More jobs:
Senior Security Engineer
Job in
Palo Alto, Santa Clara County, California, 94306, USA
Listed on 2026-08-22
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-22
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations
Job Description & How to Apply Below
Responsibilities
- Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
- Oversee and optimize Managed Detection and Response (MDR), as well as Security Orchestration, Automation, and Response (SOAR), capabilities and related integrations.
- Serve as a technical owner for SIEM operations, including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
- Develop, tune, and maintain high-value Threat Detection content, including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity-based alerts.
- Analyze security events, threat intelligence, and attacker tradecraft to improve detection coverage, validate alert effectiveness, and support incident response investigations.
- Support and participate in Incident Response activities, including triage, investigation, containment, eradication, recovery, evidence collection, and post-incident reviews.
- Support security investigations involving endpoint activity, cloud events, identity logs, network telemetry, SaaS activity, and other relevant data sources.
- Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations with other security systems.
- Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
- Manage threats from AWS and cloud-native environments, including monitoring and responding to Cloud Trail, VPC Flow Logs, workload logs, IAM activity, container activity, and cloud security findings.
- Build dashboards, metrics, and reports to measure Security Tool health, detection coverage, Vulnerability Management posture, Incident Response effectiveness, and overall security program maturity.
- Develop and maintain documentation, operational runbooks, incident response playbooks, engineering standards, and tool administration procedures.
- Evaluate AI-assisted security capabilities for detection, response, vulnerability management, and automation, while helping define how AI systems, agents, and usage are logged, monitored, and assessed for risk.
- Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross‑functional partners.
- Stay current on emerging threats, attacker tradecraft, vulnerability trends, Security Tooling, Cloud Security practices, and Security Engineering best practices.
- 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, Detection Engineering, or a related security role.
- Broad hands‑on experience administering and improving enterprise security tools.
- Experience supporting Incident Response in a SOC or enterprise security environment.
- Strong experience with SIEM platforms, including log ingestion, alerting, detection content, dashboards, and operational support.
- Experience with EDR platforms, including investigation, containment, policy management, and response workflows.
- Experience with Vulnerability Management platforms and processes, including vulnerability scanning, prioritization, remediation tracking, and reporting.
- Hands‑on experience securing and monitoring AWS or other cloud environments.
- Experience working with identity and access logs, preferably including Okta or similar identity platforms.
- Strong understanding of endpoint, cloud, identity, network, SaaS, and infrastructure security telemetry.
- Experience developing documentation, runbooks, playbooks, and repeatable operational procedures.
Demonstrates expertise in Security Engineering and Operations, with a strong focus on SIEM and EDR platforms, Vulnerability Management, and Incident Response. Proficient in developing detection content, managing cloud security, and providing technical leadership in security practices.
#J-18808-LjbffrPosition Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×