About this role
It's fun to work in a company where people truly believe in what they are doing. At Dutch Bros Coffee, we are more than just a coffee company. We are a fun-loving, mind-blowing company that makes a difference one cup at a time.
Position Overview:
We’re looking for a Cybersecurity Engineer to drive the design, implementation, and automation of advanced security controls across our Security Operations team. Reporting to the Director, Cybersecurity this role drives key cybersecurity programs, including the Security Operations Center (SOC), Network Security, Cloud Security, and Data Loss Prevention (DLP), ensuring the confidentiality, integrity, and availability of critical assets. This role will be tasked with supporting security strategies and initiatives while proactively addressing emerging cybersecurity risks. Strong technical expertise and a proactive approach to challenges are essential for success in this role.
The ideal candidate combines hands-on technical expertise with strong problem-solving skills and a passion for continuous improvement. You’ll work at the intersection of security engineering, architecture, and automation to help us stay ahead of evolving threats.
Job Qualifications:
Required Qualifications
- 2–4+ years of hands-on experience in security engineering roles
- 1+ year of hands-on experience in software engineering
- Strong understanding of security principles, software development, IAM, networking, cloud, SOAR, and security operations
- Strong problem-solving, communication, and documentation skills
- Proven ability to collaborate effectively with cross-functional technical teams
Hands-On Experience
- Zero Trust methodologies and SSE platforms, including Cloudflare, Cisco, Microsoft, and Palo Alto Networks
- Python, REST APIs, and data formats such as JSON, CSV, and XML
- Security automation, including SOAR, CI/CD, and Infrastructure as Code (IaC)
- Cloud environments, including Azure and AWS
- IAM/PIM solutions, including Entra ID, CyberArk, Okta, and Auth0
- Linux and Windows administration
- SIEM platforms, including Microsoft Sentinel, Splunk, and Rapid7
Additional Experience
- DevOps methodologies and principles
- Next-Generation Firewalls, including Palo Alto, Fortinet, Sophos, and Check Point
- Compliance frameworks, including PCI DSS, SOX, NIST, and CIS Controls
- EDR platforms, including Microsoft, CrowdStrike, and SentinelOne
- DLP solutions, including Microsoft Purview, Symantec, and Trellix
- Large Language Models (LLMs) and prompt engineering concepts
Preferred / Highly Desired Certifications
- CISSP, CCSP, or OSCP
- AWS Certified Solutions Architect – Associate
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- CCNA
- HashiCorp Certified: Terraform Associate
- HashiCorp Certified: Terraform Associate
Location Requirement:
This role is located in Tempe, Arizona. This position is required to be in office 4 days per week (Mon-Thurs); Fridays are optional remote work days.
Key Result Areas (KRAs):
S ecurity Operations Center (SOC)
- Manage and optimize SOC operations, tools, and workflows to ensure effective security monitoring, detection, and incident response.
- Develop and implement SOC processes that improve operational efficiency and enable advanced threat detection capabilities.
Endpoint Protection
- Manage and optimize EDR/XDR coverage across servers, workstations, and mobile endpoints.
- Implement endpoint hardening controls, including attack surface reduction, application control, host firewall, and disk encryption aligned with CIS Controls.
- Develop and maintain automated endpoint containment and remediation capabilities to reduce attacker dwell time.
- Partner with IT and Infrastructure teams to remediate endpoint security gaps and validate control effectiveness.
Data Loss Prevention (DLP)
- Implement and optimize DLP policies across endpoints, email, SaaS, and cloud environments to protect sensitive and regulated data.
- Partner with Legal, GRC, and business stakeholders to establish data classification and sensitivity labeling standards.
- Investigate DLP and insider risk alerts while tuning policies to balance security coverage and false positives.
- Automate DLP response actions and establish metrics to measure program effectiveness and compliance.
Incident Response
- Support incident response activities across identification, containment, eradication, and recovery.
- Develop and maintain incident response playbooks and conduct simulations to strengthen organizational readiness.
- Lead post-incident reviews and implement lessons learned to improve security controls and processes.
Vulnerability Management
- Support vulnerability assessments, prioritization, remediation, and ongoing program management.
- Partner with IT and Development teams to drive timely patching and vulnerability mitigation.
- Establish program metrics and communicate security risks and areas of opportunity to leadership.
Security Automation
- Develop and maintain SOAR playbooks to automate enrichment, triage, and response for high-volume security alerts.
- Apply Infrastructure as Code (IaC) and CI/CD practices to security tooling, ensuring detections, policies, and integrations are version-controlled, peer-reviewed, and repeatable.
- Identify manual security processes and develop scalable, measurable automated workflows with defined owners and success criteria.
Skills:
- Collaborative
- Communication
- Critical Problem Solving
- Change Management
Physical Requirements:
- In-Office Environment: Must be able to work in a busy, crowded, and loud office with frequent distractions and interruptions
- Must be able to collaborate in-person with occasional impromptu in-person meetings
- Office Conditions: Adaptability to typical office conditions, which may include exposure to air conditioning, heating, artificial lighting, and varying noise levels
- Mobility : Ability to sit, stand, reach, twist, stretch, and work at a desk for long stretches. Must be able to occasionally move or lift office items up to 25 pounds
- Hearing Requirements: Hearing must be sufficient or correctable to ensure clear understanding of spoken information, including participating in virtual meetings and phone calls. Use of hearing aids or other assistive devices is acceptable if needed.
- Reading and Writing Proficiency: Ability to read and write in English is essential for processing documents, drafting reports, and following up on necessary actions. Proficiency in written communication is required to handle job-related tasks effectively.
- Vision Requirements: Vision must be adequate or correctable to perform essential job duties, such as reading documents on a computer screen and using other visual tools. Use of corrective lenses or other measures to meet visual requirements is expected if needed.
- Technology Proficiency: Must be proficient in operating a computer and other office productivity tools such as printers, scanners, and collaboration software.
- Effective Communication: Must possess strong verbal and written communication skills to interact effectively with team members, clients, and other stakeholders via email, video conferencing, and other in office communication tools.
Compensation:
DOE
If you like wild growth and working in a unique and fun environment, surrounded by positive community, you'll enjoy your career with us!