> Markdown version of [/jobs/ext/2717573-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2717573-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Vsg Business Solutions - **Location:** Blue Ash, OH, United States - **Experience:** Expert - **Salary:** $145,600.0 - $159,952.0 - **Contract:** Temporary to permanent - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Data Systems, Intrusion Detection and Prevention, Network Security, Security Information and Event Management, Data Logging, Google Cloud, Mitre Att&ck, Firewalls (Computer Science) - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/jobad/use9ba5fda34b436aee5ffe63d07134c19 ## About the Role Communicate incident status, technical findings, business impact, and recommended actions clearly to both technical and non-technical stakeholders. Required Qualifications 5 10+ years of relevant cybersecurity experience with significant hands-on Security Operations responsibilities. Strong experience performing security investigations and incident response. Demonstrated experience investigating security alerts and determining whether activity represents a legitimate threat. Hands-on experience supporting or leading: Containment Eradication Recovery Post-incident analysis Experience working with multiple Security Operations technologies, which may include: SIEM platforms SOAR platforms Endpoint Detection and Response (EDR) Email security gateways Firewalls and network-security controls Identity and authentication telemetry Experience developing, maintaining, or improving incident-response playbooks and operational runbooks. Strong analytical and critical-thinking skills. Ability to operate effectively during high-pressure security incidents. Strong written and verbal communication skills. Ability to explain complex cybersecurity events to both technical and non-technical audiences. Demonstrated technical leadership as a senior individual contributor. Experience mentoring or developing less-experienced Security Operations professionals. Preferred Qualifications Detection engineering experience. Experience creating or tuning SIEM rules, alerts, or detection logic. Experience reducing false positives and improving alert fidelity. Familiarity with the MITRE ATT&CK framework. Experience mapping security behavior, detections, or incidents to MITRE ATT&CK tactics and techniques. Security Operations experience in AWS, Azure, or Google Cloud Platform environments. Familiarity with Google Security Operations. Experience participating in cybersecurity tabletop exercises. Experience supporting security audits or operational-readiness reviews. Experience improving security logging, telemetry, enrichment, and automated-response capabilities. ## Description Strategic Data Systems is seeking a Senior Security Engineer to join a Security Operations team responsible for investigating security events and responding to complex cybersecurity incidents. This is a senior individual-contributor position with no direct reports. The successful candidate will bring substantial hands-on Security Operations and incident-response experience and will serve as an escalation point when security events require deeper technical investigation, rapid decision-making, and coordinated response. This is not primarily a governance, compliance, architecture, vulnerability-management, or security-management position. Candidates must have demonstrated experience personally investigating security events and participating directly in containment, eradication, and recovery activities. The Senior Security Engineer will work across endpoint, identity, cloud, email, network, and other security domains to determine what happened, assess impact, contain threats, eliminate malicious activity, restore affected environments, and improve defenses based on lessons learned. Key Responsibilities Investigate complex security alerts, events, and suspected security incidents. Determine incident scope, severity, affected assets, attack path, and appropriate response. Lead or materially contribute to containment, eradication, and recovery activities. Serve as an escalation point for complex Security Operations investigations. Analyze telemetry from endpoint, identity, cloud, email, network, and other security controls. Correlate information across multiple security tools and data sources to develop an accurate incident timeline. Work with infrastructure, cloud, application, networking, identity, and other technology teams during incident response. Develop, maintain, and improve Security Operations playbooks and runbooks. Provide actionable feedback to detection teams regarding alert quality, enrichment, tuning, and automated response. Identify gaps in security logging and telemetry and collaborate with appropriate teams to improve visibility. Contribute to post-incident reviews and translate lessons learned into operational improvements. Mentor junior Security Operations professionals and help improve their investigation and response capabilities. Participate in tabletop exercises, security audits, and other operational-readiness activities as appropriate. ## Related Videos - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Data Mesh as the end of the Datalake as we know it](https://www.wearedevelopers.com/videos/156-the-data-mesh-as-the-end-of-the-datalake-as-we-know-it) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)