Security Engineer
Role details
Job location
Tech stack
Job description
In this role, you will engineer and automate security controls across our Microsoft security ecosystem, mature our security information event manager (SIEM) processes toward infrastructure-as-code (IaC), and build secure cloud-native automation to accelerate security operations. You will execute proactive threat hunts leveraging threat intelligence, serve as an escalation point for complex alerts by coordinating with infrastructure, application, network, and security teams, and partner across the business to reduce vulnerability risk. You'll also mature incident response processes and documentation, ensuring repeatable, high-quality outcomes., Detection Engineering Design and implement SIEM content using standardized deployments across environments.
SOAR & Secure Automation Build, harden, and maintain SIEM automation using cloud-native automation tools.
Threat Hunting & Intelligence Integration Develop and conduct hunts using scripting & query-based languages across endpoint, network, and identity telemetry. Enrich hypotheses with threat intelligence and pivot to investigation and detection creation.
Incident Response & Escalation Act as an escalation point for complex alerts; lead triage, scoping, containment, and eradication; coordinate cross-functional groups and drive root cause analysis and lessons learned, including evidence collection and malware triage to support investigations.
Vulnerability Risk Reduction Support investigations into risk-related findings.
Requirements
- Hands-on experience with SIEM administration and XDR experience
- Experience with cloud-native automation tooling and managing SIEM and security configurations.
- Experience with SOAR tooling
- Advanced Incident response capabilities, including threat triage, containment/eradication, host-based forensics, and post-incident improvements; experienced in coordinating with cross-functional teams.
- Experience in developing threat hunting using query languages with threat intelligence.
- Hands-on experience in vulnerability management
PREFERRED REQUIREMENTS:
- Security operations or cloud security industry-standard certifications
- Experience implementing "SIEM-as-code" frameworks with repository governance, branching strategies, and automated content testing in CI/CD.
- Aligning IR processes with NIST SP 800-61/CIS controls and evidence collection requirements.
- Background in security operations, systems administration, and/or network administration.
WORK ENVIRONMENT AND PHYSICAL DEMANDS
- The work environment and physical demands described here are representative of those that must be met by the employee to successfully perform the essential functions of the job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Standard office environment. Some stress may occur with tight deadlines and long hours.