Senior Security Operations Engineer
Core
Engineer, operate, and improve enterprise Attack Surface and Vulnerability Management capabilities across cloud, infrastructure, endpoints, and internet-facing environments.
Role type
Senior Security Operations Engineer (Attack Surface & Vulnerability Management)
Builds
Enterprise ASM/Vulnerability Management platforms, risk-based prioritization workflows, and security automation integrations.
Domain
Cybersecurity, Cloud Security, Zero Trust, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Asset discovery, vulnerability lifecycle management, risk-based prioritization, remediation workflow design, SIEM detection engineering, security automation scripting, cloud infrastructure security, secrets and credential security, threat hunting, network security fundamentals
Preferred skills
Zscaler ZIA/ZPA/Zero Trust, Tenable/Qualys/Wiz/Prisma Cloud, GitGuardian/Gitleaks/TruffleHog, Splunk/SOAR, CrowdStrike EDR/XDR, AWS/Azure/GCP, DevSecOps/CI/CD security, External Attack Surface Management (EASM)
Technologies
Python, PowerShell, REST APIs, SOAR, Zscaler, Tenable, Qualys, Wiz, Prisma Cloud, GitGuardian, Gitleaks, TruffleHog, Splunk, CrowdStrike, AWS, Azure, GCP
Responsibilities
Discover and correlate assets to identify unknown, unmanaged, and exposed assets; Drive risk-based vulnerability prioritization using threat intelligence and asset criticality; Establish remediation workflows and SLAs with asset owners; Operate and troubleshoot Zscaler ZIA/ZPA and Zero Trust controls; Investigate exposed secrets and credentials across CI/CD and cloud platforms; Develop and improve SIEM detections for exploitation and anomalous activity; Support threat hunting and incident investigations; Develop automation for asset enrichment, triage, and reporting; Partner with engineering teams to drive remediation; Translate technical findings into actionable risk guidance for leadership.
Seniority
Senior, hands-on IC
