Skip to content
ZooxZooxFoster City, CA

Senior Information Security Engineer

Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.

190k – 228k/yr
Hybrid8+ YOESecurity Engineering

About the role

Responsibilities

Detection Engineering & SIEM Operations

  • Design, build, test, and maintain high-fidelity detection logic within the SIEM platform.
  • Map detections to the MITRE ATT&CK framework to ensure comprehensive visibility across threat vectors.
  • Tune alerts to minimize false positives and reduce alert fatigue.

Automation & Tooling

  • Architect and implement automated playbooks within a SOAR platform to reduce mean time to respond (MTTR).
  • Develop Python scripts, tools, and integrations using REST APIs to connect security tools and data sources.
  • Treat infrastructure and configuration as code to support automated deployments and consistency.

Next-Generation Triage & AI Integration

  • Design workflows that use large language models (LLMs) to analyze, summarize, and add context to security alerts.
  • Build prompt-engineering pipelines or agentic workflows to assist analysts during investigations and reduce initial triage time.

Incident Response & Cloud Infrastructure

  • Serve as a senior escalation point for security incidents, guiding containment, eradication, and recovery.
  • Monitor and secure workloads across AWS and on-premises environments.
  • Conduct post-incident reviews to identify root causes and create automated preventions and detections.

Requirements

  • 8+ years of dedicated experience in information security, security operations, or DevSecOps engineering.
  • Hands-on experience with Splunk (SPL, Enterprise Security) or Elastic SIEM (ES|QL, KQL, Kibana) for log analysis and detection creation.
  • Strong proficiency in Python and experience building security tools, scripts, and API-based automation pipelines.
  • Experience designing and maintaining automated playbooks in a SOAR platform such as Cortex XSOAR or Tines.
  • Experience using LLM APIs such as OpenAI, Anthropic, or AWS Bedrock for security-log processing or triage workflows.
  • Understanding of AWS security services, including GuardDuty, CloudTrail, IAM, and VPC Flow Logs.
  • Familiarity with incident response lifecycles such as NIST SP 800-61 and SANS PICERL.
  • Experience as an incident commander or incident handler is strongly desired.

Nice-to-Haves

  • CISSP, GCIA, GCIH, or AWS Certified Security - Specialty certification.
  • Experience with infrastructure-as-code tools such as Terraform.
  • Contributions to the open-source security community, including tools or Sigma rules.

Skills

PythonAWSSplunkelastic siemsoarREST APIsLLMsmitre att&ckTerraformLinuxguarddutycloudtrailIAMkibana
Thinking Machines Lab

Safety Operations Lead

Thinking Machines LabSan Francisco, CA

Leads operational trust and safety for human-AI collaboration products by reviewing abuse cases, enforcing policy, and building automation and detection systems. Requires 7+ years of recurring case-queue experience plus expertise in AI abuse risks, policy operations, and production safety incidents.

190k – 300k/yrHybrid7+ YOESecurity Engineering
Apollo

Senior Application Security Engineer

ApolloUnited States

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273k/yrRemote5+ YOESecurity Engineering
Skydio

Senior Software Engineer - Security

SkydioSan Mateo, CA

Designs, reviews, and builds security systems for multi-tenant cloud and corporate environments, including architecture guidance, internal tooling like WAF and vuln management, and compliance controls. Requires 5+ years in cloud security, AWS expertise, and strong Python/Go coding skills.

190k – 250k/yrHybrid5+ YOESecurity Engineering
Sentry

Senior Security Engineer, Application & Platform Security

SentrySan Francisco, CA

Senior Security Engineer drives security solutions for Sentry's cloud-based application and Kubernetes platform, partnering with engineering on architecture, threat modeling, and implementations. Requires 6+ years experience securing distributed systems, cloud/container environments, and programming in Python/Go/Rust.

190k – 280k/yrHybrid6+ YOESecurity Engineering
Replit

Senior Software Engineer, Anti-Abuse & Security

ReplitFoster City, CA

Builds AI-powered anti-abuse detection systems using LLMs to combat phishing, cryptomining, and platform exploitation at scale. Requires 4+ years in security engineering with Python/TypeScript and data analysis experience.

190k – 240k/yrHybrid4+ YOESecurity Engineering