Sr. Security Engineer - Cloud Threat Detection
Core
Design and enhance enterprise-scale cloud threat detection capabilities across AWS and GCP, integrating telemetry into the SIEM to improve visibility into cloud-based threats.
Role type
Senior IC Cloud Threat Detection Engineer
Builds
High-fidelity detections, SIEM analytics, dashboards, and alerting content for cloud environments
Domain
Cloud Security / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis
Required skills
AWS security services, GCP security services, enterprise SIEM detection development, cloud-native security tool integration, cloud attack methodologies, raw cloud telemetry investigation, operational documentation, SOC analyst mentoring
Preferred skills
Splunk Enterprise Security (SPL, RBA), MITRE ATT&CK, SOAR platforms, Python/PowerShell/Bash scripting, multi-cloud security programs, threat hunting, EDR platforms
Technologies
AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google Security Command Center, Google Cloud Audit Logs, Google Cloud Logging, Splunk, Microsoft Sentinel, QRadar, Cortex XSIAM, Orca, CrowdStrike, Wiz
Responsibilities
Design, develop, test, and deploy detection content for AWS and GCP threats; Integrate and normalize cloud security telemetry into the enterprise SIEM; Continuously tune detection logic to reduce false positives; Map detections to MITRE ATT&CK; Participate in adversary emulation and purple team exercises; Create SOPs and runbooks; Train and mentor L1/L2 SOC analysts; Provide advanced escalation support during investigations
Seniority
Senior, hands-on IC