Senior Security Operations Engineer
You will detect, investigate, and contain threats across endpoints, cloud infrastructure, and network telemetry. You will triage and resolve security incidents, execute containment and remediation actions, and improve runbooks. You will tune SIEM and EDR detections, apply threat intelligence, automate security workflows using AI, participate in on-call rotations, document incidents, conduct post-incident reviews, and mentor teammates.
Responsibilities
- Triage, investigate, and respond to security alerts across endpoints, cloud infrastructure, and network telemetry.
- Automate repetitive workflows and use AI to improve security operations.
- Execute containment and remediation actions for confirmed incidents.
- Maintain and improve incident-response runbooks.
- Tune and maintain SIEM and EDR detections.
- Apply threat intelligence, including IOCs and TTPs, to investigations and monitoring.
- Participate in the on-call rotation.
- Create actionable post-incident documentation.
Requirements
- 5+ years of experience in security operations, detection and response, or a related security engineering role.
- Experience leading investigations and response efforts across endpoints, cloud environments, and network telemetry.
- Ability to manage complex security incidents from triage through containment, eradication, and recovery.
- Advanced hands-on experience with SIEM and EDR platforms.
- Experience building and tuning detections, improving signal quality, and reducing false positives.
- Experience automating repetitive security workflows and applying AI to investigations and response.
- Skill in applying threat intelligence, IOCs, TTPs, and adversary tradecraft to investigations, threat hunting, monitoring, and detection.
- Ability to participate in an on-call rotation and document incidents clearly.
- Experience mentoring teammates and influencing security operations processes, tooling, and standards.