> Markdown version of [/jobs/ext/1502980-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1502980-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Miradero Cybersecurity, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Artificial Intelligence, Amazon Web Services, Computing Platforms, Microsoft Azure, Computer Programming, Continuous Integration, DevOps, Github, Intrusion Detection and Prevention, Python (Programming Language), Security Information and Event Management, Scripting, Google Cloud, Okta, Retrieval-Augmented Generation, Large Language Models, Mitre Att&ck, Gitlab, Git, Documentation System, Software Version Control, Api Management - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cd7a573f2af4bd4f ## About the Role * 7+ years in Security Engineering, Detection Engineering, or Platform Architecture. * Coding Proficiency: Strong Python skills are non-negotiable. You must be able to write clean, maintainable code for automation and API integration. * DevOps Mindset: Fluency in Git (GitHub/GitLab). Experience with CI/CD pipelines and treating infrastructure/detections as code. * Tooling Expertise: Deep, hands-on experience with CrowdStrike Falcon and ArmorPoint (or equivalent enterprise EDR/XDR platforms). * Infrastructure Knowledge: Strong understanding of cloud telemetry (AWS, Azure, GCP) and identity frameworks (Entra ID/Okta). * Security Frameworks: MITRE ATT&CK fluency and experience translating those tactics into actual detection logic. ## Description Miradero is a specialized MSSP delivering high-fidelity security and compliance services to regulated SMBs (Healthcare/Financial) in Southern California. We are building a lean, high-density operation that prioritizes technical precision over corporate overhead. We are currently in the launch phase and seeking a founding operational leader to build our SOC from the ground up. About the Role We are looking for a Toolsmith. You will be the primary builder of our technical infrastructure, responsible for transforming security requirements into scalable code. You are not a "tool operator"; you are a platform engineer who uses security tools as components in a larger, automated system. You will partner with the CTO to implement our proprietary AI layer and work alongside the SOC Manager to ensure that detection logic is operationalized without friction. What You'll Do * Platform Engineering: Architect and build the multi-tenant telemetry pipeline. Implement "Detection-as-Code" using GitHub/GitLab for version control and CI/CD deployment of detection logic. * Tooling Orchestration: Own the deep technical configuration and integration of CrowdStrike Falcon (EDR) and ArmorPoint (XDR/SIEM). You will be responsible for the "plumbing" that ensures high-signal telemetry flows from endpoint to analyst. * Python Development: Write production-grade Python scripts to automate repetitive SOC tasks, build custom API integrations between our security stack and PSA/Documentation tools, and develop internal tooling. * AI Implementation: Co-lead the engineering of our private AI layer. This includes building RAG (Retrieval-Augmented Generation) pipelines and developing LLM-based classifiers to automate triage and summary generation. * Detection Authoring: Act as the senior authority for detection content across CrowdStrike (CQL/LogScale) and ArmorPoint, ensuring rules are tuned to minimize false positives. * Technical Pre-Sales: Serve as the technical authority on standard client engagements, scoping the technical requirements for pilot deployments and ensuring architectural sanity. * Escalation Engineering: Act as the final technical stop for complex root-cause analysis and deep-dive investigations that exceed the SOC's standard playbooks. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)