
Senior Security Engineer
Posted Jul 14

Posted Jul 14
This is a fully remote position, open to applicants in United States.
• Take full ownership of the SIEM platform, encompassing log source onboarding, correlation rule creation, detection tuning, dashboard development, and management of platform performance and costs.
• Oversee the entire incident response lifecycle, which includes triage, containment, eradication, recovery, root cause analysis, and post-incident reporting.
• Create and maintain detection content aligned with the MITRE ATT&CK framework; perform proactive threat hunting across cloud infrastructure, endpoints, identity systems, and network traffic.
• Establish and enforce SOC procedures, including alert triage workflows, escalation paths, on-call protocols, and operational metrics such as mean time to detect and mean time to respond.
• Manage the ingestion pipelines for cloud audit logs (e.g., AWS CloudTrail), EDR, identity providers, network security platforms, and endpoint management tools into the SIEM.
• Transform threat intelligence feeds into actionable detection rules, enrichment workflows, and hunting hypotheses.
• Create automation for detection engineering, alert enrichment, and response playbooks to minimize manual analyst workload and enhance response speed.
• Lead and facilitate tabletop exercises to evaluate and continuously enhance incident response protocols, crisis management, and disaster recovery strategies.
• Integrate findings from infrastructure, application security, and identity teams during investigations, driving permanent remediation of identified vulnerabilities.
• Generate technical incident reports and SOC posture reports that provide leadership with clear insights into detection coverage, response effectiveness, and existing risks.
• Establish and enforce standards for detection engineering, runbooks, and playbooks utilized across the security team.
• A Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience is required.
• A cyber-specific certification is mandatory (e.g., GCIH, GCFA, CISSP, or a relevant SIEM/vendor certification).
• A minimum of seven (7) years of IT experience, with at least four (4) years in a security engineering, SOC, or incident response capacity.
• Expertise with SIEM platforms (Sumo Logic is highly preferred), including log architecture, correlation rule development, and performance optimization.
• Familiarity with incident response methodologies (e.g., NIST 800-61) and proficiency with the MITRE ATT&CK framework.
• Strong understanding of AWS security logging and detection services (CloudTrail, GuardDuty, Security Hub) and log sources from Windows/Linux; Linux experience is essential.
• Hands-on experience in investigating alerts and telemetry from EDR (e.g., CrowdStrike), network security platforms (e.g., Zscaler), and O365/identity log sources.
• Advanced scripting and automation skills using PowerShell, Python, or Bash are necessary.
• Capability to work independently and lead multiple complex investigations and projects to successful completion.
• Exceptional interpersonal and communication abilities (both verbal and written) at all organizational levels.
• Strong analytical and problem-solving skills, demonstrating sound judgment under incident pressure.
• Proven ability to achieve objectives.
• Remote-first work environment.
• Choice between a HDHP or PPO Medical plan, with 100% of the premium for the HDHP covered for you and your eligible family members.
• Dental, Vision, Short- and Long-Term Disability, and Group Life Insurance with all premiums fully covered (including family coverage for Dental and Vision).
• Additional buy-up options for Short- and Long-Term Disability and Life Insurance.
• 401(k) plan with employer matching up to 3.5%, available after 60 days.
• Community Service Day to give back and support causes you care about in your community.
• 10 company holidays including MLK Day, Juneteenth, and the day after Thanksgiving, plus a floating holiday for your personal use.
• Reimbursement for high-speed internet; we will provide you with a computer and monitors to help you excel in your work.
• Tuition Reimbursement for accredited degree programs.
• Paid New Parent Leave applicable for adoption or birth.
• Pet insurance available to safeguard your furry companions.
• Comprehensive mental health benefits and EAP services through Spring Health to support you when needed.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.