> Markdown version of [/jobs/ext/2693185-sr-security-engineer](https://www.wearedevelopers.com/jobs/ext/2693185-sr-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer - **Company:** World Wide Technology - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $125,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Amazon Elastic Compute Cloud, Cloud Computing, Cyber Security, Computer Networks, Linux, Elasticsearch, Hypervisor, Intrusion Detection Systems, Linux System Administration, Network Architecture, Network Forensics, Packet Analyzer, Logstash, Software Deployment, Virtual Machines, Scripting, Mitre Att&ck, Amazon Virtual Private Cloud (VPC), Tanium Platform Expertise, Kubernetes, Information Technology, Cybercrime, Performance Monitor, Hashicorp, Api Gateway, Kibana, Cyber Warfare, Cisco, Docker - **Published:** September 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9138777/sr-security-engineer ## About the Role This is a full-time direct hire position and you must currently have an active Top Secret/SCI Clearance or above. We are not able to offer visa sponsorship, 1099 status, or work with C2C for this role., * Top Secret clearance with SCI eligibility required * Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field. * 4+ years of experience supporting cybersecurity platforms, cyber operations environments, or enterprise IT systems. * Experience with network detection and response (NDR) and intrusion detection systems (IDS) such as Zeek, Suricata, or equivalent * Experience using the Elastic Stack (Elasticsearch, Logstash, Kibana), MDE, Trellix, or Tanium to ingest, correlate, and analyze large-scale security telemetry and develop queries and dashboards to detect anomalous behavior and indicators of compromise. * Experience performing threat hunting in AWS environments using cloud telemetry such as CloudTrail and VPC Flow Logs, with familiarity leveraging HashiCorp Boundary for secure, identity-aware access to investigative systems and cloud resources. * Experience with Docker, Podman or Kubernetes for application deployments. * Experience with Type 1 hypervisors, virtual machines, EC2 instances, and Linux administration * Experience supporting security products or security operations workflows. * Minimum 4 years' experience in DoW incident response and threat hunting * Familiarity with the Pyramid of Pain and the MITRE ATT&CK framework. * DoD 8570 IAT Level II certification (e.g., Security+ or equivalent). * AWS API integration experience * AWS Cloud Certification, * Experience conducting threat hunting within enterprise or mission-hosted network environments by analyzing network traffic, authentication activity, endpoint telemetry, and application logs to identify malicious activity, lateral movement, and persistence mechanisms. * Experience configuring network infrastructure to enable packet capture solutions. Familiarity with the Cisco 3-Layer Hierarchical Model, Purdue Model, and other architectural frameworks (Strongly Preferred) * GIAC Certified Forensic Analyst (GCFA) Want to learn more about Government Services? Check us out on our platform ## Description * Support deployment, configuration, API integration and sustainment of cloud-based cyber platform components. * Maintain and troubleshoot Linux based applications on various distributions. * Maintain and troubleshoot services hosted as containers or virtual machines. * Maintain and troubleshoot network forensics technologies similar to Zeek and Suricata. * Develop and maintain automation using python scripts to support platform operations and security analytics. * Support integration of threat intelligence data sources and detection workflows aligned with the MITRE ATT&CK framework. * Assist with automated attack kill chain analysis and security event correlation. * Support cybersecurity operations teams with the platform API integration (Cloud), troubleshooting, performance monitoring, and system maintenance., We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for All! ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Debug a Kubernetes Operator](https://www.wearedevelopers.com/videos/487-debug-a-kubernetes-operator) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Add Location-based Searching to Site with ElasticSearch](https://www.wearedevelopers.com/videos/77-add-location-based-searching-to-site-with-elasticsearch) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)