Senior Information Security Engineer (Detection, Automation & AI)

Zoox
Foster City, CA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Audit Trail Cyber Security Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Log Analysis Open Source Technology Kusto Query Language Security Information and Event Management
+10 more
Data Processing Large Language Models Mitre Att&ck Amazon Virtual Private Cloud (VPC) Cortex XSOAR Platform Kibana Restful APIs Terraform Splunk Devsecops

Job description

Experteer Overview As a Senior Information Security Engineer at Zoox, you design and operationalize security as code, steering detection engineering and automation. You will architect SIEM-driven detection, SOAR playbooks, and AI-enhanced triage to shorten incident response times. You’ll influence how security data is collected, analyzed, and acted upon across cloud and on-prem environments. This is a hands-on, impact-focused role at the intersection of security, automation, and cutting-edge AI.” Compensation / Benefits * Design, build, test, and maintain high-fidelity SIEM detections and map them to MITRE ATT&CK for broad visibility * Create automated playbooks in SOAR and develop Python-based tools and REST API integrations to connect security tools * Treat infrastructure and configuration as code to ensure repeatable deployments and consistency * Develop workflows that use LLMs to automatically analyze and contextualize security alerts and speed initial triage * Serve as senior escalation point for security incidents, guiding containment, eradication, and recovery per IR procedures * Monitor and secure AWS and on-prem workloads across multiple operating systems; perform post-incident reviews to drive automated prevention and detections Tasks * 8+ years of information security, security operations, or DevSecOps experience * Deep hands-on experience with Splunk (SPL, Enterprise Security) or ElasticSIEM (ES QL, KQL, Kibana) for log analysis and detections * Strong Python skills and track record building security tools/automation via APIs * Experience designing automated playbooks in modern SOAR platforms (e.g., Cortex XSOAR, Tines) * Experience with LLM APIs (OpenAI, Anthropic, AWS Bedrock) for security data processing or triage * Knowledge of AWS security services (GuardDuty, CloudTrail, IAM, VPC Flow Logs) * Solid understanding of IR lifecycles (NIST SP 800-61, SANS PICERL); Incident Commander/Handler experience desired * Bonus: CISSP, GCIA, GCIH, or AWS Certified Security - Specialty; Terraform IaC; open-source security contributions Key requirements * paid time off * health insurance * long-term disability * short-term disability * life insurance * Zoox stock appreciation rights / RSUs

Requirements

response point for security incidents, guiding containment, eradication, and recovery per IR procedures * Monitor and secure AWS and on-prem workloads across multiple operating systems; perform post-incident reviews to drive automated prevention and detections Tasks * 8+ years of information security, security operations, or DevSecOps experience * Deep hands-on experience with Splunk (SPL, Enterprise Security) or ElasticSIEM (ES|QL, KQL, Kibana) for log analysis and detections * Strong Python skills and track record building security tools/automation via APIs * Experience designing automated playbooks in modern SOAR platforms (e.g., Cortex XSOAR, Tines) * Experience with LLM APIs (OpenAI, Anthropic, AWS Bedrock) for security data processing or triage * Knowledge of AWS security services (GuardDuty, CloudTrail, IAM, VPC Flow Logs) * Solid understanding of IR lifecycles (NIST SP 800-61, SANS PICERL); Incident Commander/Handler experience desired * Bonus: CISSP, GCIA, GCIH, or AWS Certified aa CISSP, - Specialty; Terraform IaC; open-source security contributions Key requirements * paid time off * health insurance * long-term disability * short-term disability * life insurance * Zoox stock appreciation rights / RSUs

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · WWC Europe 2026

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn · WWC 2022

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:51 min

Executing simple full-text search queries using the Kibana interface

Derek Binkley · LIVE

Videos

See all

Related articles

See all