Senior Detection & Security Automation Engineer
This position is 100% remote anywhere in the US
The Company advocates employee career development and employee requests to pursue internal employment opportunities are encouraged. Employees are also encouraged to discuss their career interests with their Manager at any time. Open communication regarding career advancement promotes a positive working environment. Both internal and external candidates are granted equal consideration for available employment opportunities.
Overview:
We are seeking a highly skilled Senior Detection & Security Automation Engineer to drive the evolution of our security monitoring, detection, and automation capabilities. This role will be responsible for expanding SIEM and SOAR capabilities, onboarding and optimizing security telemetry, improving detection coverage, conducting threat hunting activities, and implementing strategies that improve operational effectiveness while controlling telemetry costs. This individual will serve as a senior technical resource and escalation point for security operations activities and will support FedRAMP-related security operations requirements.
What you will do:
Lead administration, expansion, and optimization of the enterprise SIEM platform.
Develop and maintain SOAR workflows and security automation capabilities.
Design, onboard, and maintain log sources across cloud, infrastructure, identity, endpoint, and application environments.
Create, tune, and maintain detection content.
Conduct proactive threat hunting activities and serve as an escalation point for complex investigations.
Implement telemetry management, cost optimization, data fabric, and data lifecycle management capabilities.
Collaborate with IT, Networking, and Cloud Operations to improve security telemetry coverage, detection effectiveness, and incident response readiness.
Mentor team members and establish operational standards.
Support FedRAMP-related security operations activities.
Participate in the incident response on-call rotation.
What we are looking for:
Required:
Bachelor's degree in Information Security or equivalent work experience will be accepted in place of the education requirement
Years of experience: 5+
Years of experience needed with specific skills: 5+ years SIEM/SOAR engineering experience.
Specific technical or software skills required: Strong familiarity with Windows AD and Office 365 environments. Cloud security monitoring and data fabric layer tooling. Strong communication skills and working knowledge of software pipelines.
Travel is required: Approximately 5%
AI Skills/Knowledge:
Experience assessing AI tools for security risk (data leakage, shadow AI, prompt injection); familiarity with AI governance frameworks and enterprise AI policies; uses AI for threat detection, log analysis, or security documentation; contributes to AI tool vetting processes.
Preferred Skills (a plus but not required):
Experience supporting incident response investigations at enterprise scale.
Familiarity with Google SecOps, Microsoft Sentinel, the Microsoft Defender suite.
Familiar with the major cloud providers and their services.
#LI-GB1 #LI-Remote