> Markdown version of [/jobs/ext/596567-senior-security-operations-secops-engineer](https://www.wearedevelopers.com/jobs/ext/596567-senior-security-operations-secops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Operations (SecOps) Engineer - **Company:** Samsung - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $150,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, System Configuration, Linux, Digital Assets, Information Security Management, Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Windows Servers, Windows PowerShell, Ansible, Zero Trust Network Access, Security Information and Event Management, In-Plane Switching (IPS), QRadar, Firewalls (Computer Science), Information Technology, Nessus, Malware Detection, Terraform, Splunk, Qualys, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://www.juju.com/job/00000000g9j1az ## About the Role + 8+ years in enterprise information security with a proven track record of delivering security-operations projects (platform migrations, automation initiatives). + Hands-on knowledge of firewalls, IDS/IPS, anti-malware, VPN, DLP, SIEM (Splunk, QRadar), vulnerability scanners (Nessus/Qualys), and cloud security controls (AWS GuardDuty, Azure Sentinel). + Designed SOAR playbooks; scripted in Python/PowerShell; implemented IaC for security controls. + Proficient in the implementation, configuration, & administration of Windows servers, Linux, VM, and Container systems and hardening. + Demonstrated ability to manage scope, schedule, risk, and stakeholder communication for security programs. + Translate legal/regulatory mandates (NIST, ISO 27001) into actionable security controls and governance artifacts. + The demonstrated ability to work effectively in a collaborative team environment or as an individual contributor. + Experience managing information security controls, specifically monitoring, troubleshooting, maintaining, and modernization of mission critical networks and information systems. + Must be eligible to work in the US for any employer without restrictions. + Must be willing and able to work onsite in San Jose, CA. Preferred Qualifications: + Experience with project management, vendor management, and policy development. + Hands-on experience with Netskope (NG-SWG, CASB, DLP, ZTNA, RBI, Cloud Firewall) or similar. + Demonstrated ability in deploying, configuring, and operationalizing Darktrace threat detection platform. + Prior experience in leading or being part of a security incident response team and proven experience in using SIEM and network DLP. + Ability to work in a small, collaborative team environment and as an individual contributor. + Bachelor's Degree in relevant field is strongly preferred. ## Description Samsung SDS America (SDSA) serves as the U.S. technology and innovation hub for Samsung's global enterprise solutions, delivering secure, scalable, and high-performance IT services that support some of the world's most complex business environments. As SDSA continues to expand its cloud, mobility, analytics, and cybersecurity capabilities, maintaining a resilient security operations foundation is essential to protecting the company's digital assets and ensuring uninterrupted service delivery. This need for operational rigor and real-time threat defense creates the environment in which the Security Operations Engineer plays a critical role. The Senior Security Operations Engineer leads project-focused initiatives that advance SDSA's security posture, rather than handling routine ticket resolution. The engineer drives end-to-end delivery of security-control automation, threat-management platforms, and governance frameworks while maintaining day-to-day operational integrity. Core responsibilities span strategic program leadership, real-time threat detection & response, and security-control optimization. Responsibilities: + Lead Security-Operations Projects - Own the full lifecycle of multi-disciplinary security projects (e.g., SIEM migration, DLP automation, Secure-Web-Gateway hardening), from requirements gathering and stakeholder alignment to design, implementation, testing, and post-deployment review. + Architect & Enforce Control Governance - Develop and maintain detailed runbooks, playbooks, and SOPs that codify security-control configuration, change-control processes, and compliance checkpoints across firewalls, IDS/IPS, anti-malware, and data-loss-prevention solutions. + Direct Real-Time Threat Management - Oversee the configuration, tuning, and integration of SIEM, DLP, and Secure-Web-Gateway telemetry; design correlation rules that reduce false positives by > 30 % and trigger automated containment workflows via SOAR platforms. + Participate in Incident Response Programs - Play a key SME role to identify and drive incident response resolutions. + Collaborate with Security Engineering & Architecture Teams - Partner with engineers to embed vulnerability-management findings into patch-prioritization pipelines; advise architects on control selection that satisfies regulatory requirements (e.g., GDPR, CCPA, NIST 800-53). + Drive Continuous Improvement - Lead change-management initiatives that modernize legacy security tools, introduce security orchestration (e.g., Ansible, Terraform), and enforce configuration-as-code standards. + Vendor & Policy Management - Assist GRC in technology review of 3rd party and partners ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)