IT Security Engineer
Summary
Hands-on IT Security Engineer on DoubleLine Group's Information Security team in Los Angeles, reporting to the Director of Information Security. The role investigates security events and incidents, tunes detections and alerting across endpoint, identity, network, and cloud environments, and builds scripts and automation to improve controls.
We are seeking an experienced Security Engineer to join the Information Security team. This is a hands-on position with significant responsibility and visibility across the organization and will report directly to the Director of Information Security.
The IT Security Engineer will have experience in solving complex technical problems, investigating security events, engineering and improving security controls, automating repetitive processes, and partnering directly with infrastructure, application, and business teams. The individual must be comfortable independently owning technical initiatives from problem identification and design through implementation, documentation, and ongoing operation.
Job Functions
-
Serve as a technical escalation point for security alerts, investigations, and incidents using security telemetry.
-
Independently investigate suspicious activity across endpoint, identity, email, network, cloud, and application environments and support or lead incident-response activities through containment, remediation, root-cause analysis, and post-incident improvement.
-
Work closely with critical security partners on the development, testing, and tuning of security detections, correlation logic, searches, dashboards, and alerting — continuously improving telemetry quality, detection coverage, and signal-to-noise ratio.
-
Develop scripts, integrations, or automated workflows using APIs and appropriate scripting technologies to improve security analysis, control validation, investigation, enrichment, reporting, and remediation.
-
Develop, review, and maintain technical security standards, procedures, architecture documentation, and operating processes.
-
Support the design, implementation, configuration, and continuous improvement of enterprise security technologies and controls.
-
Partners with IT infrastructure — including networking, endpoint, identity, and cloud teams — as well as application development to integrate security into technology architecture and operational processes.
-
Assess security configurations and controls across hybrid infrastructure, cloud, SaaS, endpoint, server, network, and identity environments and identify practical opportunities to reduce risk.
-
Identify processes that can be safely automated while maintaining appropriate human oversight.