> Markdown version of [/jobs/ext/1976058-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1976058-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** SanDisk - **Location:** Milpitas, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Linux, Dynamic Program Analysis, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Malware, SentinelOne Expertise, Vulnerability Analysis - **Published:** August 7, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/senior-security-engineer-milpitas-ca-usa-58829137 ## About the Role _ metrics across the enterprise * Develop testing frameworks to validate detections, policies, and response actions * Enable high-fidelity detections through detection engineering tooling and telemetry * Maintain malware detonation/analysis environments and support tooling for static/dynamic analysis * Assess emerging threats and evaluate tooling coverage and gaps * Automate routine SOC operations and build scripts to reduce analyst toil * Author engineering documentation and define standards/guardrails for tool usage * Support audits, tabletop exercises, and incident reviews from a tooling perspective Tasks * 5-10+ years in security engineering or advanced SOC roles * Hands-on experience with EDR/XDR platforms (CrowdStrike, Defender, SentinelOne) * Experience owning SOC platforms (beyond just consuming alerts) * Strong Windows internals, Linux, and server telemetry knowledge * Experience supporting malware analysis and sandboxing * Familiarity with SOC workflows, detection pipelines, and IR requirements * Scripting and automation skills (PowerShell, Python) * Knowledge of attacker TTPs mapped to MITRE ATT&CK * Preferred exposure to SIEM/SOAR integrations and vulnerability management * Relevant certifications (GIAC, GREM, GCED, GCIA, OSCP) preferred Key requirements * paid vacation * paid sick leave * medical/dental/vision insurance * 401(k) plan with employee stock purchase plan * tuition reimbursement * short-term incentive plan ## Description Experteer Overview In this role you will own and evolve the SOC tooling stack to enable a detection-first security operation. You will work closely with SOC analysts and cross-functional teams to ensure tools are scalable, reliable, and tightly aligned with adversary behaviors. You will shape detection capabilities, automate workflows, and improve EDR health to accelerate investigations. This is a hands-on, technically deep position at the core of Sandisk's security program, offering meaningful impact on enterprise defenses. Compensation / Benefits * Engineer, deploy, and maintain core SOC platforms (EDR/XDR, malware analysis, sandboxing, email security, vulnerability scanning) * Act as technical owner for SOC platforms with lifecycle management and decommissioning * Ensure scalability, reliability, performance, and forensic integrity of SOC tooling * Collaborate with IT and platform teams to resolve infrastructure and access issues * Own EDR engineering, hygiene standards, and health metrics across the enterprise * Develop testing frameworks to validate detections, policies, and response actions * Enable high-fidelity detections through detection engineering tooling and telemetry * Maintain malware detonation/analysis environments and support tooling for static/dynamic analysis * Assess emerging threats and evaluate tooling coverage and gaps * Automate routine SOC operations and build scripts to reduce analyst toil * Author engineering documentation and define standards/guardrails for tool usage * Support audits, tabletop exercises, and incident reviews from a tooling perspective Tasks * 5-10+ years in security engineering or advanced SOC roles * Hands-on experience with EDR/XDR platforms (CrowdStrike, Defender, SentinelOne) * Experience owning SOC platforms (beyond just consuming alerts) * Strong Windows internals, Linux, and server telemetry knowledge * Experience supporting malware analysis and sandboxing * Familiarity with SOC workflows, detection pipelines, and IR requirements * Scripting and automation skills (PowerShell, Python) * Knowledge of attacker TTPs mapped to MITRE ATT&CK * Preferred exposure to SIEM/SOAR integrations and vulnerability management * Relevant certifications (GIAC, GREM, GCED, GCIA, OSCP) preferred Key requirements * paid vacation * paid sick leave * medical/dental/vision insurance * 401(k) plan with employee stock purchase plan * tuition reimbursement * short-term incentive plan ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)