Sr Engineer, Advanced Security Response Team (ASRT)

Thales Transport & Security, Inc.
Phoenix, AZ, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Proxy Servers Bash Shell Information Systems Internet Security Python (Programming Language) Network Security Open Web Application Security Web Application Security Security Information and Event Management SQL Injection TCP/IP
+9 more
Web Applications Scripting Computer Network Technologies Software Security Cyber Threat Analysis Firewalls (Computer Science) Cross-Site Scripting (XSS) Information Technology Ddos

Job description

Thales is looking for a Sr Engineer, Advanced Security Response Team (ASRT), who will work with a team which is dedicated to providing first response to security incidents and focused on the operational aspects of web application security: analyzing threats, suggesting direct methods of remediation and mitigation, and actively working to block attacks in real time.

In this customer-facing role, you will continuously interact with customers to mitigate security attacks while creating long lasting relationships through your technical expertise and engagement. Manage technical escalations, and work closely with Product and CS teams for our application security products (Value Added-Services, Dev, Support, Security, Sr. Management) in order to get issues resolved.

You will be a technical authority of Imperva’s Application Security suite, while constantly improving best practices for solutions and services. You will work closely with Management to implement and expand the global Advanced Security Response program.

Key Areas of Responsibility

  • Serve as a senior technical resource for the Americas Advanced Security Response (ASR) team, providing technical leadership, mentoring engineers, and promoting best practices in incident response and application security.
  • Own the technical resolution of complex customer issues, escalations, and critical incidents, acting as a trusted advisor while ensuring timely communication, root cause analysis, and customer satisfaction.
  • Collaborate with customers, Services Teams, Customer Success, Security Threat Research, Product Management, Product Development, and Engineering teams to resolve high-impact issues and drive product and service improvements.
  • Analyze customer traffic, logs, attack trends, security alerts, and case history to identify risks, recommend security improvements, and strengthen customers’ overall application security posture.
  • Design, implement, and optimize custom security policies that detect, prevent, and mitigate application-layer attacks while minimizing false positives and ensuring optimal application availability.
  • Serve as technical escalation point during sophisticated application attacks, including large-scale Distributed Denial-of-Service (DDoS) incidents, zero-day threats, and advanced web application exploits.
  • Perform forensic analysis of application logs, security events, and attack payloads to identify vulnerabilities, validate attack patterns, and provide actionable remediation recommendations.
  • Document technical findings, create knowledge base articles, and share best practices that improve operational consistency, accelerate incident resolution, and enhance the technical capabilities of the ASR team.
  • Develop and maintain automation solutions to streamline ASR workflows, reduce manual effort, and improve incident response efficiency.

Requirements

  • Minimum of 4 year bachelors degree in Information Systems or Computer Science or Telecommunications or any Technology field and minimum of 6 years experience in application or network security in a customer facing role with at least last 3 years in Security Engineering/Threat Mitigation role OR 4 years’ experience in application or network security with a Master’s degree in a technology field with at least 2 years in Security Engineering/Threat mitigation role.
  • Excellent analytical and problem-solving approach alongside self-learning ability. Passion for customer success/advocacy.
  • Demonstrated experience in working with Internet Security and Networking Technologies such as TCP/IP, HTTP, SSL/TLS, Proxies, Firewalls, OWASP Top 10, and OWASP Automated Threats to Web Applications.
  • Hands-on experience in identifying BOT behaviors and mitigating BOT attacks. And with web application vulnerabilities and common attack techniques (SQLi, XSS, OWASP Top 10, etc).
  • Experience with one or more scripting languages (i.e. python, bash, java, etc).

Applicants must be legally authorized to work in the United States for any employer at the time of hire. This position is not eligible for visa sponsorship or for assuming sponsorship of an employment visa now or in the future.

Preferred Qualifications

  • Expertise with network security architecture, engineering, and security frameworks.
  • Ability to anticipate customer and team expectations/needs and communicate effectively with relevant teams to resolve technical issues.
  • A degree of flexibility to take appointments evenings and mornings, as required., This position will require successfully completing a post-offer background check. Qualified candidates with [a] criminal history will be considered and are not automatically disqualified, consistent with federal law, state law, and local ordinances.

Benefits & conditions

Pulled from the full job description

  • Pet insurance
  • AD&D insurance
  • Retirement plan
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, The reference Total Target Compensation (TTC) market range for this position, inclusive of annual base salary and the variable compensation target, is between

This reflects how companies in a similar industry and geographic region generally pay for similar jobs. This range helps the Company make pay decisions as one data point among many. Where a position falls within this range is also dependent on other factors including - but not limited to - the employee’s career path history, competencies, skills and performance, as well as the company’s annual salary budget, the customer’s program requirements, and the company’s internal equity. Thales may offer additional benefits and other compensation, depending on circumstances not related to an applicant’s status protected by local, state, or federal law.

(For Internal candidate, if you need more information, please raise HR request through MyThales)

Thales provides an extensive benefits program for all full-time employees working 30 or more hours per week and their eligible dependents, including the following: * Elective Health, Dental, Vision, FSA/HSA, Voluntary Life and AD&D, Whole Group Life w/LTC, Critical Illness, Hospital Indemnity, Accident Insurance, Legal Plan, Identity Theft, and Pet Insurance

  • Retirement Savings Plan after 30 days of employment with a company contribution and a match, and with no vesting period
  • Company paid holidays and Paid Time Off
  • Company provided Life Insurance, AD&D, Disability, Employee Assistance Plan, and Well-being Program

About the company

Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

Videos

See all

Related articles

See all