Senior Security Operations Engineer
Core
Monitor and analyze security events, lead incident response, and develop automation workflows for security operations.
Role type
Senior Security Operations Engineer (Incident Response & Automation)
Builds
Security detection rules, incident response playbooks, and automated response workflows using GCP.
Domain
Cybersecurity / Cloud Security (GCP)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response leadership, SIEM/EDR administration, Python/Go scripting, Terraform/Ansible, threat intelligence analysis, security architecture design, automation development, root cause analysis, compliance reporting, mentorship
Preferred skills
OffSec/GIAC certifications, digital forensics, cloud security (AWS/Azure/GCP), SOAR platforms, networking knowledge, security community contributions
Technologies
GCP, Terraform, Ansible, SIEM, EDR, SOAR, Python, Go
Responsibilities
Monitor and analyze security events from SIEM, EDR, and SASE sources; Lead security incident response including investigation, containment, and recovery; Develop and maintain incident response plans, playbooks, and detection rules; Manage security tools and evaluate new technologies; Develop automation scripts and workflows for event enrichment and response; Conduct threat research and contribute to security systems architecture; Mentor junior security analysts and engineers; Support security compliance, audits, and policy adherence; Participate in on-call rotation
Seniority
Senior, hands-on IC with mentorship responsibilities
