Job Closed

This listing is no longer active.

Jobgether logo
Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Senior Security Operations Engineer, Detection & Response

Location

United States

Posted

74 days ago

Salary

$194K - $235K / year

Seniority

Senior

Job Description

Senior Security Operations Engineer, Detection & Response

Jobgether

Role Description This role offers a high-impact opportunity to strengthen and maintain an organization’s security posture across global cloud environments, endpoints, and SaaS platforms. You will lead threat detection, incident response, and continuous monitoring initiatives while serving as a subject matter expert in security operations. The position requires collaboration across multiple teams to improve detection coverage, automate workflows, and enhance overall security resilience. You will actively participate in 24/7 on-call rotations, drive the development of detection rules and runbooks, and mentor junior engineers. Ideal candidates thrive in fast-paced, high-pressure environments, enjoy solving complex security challenges, and are passionate about automation and process improvement. This is a role where your contributions directly protect organizational assets and empower teams to respond efficiently to threats. - Lead investigations and coordinate response efforts for security incidents across global infrastructure, minimizing impact and recovery time - Participate in 24/7 on-call rotations, managing active security events and incidents - Develop and maintain detection rules, runbooks, and response procedures aligned with the organization’s threat model - Triage and investigate alerts from tools such as EDR, CSPM, and cloud security platforms, reducing false positives and improving detection accuracy - Automate alert triage workflows and enhance mean time to detection and response using tooling and AI enrichment - Collaborate with Infrastructure, Application Security, and Enterprise Security teams to implement secure-by-design principles - Conduct tabletop exercises and game days to test detection, response, recovery, and remediation capabilities - Mentor junior security engineers and cross-functional team members on incident handling best practices Qualifications - 8+ years of professional experience in security, including at least 4 years in security operations, incident response, threat hunting, or threat detection - Demonstrated experience leading security incident investigations and coordinating cross-team response efforts - Hands-on experience with security tooling (SIEM, SOAR, EDR, CSPM) with focus on detection engineering and alert tuning - Experience with cloud-native production environments and multi-cloud platforms (AWS, Azure, GCP) - Proficiency in automation tools and scripting (Python, Terraform) and leveraging AI for workflow improvements - Strong understanding of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK - Excellent communication skills for both technical and non-technical stakeholders - Ability to work effectively in a distributed, remote environment and manage high-pressure situations calmly Requirements - Experience with tools such as Wiz, Crowdstrike, Jamf, Okta, and Google Workspace - Knowledge of Kubernetes-based environments and SaaS integrations - Relevant certifications (GCIH, GCIA, GCFA, or equivalent) - Experience with eDiscovery, digital forensics, or bug bounty management - Contributions to open source security tooling or detection content Benefits - Competitive salary range: $175,000 – $212,000 USD (select locations: $194,000 – $235,000 USD) - Equity or comparable benefits depending on legal and geographic limitations - Unlimited vacation policy - 401(k) plan with 3% guaranteed contribution - Comprehensive healthcare coverage - Paid parental leave - Wellness and home office stipends - Professional development opportunities and a collaborative, inclusive work environment

Job Requirements

  • 8+ years of professional experience in security, including at least 4 years in security operations, incident response, threat hunting, or threat detection
  • Demonstrated experience leading security incident investigations and coordinating cross-team response efforts
  • Hands-on experience with security tooling (SIEM, SOAR, EDR, CSPM) with focus on detection engineering and alert tuning
  • Experience with cloud-native production environments and multi-cloud platforms (AWS, Azure, GCP)
  • Proficiency in automation tools and scripting (Python, Terraform) and leveraging AI for workflow improvements
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
  • Excellent communication skills for both technical and non-technical stakeholders
  • Ability to work effectively in a distributed, remote environment and manage high-pressure situations calmly
  • Experience with tools such as Wiz, Crowdstrike, Jamf, Okta, and Google Workspace
  • Knowledge of Kubernetes-based environments and SaaS integrations
  • Relevant certifications (GCIH, GCIA, GCFA, or equivalent)
  • Experience with eDiscovery, digital forensics, or bug bounty management
  • Contributions to open source security tooling or detection content

Benefits

  • Competitive salary range: $175,000 – $212,000 USD (select locations: $194,000 – $235,000 USD)
  • Equity or comparable benefits depending on legal and geographic limitations
  • Unlimited vacation policy
  • 401(k) plan with 3% guaranteed contribution
  • Comprehensive healthcare coverage
  • Paid parental leave
  • Wellness and home office stipends
  • Professional development opportunities and a collaborative, inclusive work environment

Related Categories

Related Job Pages

More Security Engineer Jobs

Falconwood, Incorporated logo

Information System Security Officer, ISSO

Falconwood, Incorporated

A Certified Veteran-Owned Women-Owned Business

Full TimeRemoteTeam 201-500Since 2002H1B No Sponsor

• Plan, implement, and maintain all phases of the Risk Management Framework (RMF) for assigned systems • Assist in the development and maintenance of security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms) • Work closely with the Information System Security Manager (ISSM) in executing their duties and responsibilities • Collaborate with system owners, stakeholders, and other security professionals • Provide security guidance and training to system users • Prepare and present security briefings to management • Ensure compliance with all Department of Defense (DoD) and Department of Navy (DoN) cybersecurity policies • Ensure relevant policy and procedural documentation is current and accessible to properly authorized individuals

United States
$103K - $108K / year
Job Closed
ENSEK logo

Senior Cyber Security Engineer

ENSEK

The award-winning SaaS platform behind leading energy suppliers.

Full TimeRemoteTeam 201-500Since 2010H1B No Sponsor

• Collaborate with engineering and platform teams to design secure solutions, perform threat modelling and review designs for cloud, container and service‑based architectures. • Define and enforce secure configurations, network segmentation, identity and access controls for public cloud (primarily AWS). • Implement secure coding practices, vulnerability management, secrets management and runtime protections for services and CI/CD pipelines. • Build and maintain monitoring, logging and alerting for security events; lead incident response and post‑incident reviews to drive remediation and lessons learned. • Support ENSEK’s 24/7 Incident Management processes to ensure security and stability for clients. • Automate security checks, policy enforcement and remediation using IaC, CI/CD integrations and custom tooling where appropriate. • Work with Risk, Legal and InfoSec to embed controls that support regulatory, privacy and contractual requirements across new territories.

United Kingdom
Job Closed
BeyondTrust logo

Identity Security Sales Specialist

BeyondTrust

Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• Own and execute a strategic territory plan focused on net-new commercial acquisition. • Drive full-cycle sales motions from prospecting through close within your assigned accounts. • Operate as an overlay specialist across aligned Commercial Account Executives, identifying and advancing Entitle opportunities within their territories. • Build strong internal partnerships with Commercial AEs to create joint account plans and pipeline acceleration strategies. • Generate pipeline through proactive prospecting, executive outreach, partner collaboration, and targeted account strategies. • Lead complex, multi-threaded sales engagements within commercial organizations. • Engage C-level and senior security stakeholders (CISO, CIO, VP Security, Cloud Security leaders) in outcome-driven security conversations. • Deliver consultative discovery centered on privilege risk reduction, identity governance, and cloud security posture. • Coordinate cross-functional resources (Sales Engineering, Channel, Marketing, Professional Services, Customer Success) to accelerate deal progression and ensure successful outcomes. • Develop compelling business cases and ROI-driven proposals aligned to customer security initiatives. • Accurately forecast and manage pipeline using Salesforce, maintaining disciplined deal inspection and territory hygiene. • Consistently meet and exceed quarterly and annual revenue targets across both direct and overlay motions. • Represent the company at industry events, executive briefings, and partner engagements.

United States
Job Closed
Lakeview Loan Servicing logo

Identity and Access Management Engineer

Lakeview Loan Servicing

Lakeview is an Equal Employment Opportunity employer. All aspects of consideration for employment and employment with the Company are governed on the basis of merit, competence and qualifications without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, or any other category protected by federal, state, or local law.

Full TimeRemoteTeam 501-1,000

Overview The Identity and Access Management Engineer will lead technical initiatives for IAM solutions focused on SailPoint Identity Security Cloud. Oversee design, automation, operation, integrations, troubleshooting, and mentoring to enhance lifecycle efficiency, reliability, and security. This role can be remote anywhere in the country. The salary range for this role is $150,000 to $175,000, plus an annual bonus. However Lakeview considers several factors when extending an offer, including but not limited to, the roles and associated responsibilities, a candidate's work experience, education/training, location and key skills. Responsibilities - Deliver and lead IAM/IGA projects and integrations (SailPoint ISC), supporting access control, provisioning, deprovisioning, reviews, and service account management. - Build automation tools (workflows, scripts, connectors) to reduce manual tasks and scale solutions. - Manage identities, groups, roles, policies, and permissions in major cloud providers (Azure AD/Entra, AWS IAM/IAM Identity Center, Google Cloud IAM). - Implement role‑based access control (RBAC), resource policies, and least‑privilege patterns in cloud environments. - Troubleshoot production issues, conduct root cause analysis, and implement sustainable fixes. - Collaborate with IT, security, application, and business teams to align IAM with enterprise goals and ensure integration. - Operate and monitor IAM systems, escalate and resolve critical incidents, maintain high availability. - Support access reviews, entitlement certifications, SoD controls, and attestation processes. - Mentor junior engineers, set best practices, and foster team collaboration. - Document architecture, SOPs, and knowledge resources for ongoing improvement. - Research and recommend new IAM technologies. Qualifications - Undergraduate degree in computer science, information systems, cybersecurity, or related field preferred. - 3 - 4+ years of hands-on experience with SailPoint Identity Security Cloud in enterprise settings. - Proficient with Active Directory, Azure AD, Workday integrations, and SailPoint workflows. - Strong grasp of IAM fundamentals: provisioning, RBAC, access reviews, least privilege. - Skilled in scripting (PowerShell), automation platforms (Azure Automation/AWS Lambda preferred). - Familiar with protocols: SAML, OAuth, OpenID Connect, SCIM, LDAP. - Experience with REST APIs, system authentication, and cloud/hybrid environments. - Excellent communication; proven leadership in technical projects. - Strong problem-solving and analytical skills with attention to detail. - Ability to work independently and collaboratively in a fast-paced environment. - Self-starter with strong interpersonal, written and verbal communication skills and the ability to interact with technical and non-technical stakeholders. Certifications, Licenses, and/or Registration - SailPoint and Microsoft Certifications preferred Location & Compensation - The annual salary for this role is $150-175K depending on the individual’s experience - Role can be 100% fully remote depending on geographic location Physical Demands and Work Environment The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to sit and use hands to handle, touch or feel objects, tools, or controls. The employee frequently is required to talk and hear. The noise level in the work environment is usually moderate. The employee is occasionally required to stand; walk; reach with hands and arms. The employee is rarely required to stoop, kneel, crouch, or crawl. The employee must regularly lift and/or move up to 10 pounds. Specific vision abilities required by this job include close vision, color vision, and the ability to adjust focus. EEOC Lakeview is an Equal Employment Opportunity employer. All aspects of consideration for employment and employment with the Company are governed on the basis of merit, competence and qualifications without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, or any other category protected by federal, state, or local law.

United States
$150K - $175K / year
Job Closed