Senior Security Engineer, Operations
Core
Own detection and response for the corporate environment, running SIEM, triaging alerts, and driving incidents from signal through containment and remediation.
Role type
Senior Security Operations Engineer (Detection & Response)
Builds
Detection content, response playbooks, automation, and incident response capabilities for corporate security
Domain
Cybersecurity, Corporate Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM administration and tuning, incident command and response, detection-as-code, threat hunting, adversary emulation, forensic analysis, scripting/automation, MITRE ATT&CK knowledge
Preferred skills
Cloud detection and response, threat intelligence, malware analysis, reverse engineering, defense/aerospace environment experience
Technologies
Splunk, Microsoft Sentinel, Elastic, Panther, Chronicle, SOAR, Python, Go, C++, Rust, AWS, Azure, GCP
Responsibilities
Administer and mature the SIEM, write and maintain detection content using detection-as-code, act as incident commander, build response playbooks and automation, perform threat hunting and adversary emulation, conduct host/network/cloud forensics, investigate phishing and insider risk, partner with IT to harden controls, translate findings into vulnerability management priorities, participate in on-call rotation, mentor junior members
Seniority
Senior, hands-on IC