Senior Security Engineer

Gordon Food Service
Wyoming, MI, United States
8 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Automation of Tests Cyber Security Information Systems Continuous Integration Data Normalization Database Queries Linux Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection and Prevention Python (Programming Language)
+18 more
Network Security Open Source Technology Platform as a Service (PAAS) Windows PowerShell Red Team (Cyber Security) Security Information and Event Management Virtualization Technology Data Ingestion Mitre Att&ck Malware Cyber Threat Analysis HybridCloud Infrastructure Automation Frameworks Information Technology Cybercrime Multiplatform Automation Anywhere Security Orchestration, Automation & Response

Job description

The Senior Cybersecurity Engineer is a core technical leader within our Security Operations (SecOps) team, responsible for designing, automating, and maintaining the organization’s enterprise security architecture. Operating in a high-impact, low-friction environment, this role directly drives threat hunting, detection engineering, security validation, and tool automation across enterprise, cloud, and hybrid environments. This role balances deep platform infrastructure operations with modern automation techniques (CI/CD, Infrastructure-as-Code, AI workflows) to maximize defensive coverage and empower SOC analyst operations.

What you will do:

Security Strategy and Leadership:

  • Provide strategic leadership in the development and execution of cybersecurity strategies, policies, and frameworks.
  • Collaborate with senior stakeholders to align cybersecurity initiatives with organizational goals and objectives.
  • Stay updated with emerging cybersecurity trends, threats, and technologies to provide expert guidance and recommendations.

Threat Hunting & Threat Intelligence:

  • Lead the SecOps threat hunting program across multi-platform operating systems, enterprise cloud environments, virtualized infrastructure, and network environments.Correlate open-source and proprietary threat intelligence (TTPs) into proactive, baseline, and reactive threat hunts.Maintain and expand automated hunt dashboards and threat hunting automation frameworks.

Security Architecture and Engineering:

  • Aid in designing, implementing, and maintaining secure network architectures and infrastructure.
  • Maintain log ingestion pipelines, custom parsers, data normalization models, feed integrations, and overall platform health of the SIEM/SOAR environment.
  • Collaborate with cross-functional teams to evaluate and select security technologies and solutions.

Incident & Operational Response:

  • Act as the Tier 2 technical escalation point and mentor for Security Analysts.Participate in critical Incident Response efforts, root-cause investigations, and the SecOps On-Call rotation.Conduct detailed investigations of security incidents, perform root cause analysis, and implement remediation measures.

Detection Engineering & Security Validation:

  • Design, build, and tune custom detections in vendor-neutral rule languages and native SIEM/SOAR/EDR logic to eliminate false positives while maintaining robust detection posture.
  • Execute automated and manual threat emulation/attack chains using open-source testing frameworks to continuously validate log ingestion, rule efficacy, and security controls.Support external Red Team engagements and remediate identified visibility and control gaps.Security Automation & Infrastructure-as-Code (IaC):
  • Build and manage Infrastructure-as-Code (IaC) configurations via version-controlled CI/CD pipelines for security workspaces and validation environments.
  • Write, maintain, and integrate custom automation scripts (e.g., Python, PowerShell) and SOAR playbooks to streamline analyst triage and system workflows.Assist in developing, tuning, and integrating modern AI agent platforms and operational workflows into core SecOps pipelines.

When you will work:

  • Monday to Friday, 8am to 5pm
  • Hybrid schedule, 4 days in office in Wyoming, MI or Atlanta, GA with 1 day remote

Requirements

  • Bachelor’s Degree in Computer Science, Information Systems, or a related field required.
  • Five to eight years previous related experience or an equivalent combination of education, training, and experience.
  • Professional certifications such as CISSP, CISM, GIAC, or CCSP are preferred.
  • Proficiency with engineering and administering Enterprise SIEM, SOAR, EDR, and NDR platforms.
  • Extensive knowledge of cybersecurity principles, technologies, and best practices.
  • Expertise with writing custom detection logic, complex queries, and log normalization.
  • Strong understanding of enterprise IT infrastructure: Windows, Linux, Enterprise Cloud (IaaS/PaaS), Identity & Access Management (IAM), and Enterprise Networking.
  • Experience writing automation scripts in Python, PowerShell, or Bash.Proficiency in security incident response, including forensic analysis, malware analysis, and threat intelligence.
  • Demonstrated experience with threat hunting frameworks (e.g., MITRE ATT&CK) and security validation tools.
  • Excellent leadership and communication skills, with the ability to effectively communicate complex technical concepts to stakeholders at all levels.
  • Proven ability to lead and mentor junior team members.
  • Must have good customer service and time management skills.
  • Ability to develop solutions to a variety of complex problems, and reference established precedents and policies.

About the company

Welcome to Gordon Food Service! We are excited that you are thinking about opportunities with us, and we have an amazing story to share. See below for a quick glance of who we are and the impact you could have on the food service industry. There’s a seat at our table for you…

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all