Security Operations Engineer
Job description
About the role
Everpure seeks a Security Operations Engineer to redefine enterprise defense. This position operates within the Global Information Security Office, driving risk-based outcomes across cloud, endpoint, and SaaS ecosystems. The role demands innovative automation and partnership with technology peers to secure critical infrastructure. The position reports to the Senior Security Operations Manager. Collaborators include Cloud Platform, Network Engineering, and DevOps. The focus is on architecting controls rather than performing manual checks. Success is measured by reduced attack surface and demonstrable risk mitigation. You will own the vulnerability and asset lifecycle. Responsibilities include driving exploitability-led remediation and utilizing EPSS for prioritization. The goal is to shift reporting from volume to risk, ensuring SLAs tangibly lower organizational exposure. Asset intelligence guides the closure of critical findings.
You will engineer Zero Trust and connectivity operations. This involves managing the Zscaler platform, including ZIA and ZPA. You will handle complex strategies for SSL/TLS inspection and policy enforcement. The aim is to provide secure access without compromising visibility into encrypted flows. Eliminating credential and secret risk is a core duty. You will act as the primary architect for secrets detection within CI/CD pipelines. Collaboration with DevOps will automate the discovery and remediation of exposed credentials. Security is embedded leftward, from code commit to cloud deployment.
Architecting detection, deception, and automation is essential. You will build advanced queries in Splunk and deploy deception strategies aligned with MITRE ATT&CK. Python or SOAR workflows will automate triage, converting raw data into high-fidelity alerts. This automation reduces noise and accelerates response. Validating and simulating defenses is a required function. You will execute adversary simulations and controls validation, such as Atomic Red Team. The objective is to confirm detection efficacy and provide risk-rated findings to technical leaders. Testing ensures readiness before real adversaries strike.
Translating risk for stakeholders is a critical communication duty. You will pivot from deep-packet inspection details to delivering Fix Impact Reports for executives. Quantification of threat reduction justifies security investments. Business leaders receive clear insight into risk reduction. The candidate brings security engineering and vulnerability mastery. Experience includes asset discovery and secrets detection using tools like runZero, TruffleHog, or GitLeaks. Enterprise environments form the backdrop for this hands-on role.
Zero Trust and cloud specialization is mandatory. Technical depth in Zscaler ZIA/ZPA configuration is required, including SSL inspection design and policy management. Experience with AWS, GCP, or Azure is necessary for securing major platforms. Analytical automation and DevSecOps capabilities are mandatory. Proficiency in Splunk detection engineering and scripting in Python, PowerShell, or Bash is required. Integration of secrets scanning and automated remediation into CI/CD pipelines is expected. Offensive security and strategic communication are needed. Practical experience with threat emulation and deception mapped to MITRE ATT&CK is essential. The ability to partner with engineering teams ensures effective remediation prioritization. Translating technical risk into business language is a core competency.
This is a full-time position based in Santa Clara, California, or Lehi, Utah. Compliance with company location policies is required unless on approved leave.
What you'll do
- Drive the vulnerability and asset lifecycle from discovery to closure while leveraging EPSS for exploitability-led remediation.
- Engineer Zero Trust and connectivity operations by managing the Zscaler platform, including ZIA and ZPA for secure access.
- Handle complex strategies for SSL/TLS inspection and policy enforcement to maintain visibility within encrypted flows.
- Act as the primary architect for secrets detection within CI/CD pipelines to eliminate credential and secret risk.
- Collaborate with DevOps to automate the discovery and remediation of exposed credentials, embedding security leftward.
- Build advanced queries in Splunk and deploy deception strategies aligned with MITRE ATT&CK to strengthen detection capabilities.
- Create Python or SOAR workflows that automate triage, converting raw data into high-fidelity alerts and reducing noise.
- Execute adversary simulations and controls validation, such as Atomic Red Team, to confirm detection efficacy.
- Provide risk-rated findings to technical leaders and deliver Fix Impact Reports that translate deep-packet inspection details for executives.
- Quantify threat reduction to justify security investments and offer clear insight into risk reduction for business stakeholders.
- Utilize tools like runZero, TruffleHog, or GitLeaks for asset discovery and secrets detection within enterprise environments.
- Maintain technical depth in Zscaler ZIA/ZPA configuration, including SSL inspection design and policy management for cloud security.
- Demonstrate proficiency in Splunk detection engineering and scripting in Python, PowerShell, or Bash to support analytical automation.
- Integrate secrets scanning and automated remediation into CI/CD pipelines as part of DevSecOps practices.
- Apply offensive security experience with threat emulation mapped to MITRE ATT&CK to validate defenses.
- Partner with engineering teams to ensure effective remediation prioritization based on practical risk.
- Translate technical risk into business language through Fix Impact Reports and executive communications.
Requirements
- The candidate brings security engineering and vulnerability mastery.
- Experience includes asset discovery and secrets detection using tools like runZero, TruffleHog, or GitLeaks.
- Enterprise environments form the backdrop for this hands-on role.
- Zero Trust and cloud specialization is mandatory.
- Technical depth in Zscaler ZIA/ZPA configuration is required, including SSL inspection design and policy management.
- Experience with AWS, GCP, or Azure is necessary for securing major platforms.
- Analytical automation and DevSecOps capabilities are mandatory.
- Proficiency in Splunk detection engineering and scripting in Python, PowerShell, or Bash is required.
- Integration of secrets scanning and automated remediation into CI/CD pipelines is expected.
- Practical experience with threat emulation and deception mapped to MITRE ATT&CK is essential.
- The ability to partner with engineering teams ensures effective remediation prioritization.
- Translating technical risk into business language is a core competency.
- This is a full-time position based in Santa Clara, California, or Lehi, Utah.
- Compliance with company location policies is required unless on approved leave.