
Staff Security Engineer – Security Operations
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in Ireland.
• Manage comprehensive responses for intricate and critical incidents, including data breaches, coordinated attacks, and platform-level events.
• Facilitate incident war rooms and make critical decisions regarding severity and containment.
• Collaborate with Engineering, Legal, and executive stakeholders.
• Take ownership of blameless post-incident reviews.
• Establish and continuously enhance the incident response methodology, encompassing severity frameworks, escalation paths, playbooks, runbooks, on-call standards, SLAs, and ongoing improvement.
• Direct MITRE ATT&CK-mapped threat hunting across cloud, endpoint, and identity surfaces.
• Transform hunts and incidents into more precise, lower-noise detections and response procedures.
• Define the automation roadmap for triage, enrichment, investigation, and response.
• Leverage AI tools and LLM workflows to prototype, expedite investigations, and assist in building ARES.
• Oversee Pantheon’s Google SecOps (Chronicle) platform, focusing on detection coverage, log source strategy, data quality, and cost management.
• Guide analysts and engineers through incidents, hunts, pair programming, reviews, and tabletop exercises.
• Convert operational realities into risk narratives and program-level metrics for senior leadership.
• Represent SecOps in architectural and product discussions.
• Contribute to threat intelligence priorities, vendor and tooling assessments, resilience testing, red/purple team exercises, and GRC evidence for SOC 2, GDPR/NIS2, and other related obligations.
• Over 8 years of experience in information security, with significant time spent in security operations.
• Proven expertise in managing major incidents.
• In-depth knowledge of incident response methodologies, including NIST 800-61 / SANS PICERL or equivalent, applied in production environments.
• Demonstrated success in building or significantly enhancing an incident response program.
• Expert understanding of MITRE ATT&CK and attacker tradecraft.
• Established ability to convert threat hunts and incidents into detection logic and response protocols.
• Regular use of AI assistants and LLM tools; proficient in utilizing Claude effectively.
• Proficient in Python/Bash scripting, APIs, and cloud-native environments such as GCP and/or AWS.
• CISSP or equivalent credentials such as CISM, GCIH/GCIA/GDAT-class GIAC.
• Practical experience with enterprise SIEM at a governance level; preference for Google SecOps/Chronicle, with Splunk, Sentinel, or Elastic being acceptable alternatives.
• Exceptional written and verbal communication skills.
• Visa sponsorship is currently not available.
• Competitive compensation package and equity plan.
• Comprehensive vacation package with 28 days of holiday.
• Private medical and dental insurance.
• Life and critical illness coverage.
• Attractive workplace pension scheme.
• Access to an Employee Resource Platform.
• High-quality equipment.
• Monthly allowance for wellness and reading activities.
• Access to LinkedIn Learning for ongoing development.
• Engaging team-based and company-wide events and activities.
Palo Alto Networks
Convergint
Conduent
Tokio Marine HCC
Get handpicked remote jobs straight to your inbox weekly.