Security Engineer III - Security Operations
Core
Plan and deliver detection and response initiatives, build and tune Elastic SIEM detections across AWS, and investigate security incidents.
Role type
Senior IC security operations engineer (SIEM & Cloud)
Builds
Automated detection rules, incident response playbooks, and security tooling infrastructure for cloud environments.
Domain
Cybersecurity, Cloud Security (AWS), Compliance (SOC 2, PCI DSS)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM tuning (Elastic, Splunk, Sentinel), AWS cloud-native detection, Python scripting, Terraform, incident triage and investigation, risk decision-making, infrastructure-as-code, MITRE ATT&CK framework knowledge
Preferred skills
No-code security automation (Zapier, Tines), SOAR tooling, regulated industry background (fintech, payments)
Technologies
Elastic SIEM, AWS, Python, Terraform, Zapier, Tines
Responsibilities
Build, tune, and maintain Elastic SIEM detections across AWS environments; Triage, investigate, escalate, and resolve security incidents; Build runbooks and automations using Python or no-code tools; Maintain audit-ready security controls for SOC 2 and PCI DSS; Participate in on-call rotation for incident response and monitoring
Seniority
Senior, hands-on IC
