Security Engineer, Public Sector
Security Engineer building high-precision detections, incident response automation, and telemetry pipelines for cloud and SaaS platforms in the Public Sector. Requires active Top Secret clearance, 5+ years in detection engineering or incident response, and production coding skills.
About the job
Responsibilities
- Engineer, test, and deploy detection logic across cloud and enterprise environments, treating detections as software with version control, peer review, and measurable performance.
- Build and maintain incident response automation, runbooks, and tooling that reduce containment timelines without sacrificing developer velocity.
- Mature telemetry pipelines through improved schema design, normalization, enrichment, and quality checks that reduce false positives and increase signal fidelity.
- Perform digital incident investigations to identify and contain potential security breaches.
- Conduct digital forensics and malware analysis to understand attack vectors and adversary methodologies.
- Integrate alerting with messaging and ticketing systems to enable fast, traceable response workflows.
- Partner cross-functionally with IT, security, and engineering teams to harden identity and access patterns, close logging and forensics gaps, and implement maintainable guardrails that scale with the organization.
- Utilize threat intelligence platforms to improve hunting, detection, and response workflows.
- Clearly explain the significance and impact of incidents, providing actionable recommendations to both technical and non-technical stakeholders.
Requirements
- Active Top Secret clearance (required; candidates without will not be considered).
- 5+ years of experience in Detection Engineering, Incident Response, or Security Operations, with a strong emphasis on building and shipping security tooling and automation.
- Proficiency in at least one programming language (e.g., Python, Go) and comfort writing production-grade code.
- Hands-on experience designing or improving detection pipelines, SIEM content, and alerting workflows in cloud-native environments.
- Practical experience with SIEM, EDR, and SOAR tools.
- Strong understanding of modern cyber threats, common attack techniques, and adversary TTPs.
- Familiarity with digital forensics tools and malware analysis techniques.
- Experience with cloud-native environments (e.g., AWS, GCP, Azure) and the security telemetry those environments generate.
- Exposure to threat intelligence platforms and integrating intel into detection and investigation workflows.
- Strong communication skills, with the ability to translate complex security findings into clear business impact.
Nice-to-Haves
- Proficiency in NodeJS, TypeScript, Python, and/or Kubernetes.
- Relevant security certifications (e.g., GCIH, GCFA, GCIA, CISSP, GDSA).
- Experience building integrations or extending SIEM/EDR/SOAR platforms programmatically.
Skills
Node.js, TypeScript, Python, Kubernetes, SIEM, Edr, Soar, AWS, GCP, Azure, Threat Intelligence
Similar jobs
Security Engineering jobsManages global SOC operations, analyst development, shift coverage, quality assurance, and process improvement for 24/7 incident response. Requires 5+ years of SOC analyst experience, Windows forensics expertise, and at least 2 years leading or managing security operations teams.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.
Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.