SlipstreamJobsFresh Startup & VC-Backed Jobs

Cybersecurity Engineer (Detection & Response)

Swarmer - Kyiv, Ukraine - Hybrid - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Swarmer develops autonomous drone software that enables large coordinated teams to operate without pilots. The company was battle-tested in Ukraine and became the first Ukrainian defense startup to go public on NASDAQ in March 2026 following a $15M Series A. You will join as a Cybersecurity Engineer responsible for defending Swarmer's corporate perimeter: endpoints, identities, SaaS stack, networks, and cloud environment. This is a builder's role focused on designing and implementing security infrastructure from the ground up, not maintaining a mature program. Key responsibilities: - Own and continuously improve SIEM/SOAR capabilities, including log source onboarding, detection rules, alert tuning, dashboards, automated response workflows, and security stack integration - Monitor and analyze security events and logs to identify anomalies and threats; investigate, contain, and remediate incidents with full documentation - Deploy and manage endpoint and server protection across the fleet (EDR/NGAV, MDM), including policy enforcement, compliance configuration, and hardening baselines - Implement and operate identity and Zero Trust access controls (SSO, MFA, conditional access, ZTNA, device posture checks, RBAC, least privilege, PAM, access reviews) - Manage vulnerabilities across endpoints, servers, and cloud with risk-based prioritization and remediation tracking - Monitor cloud and SaaS security posture, remediate misconfigurations, and review third-party integrations - Review infrastructure projects and architecture from a security lens to ensure secure-by-default configurations - Document technical security controls (runbooks, hardening guides) and support internal and external audits The role operates at the intersection of engineering rigor and frontline reality, with direct impact on systems operating in high-stakes environments. You'll work in a fast-paced environment with minimal bureaucracy. REQUIREMENTS: - 4+ years hands-on experience in cybersecurity or IT infrastructure engineering with clear security specialization - Hands-on experience with SIEM/SOAR platforms (log source integration, detection engineering, alert investigation, security automation) - Hands-on experience with EDR/NGAV platforms (endpoint policy management, detection, investigation, response) - Experience hardening and managing endpoints across Windows, macOS, and Linux, including MDM platforms - Experience with identity and Zero Trust access technologies (SSO, MFA, conditional access, device posture, ZTNA) - Solid grasp of networking fundamentals (TCP/IP, DNS, DHCP, VPN) with practical firewall and network security control configuration experience - Working knowledge of common attack techniques and detection/prevention methods - Practical familiarity with recognized security frameworks and standards (CIS, NIST, MITRE ATT&CK) - Strong risk-assessment instincts with ability to prioritize pragmatically and explain technical issues to non-technical colleagues - English proficiency for documentation, vendors, and external partners Advantages: - Scripting ability for security and infrastructure automation (Python, Bash, PowerShell, SOAR playbooks) - Experience with vulnerability management platforms - Working knowledge of cloud and SaaS security controls (CSPM/SSPM) - Relevant security certifications - Experience in enterprise or critical-infrastructure environments

Similar roles