Job Closed
This listing is no longer active.
Access. Answers. Advocacy. We're raising the standard of healthcare for everyone.
Senior Security Operations Engineer
Location
United States
Posted
108 days ago
Salary
$138.4K - $254.1K / year
Seniority
Senior
Job Description
Senior Security Operations Engineer
Included Health
• Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling. • Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data. • Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements. • Build and refine automated response playbooks and workflows that enrich, triage, and respond to DLP alerts, reducing manual effort and mean time to respond. • Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes, using DLP telemetry, EDR, SIEM, and identity signals. • Partner with Security Engineering, IT, Legal, Privacy, Compliance, and business stakeholders to design and enforce secure data-handling patterns and exception processes. • Contribute to broader incident response activities where data exposure or regulatory impact is a concern, including evidence handling and stakeholder communication. • Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners.
Job Requirements
- Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP.
- Direct, hands-on experience deploying, tuning, and operating DLP tools (endpoint, network, SaaS, and/or cloud) in a production environment.
- Experience implementing and operating Cloud Access Security Broker (CASB) or similar SaaS security controls
- Deep experience integrating DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel)
- Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale.
- Proven experience with Endpoint Detection and Response (EDR) platforms (e.g., CrowdStrike, SentinelOne) and using them alongside DLP to investigate and contain data-focused incidents.
- Strong experience with cloud data protection in AWS, including identifying and remediating misconfigurations, and leveraging native security services (e.g., GuardDuty, Security Hub) and CSPM tooling.
- Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types.
Benefits
- Remote-first culture
- 401(k) savings plan through Fidelity
- Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
- Full suite of Included Health telemedicine (e.g. behavioral health, urgent care, etc.) and health care navigation products and services offered at no cost for employees and dependents
- Generous Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
- 12 weeks of 100% Paid Parental leave
- Up to $25,000 Fertility and Family Building Benefit
- Compassionate Leave (paid leave for employees who experience a failed pregnancy, surrogacy, adoption or fertility treatment)
- 11 Holidays Paid with one Floating Paid Holiday
- Work-From-Home reimbursement to support team collaboration and effective home office work
- 24 hours of Paid Volunteer Time Off ("VTO") Per Year to Volunteer with Charitable Organizations
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Engineer III - Cyber Incident Response
CencoraCencora, formerly known as AmerisourceBergen, is a publicly-traded pharmaceutical service company with locations spanning the globe. As an employer, the company
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today! Job Details Position Summary The Engineer III, Cyber Incident Response, is a senior technical role within the Security Operations Center (SOC) responsible for leading complex incident investigations and supporting the continuous improvement of detection and response capabilities. This role provides advanced technical expertise in identifying, analyzing, containing, and remediating cyber threats. The Engineer III will act as a mentor to junior analysts, serve as an escalation point for critical incidents, and collaborate with global cyber defense teams to ensure timely and effective responses to advanced threats. Primary Duties and Responsibilities Lead the investigation and resolution of complex security incidents, including advanced persistent threats, ransomware, phishing campaigns, and insider activities. Perform forensic analysis across endpoints, networks, and cloud environments to identify root causes and scope of compromise. Develop and enhance incident response playbooks, runbooks, and detection use cases. Collaborate with threat intelligence, vulnerability management, and countermeasures teams to strengthen defenses. Escalate high-severity incidents to senior leadership and provide clear, actionable reporting. Act as a technical escalation point for Engineer I/II analysts during incident investigations. Contribute to red team and purple team exercises to validate and improve response capabilities. Participate in after-action reviews and lessons-learned sessions to improve SOC processes. Mentor and train junior engineers on incident response best practices and investigative techniques. Education and Qualifications
Senior Manager, Security Incident Response Team
GitLabBuild software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.
• Serve as trusted advisor as part of the security division’s leadership team, actively shaping the program direction. • Build and mature incident response runbooks, procedures, and capabilities. • Provide leadership to multiple security operations team shifts that will sometimes require you to work on nights or weekends. • Develop a culture of incident response excellence through a focus on investigation depth and accuracy. • Lead cross-functional collaboration between peer SecOps teams, security departments, and extended support teams such as Legal, Customer Support, and Infrastructure. • Foster a defense first mindset through actionable incident retrospective mitigations to close defense gaps, making GitLab a hard target for attackers. • Lead a team of expert security engineers with experience in security automation, deep dive forensics and incident response, AI detection and response capabilities, and GitLab the product. • Support response readiness and expertise about new GitLab corporate and product capabilities and features. • Drive insights from the alerts, investigations, and incidents handled by SIRT to improve the security posture of GitLab.
Senior Cybersecurity Operations Consultant
Trility ConsultingStart delivering technology solutions that simplify, automate, and secure your business.
• Deploy, configure, and integrate security tooling across a number of cybersecurity sub-workstreams • Execute configuration updates to redirect logs, telemetry, and security data feeds to the new MSSP • Coordinate with the MSP on endpoint agent deployments and related technical dependencies • Validate integrations and ensure consistent security visibility across on-prem and cloud environments (outside the CMMC boundary) • Support development of operational SOPs, playbooks, and integration documentationIdentify integration risks and recommend practical mitigation strategies based on hands-on experience • Provide technical input during MSSP-related decision points, including tooling compatibility and architecture considerations • Collaborate closely with Trility team members, client IT stakeholders, MSP, and MSSP partners to ensure smooth transition and stabilization
• Analyze third party records in the vendor risk management system and assist with data entry and data maintenance • Meet with internal stakeholders to complete vendor intake questionnaires • Data analysis and maintenance of ticketing system • Provide general support for Governance, Risk & Compliance functions




