Remote job
Senior Security Engineer
Job details
About this role
Role overview
A senior security engineer is needed to monitor, investigate, and respond to security activity across cloud, identity, endpoint, and Linux-based environments. The role blends hands-on detection and response work with scripting and automation, requiring practical AWS experience and comfort operating across multiple platforms. It suits someone who thrives in a fast-moving setting where strong analytical instincts and cross-platform fluency matter.
Responsibilities
- Triage and investigate security alerts spanning cloud, identity, endpoint, and network telemetry - Review activity from AWS, GCP, Active Directory, Linux, Windows hosts, and security tooling to validate suspicious behavior - Support incident response by gathering evidence, scoping impact, and documenting findings clearly for handoff or audit - Develop scripts in Python, Bash, or PowerShell to automate repetitive analysis, enrichment, and reporting workflows - Contribute to security reviews of IAM configurations, storage exposure, compute workloads, and network design - Analyze authentication activity, privilege escalations, and behavior patterns indicative of compromise - Partner with engineering and operations teams to surface risks and support remediation, compliance, and audit efforts - Participate in after-hours on-call response when urgent security events arise
Requirements
- 3-5 years in security operations, incident response, systems administration, cloud operations, or a comparable technical role - Practical grasp of cloud security concepts, services, log sources, and shared-responsibility IAM models - Strong scripting in Python, Bash, or PowerShell applied to operational or security problems - Hands-on experience with SIEM platforms such as Splunk, Chronicle, Sentinel, or comparable tooling - Working knowledge of Linux and Windows, including command-line usage, permissions, processes, and log locations - Foundational understanding of Active Directory, including users, groups, authentication flows, and privilege changes - Ability to read and interpret logs from cloud platforms, operating systems, and security tools - Familiarity with phishing, credential compromise, privilege escalation, lateral movement, and exposed services - Strong analytical, documentation, and communication skills
Nice to have
- Hands-on Google Cloud Platform security experience across IAM, Cloud Logging, Compute Engine, Cloud Storage, VPCs, and service accounts - Exposure to Kubernetes, containers, or other cloud-native workload patterns - Background building automation pipelines for monitoring or response
Benefits and work setup
- After-hours availability is required when urgent incidents need immediate investigation - The interview process includes a live, hands-on technical exercise conducted via screen share