Principal Security Engineer
Summary
Lead security operations for AI data centers, including incident response, threat hunting, and infrastructure hardening across the Americas.
You will lead hands-on security operations for AI data centers across the Americas. You will respond to critical incidents, develop detections and threat-hunting campaigns, harden hosts and networks, manage vulnerabilities and privileged access, and coordinate customer, legal, and headquarters incident communications.
Responsibilities
- Lead 24/7 alert triage, incident response, and root cause analysis for Americas AI data centers
- Lead forensic investigation, containment, and recovery for high-severity security incidents
- Build incident response playbooks and runbooks
- Develop SIEM detection rules and threat-hunting campaigns
- Implement detection-as-code practices, including version-controlled rules, CI/CD, testing, and coverage metrics
- Assess pre-production security readiness and harden infrastructure
- Track vulnerabilities and lead regional vulnerability response
- Manage regional IAM and privileged access controls
- Operate perimeter firewalls, IPS, WAF, DDoS mitigation, and network security controls
- Respond to customer security tickets, abuse complaints, and incident notifications
- Handle law-enforcement requests in coordination with Legal
- Coordinate security handoffs and compliance evidence collection with Singapore headquarters
Requirements
- Bachelor's degree or higher in Computer Science, Cybersecurity, Computer Engineering, or a related technical field
- 10+ years of hands-on information security experience
- At least 5 years focused on cloud infrastructure, IaaS, or data center security operations
- Incident Commander experience leading at least five P0/P1 security incidents
- Knowledge of NIST SP 800-61
- Expertise in Linux security, network protocols, TCP/IP, KVM/QEMU, and container and Kubernetes security
- Experience with a SIEM platform and writing detection rules
- SIGMA rule format knowledge
- Knowledge of the MITRE ATT&CK Cloud Matrix and Container Matrix
- Python and Shell programming skills
- Familiarity with eBPF, Tetragon, Falco, and Cilium
- Experience with Terraform or Ansible and Git workflows
- GCIH, GCIA, GCFA, OSCP, CISSP, or CCSP certification
- Professional fluency in English and Mandarin Chinese
- Willingness to participate in a 24/7 on-call rotation and cross-time-zone coordination