Senior Information Security Engineer
The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
About the job
Responsibilities
Threat Hunting and Detection
- Conduct hypothesis-driven and intelligence-led threat hunts across endpoint, network, identity, cloud, email, application, and SaaS telemetry.
- Translate threat intelligence and adversary TTPs into hunt hypotheses, SIEM queries, correlation rules, dashboards, and MITRE ATT&CK-aligned alerts.
- Convert hunt findings and incident lessons into detections, prevention controls, and response playbooks.
- Evaluate detection coverage, false-positive rates, and telemetry quality.
Security Engineering and Platform Ownership
- Design, implement, test, document, and operate security technologies including SIEM, EDR/XDR, IDS/IPS, firewalls, WAF, vulnerability management, email security, identity protections, and automation.
- Strengthen security across AWS, Microsoft 365, Entra ID, Windows, macOS, Linux, containers, and SaaS environments.
- Improve endpoint and identity controls, including secure configuration, conditional access, least privilege, account lifecycle, and credential hygiene.
- Maintain documentation, standards, and runbooks; manage vendor relationships.
Incident Response and Vulnerability Management
- Lead incident response as the senior technical escalation point, including triage, scoping, containment, eradication, recovery, evidence preservation, root-cause analysis, and lessons learned.
- Build and test incident-response playbooks for high-risk scenarios.
- Lead vulnerability identification, validation, risk-based prioritization, remediation coordination, retesting, and closure.
- Coordinate security assessments, penetration testing, and adversary simulation.
Automation and Continuous Improvement
- Build scripts, integrations, and automated workflows using Python, PowerShell, and APIs.
- Establish security metrics covering detection, remediation, and incident trends.
- Own and improve firewall policies, VPN and secure connectivity, segmentation, traffic filtering, and monitoring.
- Review systems, integrations, and architecture changes to define risk-based security requirements.
- Evaluate AI-assisted security workflows with safeguards for sensitive data and human validation.
Collaboration and Leadership
- Lead cross-functional security initiatives and advise engineering, IT, legal, and business teams.
- Mentor junior team members and develop repeatable team practices.
- Support audits and assessments and maintain policies and standards aligned with NIST, ISO 27001, SOC 2, and financial-services requirements.
Requirements
- 5+ years of experience in security engineering, threat hunting, detection engineering, security operations, incident response, or infrastructure security.
- Proven ability to independently lead complex technical projects end-to-end.
- Hands-on experience with SIEM, EDR/XDR, firewalls, IDS/IPS, WAF, vulnerability-management, email-security, and identity-security platforms.
- Strong knowledge of attacker TTPs, incident-response processes, and MITRE ATT&CK.
- Solid understanding of network security fundamentals, including segmentation, firewalls, VPNs, DNS, HTTP/TLS, and access control.
- Experience securing cloud and enterprise environments; AWS, Microsoft 365, Entra ID, Windows, macOS, and Linux experience preferred.
- Scripting and automation ability with Python, PowerShell, Bash, and REST APIs.
- Strong analytical and communication skills, including the ability to work with incomplete or ambiguous information.
- High integrity and discretion when working with privileged systems and sensitive investigations.
Nice-to-Haves
- Fintech, financial-services, or other regulated-technology experience.
- Experience with CrowdStrike, Microsoft Defender, Splunk, Rapid7, Palo Alto, Fortinet, Cisco, or Cloudflare.
- AWS security services, cloud-native detection, and Docker/ECS or comparable container-security experience.
- DevSecOps practices including SAST, DAST, SCA, secrets detection, CI/CD, and infrastructure as code.
- Digital forensics, malware analysis, or offensive-security experience.
- SOAR or detection-as-code pipeline experience.
- Threat-intelligence platforms and OSINT techniques.
- Relevant degree or certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, OSCP, CCSP, or AWS Security Specialty.
Compensation and Benefits
- Annual compensation of $110,000–$140,000.
- Medical, dental, and vision insurance.
- HSA and FSA accounts.
- Life and disability insurance.
- 401(k) plan with employer contributions.
- Employee Assistance Program.
- Flexible paid time off.
- Commuter benefits, pet insurance, and continuing-education assistance.
Skills
SIEM, Edr/Xdr, Threat Hunting, Incident Response, Mitre Att&Ck, AWS, Microsoft 365, Entra Id, Python, PowerShell, Bash, REST APIs, Network Security, Vulnerability Management, Docker
Similar jobs
Security Engineering jobsBuild and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.