Remote job
Senior Security Platform Engineer
Job details
About this role
Role overview
This senior engineering role supports the security data platform that powers threat detection and incident response. You will build and operate reliable pipelines that collect, transform, validate, and route telemetry into a security information and event management environment, ensuring analysts receive accurate and timely data. The position combines security engineering, data engineering, DevOps, cloud infrastructure, automation, and on-call operations.
Responsibilities
- Onboard log sources into a SIEM by coordinating with data owners, configuring collection agents or connectors, developing parsers, and validating production data. - Design and maintain security data pipelines covering ingestion, buffering, transformation, enrichment, routing, and storage. - Manage cloud infrastructure across multiple Azure tenants and subscriptions using Terraform, including reusable modules, state, drift handling, and brownfield environments. - Build and maintain CI/CD workflows for infrastructure and pipeline configurations, with automated testing and controlled deployments. - Develop maintainable automation and security operations tooling in Python or Go. - Monitor data quality and platform reliability, participate in an on-call rotation, troubleshoot failures, and communicate technical findings to technical and non-technical stakeholders.
Requirements
- At least eight years of experience in cybersecurity, SRE, data engineering, or a related discipline, including two or more years focused on security data pipelines or SIEM platform engineering. - Strong Terraform experience managing cloud resources across Azure environments; transferable AWS or GCP experience may also be relevant. - Hands-on experience integrating log sources with platforms such as Microsoft Sentinel, Splunk, or Elastic, including parsing and production validation. - Experience designing and operating streaming or data-processing workflows for filtering, normalization, enrichment, and log routing. - Familiarity with Git-based pull-request workflows, CI/CD, infrastructure testing, and automated deployment practices. - Ability to write production-quality, testable automation code in Python or Go, plus a bachelor’s degree or equivalent experience in a related field.
Nice to have
- Exposure to the MITRE ATT&CK framework and the relationship between telemetry coverage and detection coverage. - Experience with tools such as Cribl, Logstash, Azure Data Explorer, or custom ETL systems. - Background in security operations workflows, detection engineering, or forensic and incident-response environments.
Benefits and work setup
- Hybrid arrangement requiring office access and generally at least two days per week in the office, with the weekly schedule varying by team.