Senior Security Engineer

SanDisk
Milpitas, CA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Linux Dynamic Program Analysis Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Security Information and Event Management Software Vulnerability Management Mitre Att&ck Malware SentinelOne Expertise Vulnerability Analysis

Job description

Experteer Overview In this role you will own and evolve the SOC tooling stack to enable a detection-first security operation. You will work closely with SOC analysts and cross-functional teams to ensure tools are scalable, reliable, and tightly aligned with adversary behaviors. You will shape detection capabilities, automate workflows, and improve EDR health to accelerate investigations. This is a hands-on, technically deep position at the core of Sandisk’s security program, offering meaningful impact on enterprise defenses. Compensation / Benefits * Engineer, deploy, and maintain core SOC platforms (EDR/XDR, malware analysis, sandboxing, email security, vulnerability scanning) * Act as technical owner for SOC platforms with lifecycle management and decommissioning * Ensure scalability, reliability, performance, and forensic integrity of SOC tooling * Collaborate with IT and platform teams to resolve infrastructure and access issues * Own EDR engineering, hygiene standards, and health metrics across the enterprise * Develop testing frameworks to validate detections, policies, and response actions * Enable high-fidelity detections through detection engineering tooling and telemetry * Maintain malware detonation/analysis environments and support tooling for static/dynamic analysis * Assess emerging threats and evaluate tooling coverage and gaps * Automate routine SOC operations and build scripts to reduce analyst toil * Author engineering documentation and define standards/guardrails for tool usage * Support audits, tabletop exercises, and incident reviews from a tooling perspective Tasks * 5-10+ years in security engineering or advanced SOC roles * Hands-on experience with EDR/XDR platforms (CrowdStrike, Defender, SentinelOne) * Experience owning SOC platforms (beyond just consuming alerts) * Strong Windows internals, Linux, and server telemetry knowledge * Experience supporting malware analysis and sandboxing * Familiarity with SOC workflows, detection pipelines, and IR requirements * Scripting and automation skills (PowerShell, Python) * Knowledge of attacker TTPs mapped to MITRE ATT&CK * Preferred exposure to SIEM/SOAR integrations and vulnerability management * Relevant certifications (GIAC, GREM, GCED, GCIA, OSCP) preferred Key requirements * paid vacation * paid sick leave * medical/dental/vision insurance * 401(k) plan with employee stock purchase plan * tuition reimbursement * short-term incentive plan

Requirements

_ metrics across the enterprise * Develop testing frameworks to validate detections, policies, and response actions * Enable high-fidelity detections through detection engineering tooling and telemetry * Maintain malware detonation/analysis environments and support tooling for static/dynamic analysis * Assess emerging threats and evaluate tooling coverage and gaps * Automate routine SOC operations and build scripts to reduce analyst toil * Author engineering documentation and define standards/guardrails for tool usage * Support audits, tabletop exercises, and incident reviews from a tooling perspective Tasks * 5-10+ years in security engineering or advanced SOC roles * Hands-on experience with EDR/XDR platforms (CrowdStrike, Defender, SentinelOne) * Experience owning SOC platforms (beyond just consuming alerts) * Strong Windows internals, Linux, and server telemetry knowledge * Experience supporting malware analysis and sandboxing * Familiarity with SOC workflows, detection pipelines, and IR requirements * Scripting and automation skills (PowerShell, Python) * Knowledge of attacker TTPs mapped to MITRE ATT&CK * Preferred exposure to SIEM/SOAR integrations and vulnerability management * Relevant certifications (GIAC, GREM, GCED, GCIA, OSCP) preferred Key requirements * paid vacation * paid sick leave * medical/dental/vision insurance * 401(k) plan with employee stock purchase plan * tuition reimbursement * short-term incentive plan

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all