# Senior Information Security Engineer

**Company:** [Zoox](https://hotfix.jobs/companies/zoox)
**Location:** Foster City, CA
**Role:** Security Engineering
**Salary:** $190k – $228k/yr
**Experience:** 8+ years
**Skills:** Python, AWS, Splunk, elastic siem, soar, REST APIs, LLMs, mitre att&ck, Terraform, Linux, guardduty, cloudtrail, IAM, kibana
**Posted:** 2026-08-04

> Senior Information Security Engineer who builds SIEM detections, SOAR automation, and LLM-powered alert-triage workflows. The role requires 8+ years in information security or DevSecOps, strong Python and AWS expertise, and hands-on incident response experience.

## Job Description

## Responsibilities

### Detection Engineering & SIEM Operations
- Design, build, test, and maintain high-fidelity detection logic within the SIEM platform.
- Map detections to the MITRE ATT&CK framework to ensure comprehensive visibility across threat vectors.
- Tune alerts to minimize false positives and reduce alert fatigue.

### Automation & Tooling
- Architect and implement automated playbooks within a SOAR platform to reduce mean time to respond (MTTR).
- Develop Python scripts, tools, and integrations using REST APIs to connect security tools and data sources.
- Treat infrastructure and configuration as code to support automated deployments and consistency.

### Next-Generation Triage & AI Integration
- Design workflows that use large language models (LLMs) to analyze, summarize, and add context to security alerts.
- Build prompt-engineering pipelines or agentic workflows to assist analysts during investigations and reduce initial triage time.

### Incident Response & Cloud Infrastructure
- Serve as a senior escalation point for security incidents, guiding containment, eradication, and recovery.
- Monitor and secure workloads across AWS and on-premises environments.
- Conduct post-incident reviews to identify root causes and create automated preventions and detections.

## Requirements
- 8+ years of dedicated experience in information security, security operations, or DevSecOps engineering.
- Hands-on experience with Splunk (SPL, Enterprise Security) or Elastic SIEM (ES|QL, KQL, Kibana) for log analysis and detection creation.
- Strong proficiency in Python and experience building security tools, scripts, and API-based automation pipelines.
- Experience designing and maintaining automated playbooks in a SOAR platform such as Cortex XSOAR or Tines.
- Experience using LLM APIs such as OpenAI, Anthropic, or AWS Bedrock for security-log processing or triage workflows.
- Understanding of AWS security services, including GuardDuty, CloudTrail, IAM, and VPC Flow Logs.
- Familiarity with incident response lifecycles such as NIST SP 800-61 and SANS PICERL.
- Experience as an incident commander or incident handler is strongly desired.

## Nice-to-Haves
- CISSP, GCIA, GCIH, or AWS Certified Security - Specialty certification.
- Experience with infrastructure-as-code tools such as Terraform.
- Contributions to the open-source security community, including tools or Sigma rules.



## Similar roles

- [Safety Operations Lead](https://hotfix.jobs/jobs/c83ceda2-d7a3-405c-ae10-b680f0dd7577) - Thinking Machines Lab - San Francisco, CA - $190k – $300k/yr
- [Senior Application Security Engineer](https://hotfix.jobs/jobs/45402dbe-ee8f-4a25-9817-c293c712505a) - Apollo - Remote - $190k – $273k/yr
- [Senior Software Engineer - Security](https://hotfix.jobs/jobs/e3185b76-5a92-4a24-956c-5a19fd20d75d) - Skydio - San Mateo, CA - $190k – $250k/yr
- [Senior Security Engineer, Application & Platform Security](https://hotfix.jobs/jobs/935a9604-4c7b-48d9-a08b-cb94b61fb298) - Sentry - San Francisco, CA - $190k – $280k/yr
- [Senior Software Engineer, Anti-Abuse & Security](https://hotfix.jobs/jobs/af883f53-3346-4cc3-827e-3e9664ff95c3) - Replit - Foster City, CA - $190k – $240k/yr

**Apply:** https://hotfix.jobs/jobs/ce08603c-ef42-46b3-9e93-601ca9a1e56f
**Canonical:** https://hotfix.jobs/jobs/ce08603c-ef42-46b3-9e93-601ca9a1e56f