Advanced Security Engineer, Enterprise Security
Listed on 2026-06-28
-
IT/Tech
Cybersecurity, Security Management & Operations
Advanced Security Engineer, Enterprise Security
Chicago , IL / Louisville , KY / Wichita , KS ...View All
Posting TypeRemote/Hybrid
Job OverviewThe Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design, deployment, implementation and optimization of AI-enabled security technologies at all layers. With the goal of enabling automated orchestration of security operations into day-to-day detection and response capabilities, hardening rigor, and rapid response.
This role works closely with the Senior Manager of Enterprise Security and cross-functional engineering teams to reduce the organization's attack surface, enable threat landscape adaptability, and improve detection and response times across Relativity's technical ecosystem.
- As applicable, design, deploy and optimize security controls that span perimeter, network, host, application, identity and data layers, ensuring and maintaining effectiveness of controls at each layer.
- Collaborate cross-functionally to ensure controls are aligned to industry recognized frameworks.
- Validate that telemetry from each layer feeds the central analytics platforms and supports 360-degree visibility and appropriate attack surface coverage.
- Continuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly.
- Proactively partner with IT, Engineering and other stakeholders to embed security controls natively.
- Periodically provide recommendations on technical design of security controls aligned to vulnerabilities, risks, issues and/or events.
- Support purple-team exercises and control-efficacy testing to verify depth and resilience under attack conditions.
- Ensure redundant, complementary security capabilities to prevent bypasses and ensure failure redundancy through all security layers.
- Deploy, integrate, optimize and manage EDR/XDR platforms and periodically define custom detections and automated response actions across security tooling.
- Establish and enforce endpoint and image hardening baselines, configuration standards, and application control baselines.
- Integrate endpoint telemetry into the central analytics platform (or SIEM) to support security context and cross-domain correlation; ensure SIEM coverage is adequate and effective.
- Collaborate cross-functionally to ensure security events, exposures, vulnerabilities and alerts are remediated within appropriate SLA's.
- Investigate endpoint-based alerts and incidents through to root cause: perform triage, forensic artifact collection (memory, disk, logs), timeline reconstruction, and containment/eradication actions.
- Collaborate cross-functionally to support purple team exercises and analyze security telemetry to surface anomalous and malicious behavior to the relevant stakeholders.
- Develop, execute and document structured hunts mapped to MITRE ATT&CK and ATLAS techniques and current threat intelligence.
- Perform exposure analysis on identified vulnerabilities, zero-day, alert telemetry, threat intelligence feeds and notifications from partners and customers and conclude on exploitability risk and/or exposure.
- Maintain awareness of the evolving threat landscape, adversary TTP's, and emerging vulnerabilities and their relevance to Relativity's technical ecosystem and organizational trajectory.
- Standardize and document hunt methodology, hypotheses, and outcomes and collaborate with security stakeholders to mature threat hunting program over time.
- Convert successful hunts, exposure analysis, purple team findings and alerts into durable, automated detections and containment logic and improved coverage.
- Build and maintain SOAR workflows that automate enrichment, triage, containment, and routine response actions.
- Measure and continuously improve the impact of automation on time-based detection, containment and response to reduce threat actor dwell time.
- Identify, evaluate and operationalize AI/ML capabilities for semantic anomaly detection, behavioral analytics, alert triage, and prioritization.
- Implement data classification, discovery, and data security posture management across cloud and on-premises stores.
- Deploy and tune data loss prevention controls across endpoints, network, email, cloud and SaaS surfaces.
- Investigate data key risk indicators associated with data access, exfiltration, and integrating data telemetry into central analytics (SIEM).
- Bachelor's in Computer Science, Information Security, or equivalent experience.
- 5+ years of hands-on experience in enterprise security engineering, with a focus on network and/or endpoint security domains (or) Master's Degree in Cybersecurity or relevant field.
- Hands-on experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).