Senior Security Engineer
- Роль
- Безопасность
- Опыт
- Синьор
- Занятость
- Полная занятость
- Размер компании
- Крупная
Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.
Коротко по делу
Senior security engineer for enterprise detection, response, and security tooling. Requires broad hands-on experience with SIEM, EDR, vulnerability management, cloud (AWS) security, and incident response. US-based (Remote - USA) applicants; hybrid on-site expectation if within 50 miles of a Guardant facility.
Ключевые навыки
Обязательные навыки
Желательные навыки
Обязательные языки
Чем предстоит заниматься
- Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
- Oversee and optimize Managed Detection and Response (MDR) and SOAR capabilities and related integrations.
- Serve as a technical owner for SIEM operations including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
- Develop, tune, and maintain threat detection content including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity-based alerts.
- Analyze security events, threat intelligence, and attacker tradecraft to improve detection coverage and support incident response investigations.
- Support and participate in Incident Response activities including triage, investigation, containment, eradication, recovery, evidence collection, and post-incident reviews.
- Support security investigations involving endpoint activity, cloud events, identity logs, network telemetry, SaaS activity, and other data sources.
- Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations.
- Support Vulnerability Management activities including scanner operations, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
- Manage threats from AWS and cloud-native environments and monitor CloudTrail, VPC Flow Logs, workload logs, IAM activity, container activity, and cloud security findings.
- Build dashboards, metrics, and reports to measure security tool health, detection coverage, vulnerability management posture, and incident response effectiveness.
- Develop and maintain documentation, operational runbooks, incident response playbooks, engineering standards, and tool administration procedures.
- Evaluate AI-assisted security capabilities and define logging, monitoring, and risk assessment for AI systems and agents.
- Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross-functional partners.
- Stay current on emerging threats, attacker tradecraft, vulnerability trends, security tooling, cloud security practices, and security engineering best practices.
Что требуется
- 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, Detection Engineering, or a related security role.
- Broad hands-on experience administering and improving enterprise security tools.
- Experience supporting Incident Response in a SOC or enterprise security environment.
- Strong experience with SIEM platforms including log ingestion, alerting, detection content, dashboards, and operational support.
- Experience with EDR platforms including investigation, containment, policy management, and response workflows.
- Experience with Vulnerability Management platforms and processes including vulnerability scanning, prioritization, remediation tracking, and reporting.
- Hands-on experience securing and monitoring AWS or other cloud environments.
- Experience working with identity and access logs, preferably including Okta or similar identity platforms.
- Strong understanding of endpoint, cloud, identity, network, SaaS, and infrastructure security telemetry.
- Experience developing documentation, runbooks, playbooks, and repeatable operational procedures.
- Experience modernizing SIEM, Logging, or Security Monitoring architectures.
- Experience with detection engineering frameworks such as MITRE ATT&CK.
- Experience building or managing SOAR workflows, response automation, or security orchestration.
- Experience with cloud security posture management, cloud workload protection, container security, or infrastructure-as-code security tools.
- Experience in healthcare, biotech, life sciences, or other regulated environments is a plus.
- Familiarity with compliance and regulatory requirements influencing security logging, monitoring, vulnerability management, and incident response is a plus.
- Strong written and verbal communication skills.
Преимущества
- Hybrid Work Model with defined in-person days for employees living within 50 miles of a Guardant facility.
- Reasonable accommodations in hiring processes for candidates with disabilities or protected needs.
- Background screening required; company will consider applicants with criminal histories in line with applicable laws.
- Equal Opportunity Employer commitments.
Guardant Health is a leading precision oncology company focused on guarding wellness and giving every person more time free from cancer. Founded in 2012, Guardant® is transforming patient care and accelerating new cancer therapies by providing critical insights into what drives disease through its advanced blood and tissue tests, real-world data and AI analytics.