Senior Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Strategic Data Systems is seeking a Senior Security Engineer to join a Security Operations team responsible for investigating security events and responding to complex cybersecurity incidents. This is a senior individual-contributor position with no direct reports. The successful candidate will bring substantial hands-on Security Operations and incident-response experience and will serve as an escalation point when security events require deeper technical investigation, rapid decision-making, and coordinated response. This is not primarily a governance, compliance, architecture, vulnerability-management, or security-management position. Candidates must have demonstrated experience personally investigating security events and participating directly in containment, eradication, and recovery activities. The Senior Security Engineer will work across endpoint, identity, cloud, email, network, and other security domains to determine what happened, assess impact, contain threats, eliminate malicious activity, restore affected environments, and improve defenses based on lessons learned. Key Responsibilities Investigate complex security alerts, events, and suspected security incidents. Determine incident scope, severity, affected assets, attack path, and appropriate response. Lead or materially contribute to containment, eradication, and recovery activities. Serve as an escalation point for complex Security Operations investigations. Analyze telemetry from endpoint, identity, cloud, email, network, and other security controls. Correlate information across multiple security tools and data sources to develop an accurate incident timeline. Work with infrastructure, cloud, application, networking, identity, and other technology teams during incident response. Develop, maintain, and improve Security Operations playbooks and runbooks. Provide actionable feedback to detection teams regarding alert quality, enrichment, tuning, and automated response. Identify gaps in security logging and telemetry and collaborate with appropriate teams to improve visibility. Contribute to post-incident reviews and translate lessons learned into operational improvements. Mentor junior Security Operations professionals and help improve their investigation and response capabilities. Participate in tabletop exercises, security audits, and other operational-readiness activities as appropriate.
Requirements
Communicate incident status, technical findings, business impact, and recommended actions clearly to both technical and non-technical stakeholders. Required Qualifications 5 10+ years of relevant cybersecurity experience with significant hands-on Security Operations responsibilities. Strong experience performing security investigations and incident response. Demonstrated experience investigating security alerts and determining whether activity represents a legitimate threat. Hands-on experience supporting or leading: Containment Eradication Recovery Post-incident analysis Experience working with multiple Security Operations technologies, which may include: SIEM platforms SOAR platforms Endpoint Detection and Response (EDR) Email security gateways Firewalls and network-security controls Identity and authentication telemetry Experience developing, maintaining, or improving incident-response playbooks and operational runbooks. Strong analytical and critical-thinking skills. Ability to operate effectively during high-pressure security incidents. Strong written and verbal communication skills. Ability to explain complex cybersecurity events to both technical and non-technical audiences. Demonstrated technical leadership as a senior individual contributor. Experience mentoring or developing less-experienced Security Operations professionals. Preferred Qualifications Detection engineering experience. Experience creating or tuning SIEM rules, alerts, or detection logic. Experience reducing false positives and improving alert fidelity. Familiarity with the MITRE ATT&CK framework. Experience mapping security behavior, detections, or incidents to MITRE ATT&CK tactics and techniques. Security Operations experience in AWS, Azure, or Google Cloud Platform environments. Familiarity with Google Security Operations. Experience participating in cybersecurity tabletop exercises. Experience supporting security audits or operational-readiness reviews. Experience improving security logging, telemetry, enrichment, and automated-response capabilities.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks