Security Operations Engineer
Core
Design, build, tune, and deploy threat detections; triage and investigate security alerts across endpoint, identity, cloud, and application telemetry; conduct proactive threat hunting and incident response.
Role type
Senior Security Operations Engineer (Detection & Incident Response)
Builds
Detections-as-code pipeline, security automation integrations, incident response runbooks and playbooks
Domain
Cybersecurity, Cloud Security, Identity Security
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Threat detection engineering, threat hunting, incident investigation, log and telemetry analysis, detection-as-code, automation scripting, EDR/SIEM platform proficiency, incident command coordination
Preferred skills
AI-assisted tooling for triage/correlation, experience in regulated/privacy-sensitive environments (health, genomics, financial services)
Technologies
Terraform, Python, Okta, AWS, CrowdStrike, SentinelOne, Datadog, Sumo Logic, Splunk
Responsibilities
Design, build, tune, test, and deploy threat detections; Operate and extend detections-as-code pipeline; Triage, investigate, and prioritize security alerts; Conduct proactive threat hunting; Identify automation opportunities and build integrations; Serve as Incident Commander and coordinate cross-functional response; Maintain incident response runbooks and playbooks; Participate in on-call rotation
Seniority
Senior, hands-on IC