> Markdown version of [/jobs/ext/1919375-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/1919375-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - **Company:** Edison Scientific, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Open Web Application Security, Performance Tuning, Phishing, Zero Trust Network Access, Runbook, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Logging, Google Cloud, Okta, Large Language Models, Software Security, Kubernetes, Cybercrime, Gsuite, Docker - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b6d064ac90e469aa ## About the Role * 5+ years in Security Engineering, Security Operations, Incident Response, or related cybersecurity roles. * Hands-on AWS and GCP security experience. * Experience with SIEM, EDR, detection engineering, and threat hunting. * Strong knowledge of identity security, cloud IAM, and Zero Trust. * Experience securing Kubernetes, Docker, and Infrastructure-as-Code. * Knowledge of API Security and OWASP Top 10. * Experience developing security metrics, KPIs, dashboards, and executive-level reporting. * Familiarity with SOC 2 or similar frameworks. * Excellent communication and cross-functional collaboration. Bonus points for * Experience using AI/LLMs to improve security operations, investigations, detection engineering, or automation. * Experience designing, implementing, and tuning IDS/IPS, DLP, or related security controls. * Experience developing and maintaining security policies, standards, runbooks, and SOPs for technical and business stakeholders. ## Description We're hiring our founding Security Operations Engineer to help build and scale our security program from the ground up. This is a hands-on role for a builder who wants to shape security from the ground up. As our first dedicated Security Engineer, you'll partner with the IT & Security Leader to design and scale security across cloud, identity, applications, endpoints, and incident response. You'll lead technical execution while collaborating on architecture, priorities, and long-term strategy. This role offers meaningful ownership, active mentorship, and the opportunity to build a practical security program that grows with the company., Security Operations & Incident Response * Partner with the IT & Security Leader to build and mature the company's security operations program. * Design, implement, and continuously improve SIEM, EDR, and endpoint security capabilities. * Develop, tune, and maintain detections across cloud, endpoint, identity, and SaaS platforms. * Lead technical incident investigations while collaborating on incident response planning and post-incident reviews. Cloud, Identity & Infrastructure Security * Partner on designing and continuously improving AWS and GCP security posture. * Lead implementation of identity security across Okta, Google Workspace, cloud IAM, privileged access, MFA, and SSO. * Secure Kubernetes, Docker, and Infrastructure-as-Code environments. * Design and maintain centralized security logging and telemetry. Application Security * Lead the vulnerability management program in partnership with Engineering and IT. * Partner with Engineering to improve secure software development, API security, and application security. * Lead security awareness initiatives, phishing simulations, and tabletop exercises. * Evaluate emerging AI technologies that improve security operations while supporting secure AI adoption. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)