Remote job
Senior Security Engineer
Job details
About this role
Role overview A senior technical position on the security operations team, focused on detecting, investigating, and responding to threats spanning cloud, endpoint, identity, and network environments. The role combines hands-on incident response with scripting and automation work to strengthen day-to-day security monitoring. It suits someone who enjoys analytical detective work across diverse infrastructure, including Linux and Windows systems, and who can support urgent events outside normal hours.
Responsibilities
- Monitor and triage security alerts across cloud, identity, endpoint, and network environments. - Review logs and activity from AWS, GCP, Active Directory, Linux and Windows hosts, and security tooling. - Support incident response by collecting evidence, validating suspicious behavior, and documenting findings. - Write and refine scripts that automate repetitive security tasks, log analysis, enrichment, and reporting. - Contribute to assessments of IAM configurations, storage exposure, compute workloads, and network design. - Investigate authentication events, user behavior, privilege changes, and indicators of account compromise. - Partner with internal teams to understand systems, surface risks, and support remediation, compliance, and audit work. - Be available for after-hours response when urgent security events require investigation.
Requirements
- Three to five years in security operations, incident response, systems administration, cloud operations, or a comparable technical role. - Strong scripting ability in Python, Bash, or PowerShell, with a track record of solving operational or security problems through automation. - Working knowledge of cloud security concepts, services, logs, and IAM, including hands-on AWS experience. - Practical experience with SIEM platforms such as Splunk, Chronicle, Sentinel, or comparable tools. - Familiarity with Linux and Windows command-line usage, permissions, processes, and logs. - Working understanding of Active Directory, covering users, groups, authentication, and privilege changes. - Clear analytical, documentation, and communication skills.
Nice to have
- Hands-on GCP security experience, including IAM, Cloud Logging, Compute Engine, Cloud Storage, VPCs, and service accounts. - Exposure to containers, Kubernetes, or other cloud-native workloads. - Prior automation work specifically for security monitoring or response workflows.
Benefits and work setup
- Candidates should expect after-hours on-call participation when critical incidents occur. - The interview process includes a live, screen-shared practical exercise to demonstrate relevant technical skills. - Reasonable accommodations are available for candidates participating in the application and interview process.