Staff Security Operations Engineer
Job description
About the role
This position focuses on enhancing our security posture by building and operating security tooling. You will be instrumental in developing and maintaining systems that support security investigations and data management. Your work will directly contribute to modernizing our security operations. In this capacity, you will own the design and execution of security infrastructure that underpins our defense strategy. You will partner closely with engineering and product teams to ensure security is integrated into the fabric of our systems. The role demands a proactive mindset to identify gaps and implement robust controls before threats materialize. You will act as a subject matter expert, guiding the organization on security best practices and standards. Your contributions will be measurable through improved detection capabilities and streamlined incident response.
Key facts
What you'll do
- Architect and deploy security infrastructure components to support scalable data ingestion and analysis.
- Engineer solutions that streamline the investigation of security incidents, reducing mean time to resolution.
- Construct and manage pipelines for telemetry data routing, enrichment, and long-term archival storage.
- Facilitate the transition of security datasets into cloud-based platforms to improve accessibility and scalability.
- Script and automate repetitive security workflows to increase operational efficiency and reduce manual error.
- Configure and optimize log collection and processing frameworks to ensure data fidelity and completeness.
- Collaborate with development teams to implement security controls within application design lifecycles.
- Monitor system performance and security metrics to identify anomalies and potential bottlenecks in the infrastructure.
- Maintain documentation for security architectures and operational procedures to ensure clarity and continuity.
- Evaluate emerging technologies and tools to enhance the capabilities of the existing security operations stack.
Requirements
- Possess a minimum of 5 years of cumulative experience in security operations, threat hunting, or a closely related discipline.
- Hold a Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline, or demonstrate equivalent practical experience through a proven track record.
- Demonstrate hands-on expertise with major cloud platforms, specifically Amazon Web Services, Microsoft Azure, or Google Cloud, including core networking and compute services.
- Show advanced familiarity with security information and event management (SIEM) systems, including architecture, deployment, and optimization.
- Exhibit proficiency with data routing, transformation, and normalization tools used to process high-volume telemetry streams.
- Have a history of working with security operations tools such as Splunk, Elastic, or similar platforms for data analysis and visualization.
- Understand endpoint security concepts and have experience with agents such as Crowdstrike or similar EDR solutions.
- Possess knowledge of network security appliances and logging formats associated with vendors like Palo Alto Networks.
- Have experience with cloud-native security and observability platforms such as Wiz or comparable infrastructure.
- Demonstrate experience using advanced analytics platforms like Exabeam or other User and Entity Behavior Analytics (UEBA) tools.
- Show ability to work with messaging and streaming platforms such as Confluent or Apache Kafka to manage data flow.
- Exhibit strong problem-solving skills and the ability to troubleshoot complex issues in distributed environments.
- Communicate effectively, both in writing and verbally, to convey technical concepts to diverse stakeholders.
- Operate with a high degree of integrity and discretion when handling sensitive security data and incidents.
- Thrive in a fast-paced environment, managing multiple priorities and adapting to shifting requirements.
Nice to have
- Experience within the AI Observability or security telemetry domains providing context for specific data models and challenges.
- Familiarity with the Cribl platform or log processing frameworks that handle high-velocity data streams.
- Knowledge of compliance frameworks and regulatory requirements relevant to security operations in cloud environments.
- Understanding of automation frameworks and Infrastructure as Code (IaC) principles for security configurations.
- Background in developing scripts or tools using languages such as Python or Bash to extend security capabilities.
- Experience with visualization tools and dashboards used to communicate security posture and trends.
Practical notes
- Visa sponsorship is not available for this role.
- Occasional travel may be required.
- We offer competitive compensation and benefits.
- To apply, please submit your resume and cover letter through our careers portal.