existing practices.
· Conduct security and risk assessments of applications, platforms, and infrastructure, including threat modeling and targeted technical review.
· Apply security principles to protect systems and data, ensuring availability, authentication, authorization, confidentiality, and integrity.
· Create technical documentation outlining remediation guidance and security best practices.
· Develop or implement tools to support detection, prevention and analysis of security threats.
**Required technical and professional expertise**
* Experience in security engineering or adjacent engineering roles. (e.g., networking, infrastructure, cloud, or application development.)
* Demonstrated experience leading technical teams in security, infrastructure, cloud, or platform engineering.
* Strong understanding of vulnerability management, incident response lifecycles, and remediation practices.
* Ability to guide engineers through ambiguous, high-pressure technical challenges.
* Proven ability to influence across organizations and drive outcomes without direct control.
* Strong communication skills, with the ability to translate technical issues into business and risk context.
* Experience operating in large, complex, federated enterprise environments.
**Preferred technical and professional experience**
*
Experience in security engineering or adjacent engineering roles. (e.g., networking, infrastructure, cloud, or application development.)
*
Experience supporting incident response or post‑incident remediation.
*
Experience with cloud platforms, CI/CD pipelines, containerization, and Kubernetes.
*
Experience using automation and AI to reduce mean time to remediation (MTTR).
*
Familiarity with Agile development environments.
*
Foundational understanding of cybersecurity frameworks and regulations and how they inform risk‑based remediation decisions. (e.g., NIST CSF, NIST 800-series, ISO 27001, PCI.)
*
Certifications are a plus but not required; hands‑on experience is valued most. (e.g., CISSP, CISM, OSCP, SANS, cloud security certifications.)
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Want jobs like this matched to you?
Swoopd scores fresh postings against your résumé so you only see the matches that matter.