Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.
190k – 228k/yr
Hybrid8+ YOESecurity Engineering
About the role
Responsibilities
Detection Engineering & SIEM Operations
Design, build, test, and maintain high-fidelity detection logic within the SIEM platform.
Map detections to the MITRE ATT&CK framework to ensure comprehensive visibility across threat vectors.
Tune alerts to minimize false positives and reduce alert fatigue.
Automation & Tooling
Architect and implement automated playbooks within a SOAR platform to reduce mean time to respond (MTTR).
Develop Python scripts, tools, and integrations using REST APIs to connect security tools and data sources.
Treat infrastructure and configuration as code to support automated deployments and consistency.
Next-Generation Triage & AI Integration
Design workflows that use large language models (LLMs) to analyze, summarize, and add context to security alerts.
Build prompt-engineering pipelines or agentic workflows to assist analysts during investigations and reduce initial triage time.
Incident Response & Cloud Infrastructure
Serve as a senior escalation point for security incidents, guiding containment, eradication, and recovery.
Monitor and secure workloads across AWS and on-premises environments.
Conduct post-incident reviews to identify root causes and create automated preventions and detections.
Requirements
8+ years of dedicated experience in information security, security operations, or DevSecOps engineering.
Hands-on experience with Splunk (SPL, Enterprise Security) or Elastic SIEM (ES|QL, KQL, Kibana) for log analysis and detection creation.
Strong proficiency in Python and experience building security tools, scripts, and API-based automation pipelines.
Experience designing and maintaining automated playbooks in a SOAR platform such as Cortex XSOAR or Tines.
Experience using LLM APIs such as OpenAI, Anthropic, or AWS Bedrock for security-log processing or triage workflows.
Understanding of AWS security services, including GuardDuty, CloudTrail, IAM, and VPC Flow Logs.
Familiarity with incident response lifecycles such as NIST SP 800-61 and SANS PICERL.
Experience as an incident commander or incident handler is strongly desired.
Nice-to-Haves
CISSP, GCIA, GCIH, or AWS Certified Security - Specialty certification.
Experience with infrastructure-as-code tools such as Terraform.
Contributions to the open-source security community, including tools or Sigma rules.
Leads operational trust and safety for human-AI collaboration products by reviewing abuse cases, enforcing policy, and building automation and detection systems. Requires 7+ years of recurring case-queue experience plus expertise in AI abuse risks, policy operations, and production safety incidents.
190k – 300k/yrHybrid7+ YOESecurity Engineering
Senior Application Security Engineer
ApolloUnited States
Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.
190k – 273k/yrRemote5+ YOESecurity Engineering
Senior Software Engineer - Security
SkydioSan Mateo, CA
Designs, reviews, and builds security systems for multi-tenant cloud and corporate environments, including architecture guidance, internal tooling like WAF and vuln management, and compliance controls. Requires 5+ years in cloud security, AWS expertise, and strong Python/Go coding skills.
Senior Security Engineer drives security solutions for Sentry's cloud-based application and Kubernetes platform, partnering with engineering on architecture, threat modeling, and implementations. Requires 6+ years experience securing distributed systems, cloud/container environments, and programming in Python/Go/Rust.
190k – 280k/yrHybrid6+ YOESecurity Engineering
Senior Software Engineer, Anti-Abuse & Security
ReplitFoster City, CA
Builds AI-powered anti-abuse detection systems using LLMs to combat phishing, cryptomining, and platform exploitation at scale. Requires 4+ years in security engineering with Python/TypeScript and data analysis experience.