Senior Security Operations Engineer
About the Role
As a Senior Security Operations Engineer I, you will independently lead the investigation and response to complex security events and incidents. You will serve as an escalation point for other analysts, contribute to the development of detections and automation, and help improve the processes and tooling that support our growing security operations program.
In this role, you will:
Participate in a 24/7/365 SOC, including rotating on-call coverage for overnights and weekends.
Independently investigate and respond to complex security events across Linux, macOS, cloud, and Kubernetes environments.
Determine the scope, impact, severity, and appropriate escalation path for potential security incidents.
Coordinate containment and remediation activities with security, engineering, infrastructure, and operations teams.
Utilize and query SIEM, EDR, and other security tools to identify suspicious activity and develop actionable findings.
Create and improve detections-as-code, investigation procedures, automation, runbooks, and response workflows.
Perform post-incident reviews and recommend improvements to security controls and response capabilities.
Partner with threat intelligence and detection engineering teams to prepare for emerging threats and address gaps in coverage.
Serve as an escalation point and mentor for junior engineers, providing guidance during investigations and reviewing their work.
Lead scoped operational and technical improvement projects that increase the effectiveness and scalability of the SOC.
Who You Are
3–5+ years of experience in security operations, incident response, digital forensics, detection engineering, or a related field.
Strong experience investigating and responding to security events with limited or incomplete information.
Strong working knowledge of Linux and macOS systems, including system internals, logging, and common forensic artifacts.
Experience investigating Kubernetes or container security events.
Proficiency with modern security tools and platforms, including SIEM, EDR, IDS/IPS, and firewalls.
Strong understanding of network protocols, VPNs, proxies, identity systems, and other security technologies.
Experience developing or tuning security detections, preferably using detections-as-code.
Ability to manage complex investigations, communicate risk clearly, and make sound decisions in high-pressure situations.
Experience mentoring less-experienced engineers and collaborating effectively across teams and time zones.
Degree in Computer Science, Computer Engineering, Cyber Security, Information Technology, or equivalent practical experience.
Preferred Qualifications
Experience securing cloud infrastructure or large-scale production environments.
Experience using Python or another scripting language to automate security workflows.
Familiarity with incident response in Kubernetes-based infrastructure.
Experience collaborating with detection engineering, threat intelligence, or software engineering teams.
A demonstrated commitment to staying current with emerging threats, security technologies, and industry best practices.
The base salary range for this role is $134,000 to $179,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).