> Markdown version of [/jobs/ext/1770992-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1770992-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** RxBenefits Inc - **Location:** Atlanta, GA, United States (Remote available) - **Experience:** Expert - **Salary:** $312,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Bash Shell, Cloud Computing, Cyber Security, Computer Networks, Linux, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Performance Tuning, Windows PowerShell, Security Information and Event Management, Data Logging, Scripting, Data Ingestion, Office365, Software Security, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Sumo Logic (Software) - **Published:** July 14, 2026 - **Apply:** https://dejobs.org/x/x/A0F2401D226C4BCBAE626349BA374E4F/job/ ## About the Role * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience required. * Cyber-specific certification required (e.g., GCIH, GCFA, CISSP, or a relevant SIEM/vendor certification). * Minimum of seven (7) years of IT experience, with at least four (4) years in a security engineering, SOC, or incident response role. * Expert-level, hands-on experience with SIEM platforms (Sumo Logic strongly preferred), including log architecture, correlation rule development, and performance tuning. * Working knowledge of incident response methodology (e.g., NIST 800-61) and fluency with the MITRE ATT&CK framework. * Strong understanding of AWS security logging and detection services (CloudTrail, GuardDuty, Security Hub) and Windows/Linux log sources; Linux required. * Hands-on experience investigating alerts and telemetry from EDR (e.g., CrowdStrike), network security platforms (e.g., Zscaler), and O365/identity log sources. * Advanced scripting and automation experience with PowerShell, Python, or Bash required. * Ability to work fully independently and lead multiple complex investigations and projects to completion. * Excellent interpersonal and communication skills (verbal and written) across all levels of the organization. * Strong analytical and problem-solving skills, with sound judgment under incident pressure. * Ability to deliver on objectives. Preferred Skills/Experience: * Experience participating in tabletop exercises preferred. * Healthcare industry experience preferred. ## Description RxBenefits is seeking a highly experienced Senior Security Engineer to lead our SIEM platform, security monitoring, and incident response function. This role owns the health and effectiveness of the security operations program end to end: log source architecture, detection engineering, alert triage, threat hunting, and incident response. The Senior Security Engineer operates as the technical authority for detecting and responding to threats across cloud, endpoint, identity, and network environments, and works closely with infrastructure and application security teams to close the loop from detection to remediation. The ideal candidate combines deep SIEM engineering skill with hands-on incident response experience and can operate independently in a HIPAA-regulated environment working toward NIST, ISO, and SOC 2 requirements. Essential Job Responsibilities Include: * SIEM Engineering & Administration: Own the SIEM platform end to end, including log source onboarding, correlation rule development, detection tuning, dashboarding, and platform performance and cost management. * Incident Response: Lead the full incident response lifecycle, including triage, containment, eradication, recovery, root cause analysis, and post-incident reporting. * Threat Detection & Hunting: Build and maintain detection content mapped to MITRE ATT&CK; conduct proactive threat hunts across cloud infrastructure, endpoints, identity systems, and network traffic. * Security Operations: Define and enforce SOC processes, including alert triage workflows, escalation paths, on-call procedures, and operational metrics such as mean time to detect and mean time to respond. * Log Source Architecture: Manage ingestion pipelines from cloud audit logs (e.g., AWS CloudTrail), EDR, identity providers, network security platforms, and endpoint management tools into the SIEM. * Threat Intelligence Integration: Operationalize threat intelligence feeds into detection rules, enrichment workflows, and hunting hypotheses. * Automation & Scripting: Develop automation for detection engineering, alert enrichment, and response playbooks to reduce manual analyst workload and speed response time. * Tabletop Exercises: Lead in and support tabletop exercises to assess and continuously improve incident response procedures, crisis management, and disaster recovery plans. * Cross-Functional Investigations: Correlate findings across infrastructure, application security, and identity teams during investigations, and drive permanent remediation of identified risks. * Reporting: Produce technical incident reports and SOC posture reporting that give leadership clear visibility into detection coverage, response performance, and outstanding risk. * Standards & Documentation: Define and enforce detection engineering standards, runbooks, and playbooks used across the security team. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)