25 days ago
Responsibilities
- Triage, investigate, and respond to security alerts across endpoints, cloud infrastructure, and network telemetry.
- Automate repetitive workflows and use AI to improve the speed, scale, and effectiveness of security operations.
- Execute containment and remediation actions for confirmed incidents while following and improving runbooks.
- Tune and maintain SIEM and EDR detections to reduce false positives, improve signal quality, and close coverage gaps.
- Apply threat intelligence, including IOCs and TTPs, to investigations and ongoing monitoring.
- Participate in the on-call rotation and contribute actionable post-incident documentation.
- Drive post-incident reviews, operational improvements, and stronger team readiness.
Requirements
- 5+ years of experience in security operations, detection and response, or a related security engineering role.
- Deep experience leading investigations and response efforts across endpoints, cloud environments, and network telemetry.
- Ability to independently manage complex incidents from triage through containment, eradication, and recovery.
- Advanced hands-on experience building and tuning SIEM and EDR detections, improving signal quality, and reducing false positives.
- Experience applying threat intelligence, including IOCs, TTPs, and adversary tradecraft, to investigations, threat hunting, and monitoring improvements.
- Ability to automate repetitive security workflows and thoughtfully apply AI to investigations and response.
- Experience participating in on-call rotations and documenting incidents clearly and thoroughly.
- Experience mentoring teammates and influencing security operations processes, tooling, and standards.