Назад
Company hidden
обновлено 11 дней назад

Staff Information Security Engineer - Threat Defense & Automation

187 700 - 275 275$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Information Security Engineer - Threat Defense & Automation (Cybersecurity): Leading incident response, advanced threat detection, threat hunting, and automated defense workflows across enterprise endpoints, networks, identities, and cloud environments with an accent on APT, ransomware, insider-threat, and cloud-compromise investigations. Focus on commanding high-severity incidents, designing SIEM/EDR/SOAR detections, operationalizing threat intelligence, and improving response through automation and post-incident analysis.

Location: Hybrid, based in the Draper, UT or Sunnyvale, CA office four days per week. The role also includes a 24/7 on-call incident response rotation.

Base pay for the SF Bay Area, including Sunnyvale, is $187,700–$275,275 USD annually. The role may also include variable compensation and/or equity.

Company

Cybersecurity company protecting organizations and individuals from advanced threats, phishing, data breaches, data loss, and risks across email, cloud, collaboration tools, and AI workflows.

What you will do

  • Serve as a Level 3 escalation point for high-severity security incidents.
  • Lead investigations into APTs, ransomware, insider threats, and cloud compromises.
  • Act as incident commander and coordinate enterprise response efforts.
  • Lead threat hunting across endpoint, network, identity, and cloud environments.
  • Design and improve detections across SIEM, EDR, and SOAR platforms.
  • Automate incident triage and response workflows, lead post-incident reviews, and mentor security professionals.

Requirements

  • US citizenship is required.
  • 12+ years of experience in incident response, DFIR, threat hunting, or security operations.
  • Deep expertise in incident response, threat hunting, and threat intelligence.
  • Strong knowledge of MITRE ATT&CK and adversary TTPs.
  • Experience with SIEM, EDR, SOAR, and cloud security.
  • Scripting experience with Python, PowerShell, or Bash, plus strong communication and leadership skills.

Nice to have

  • Experience building threat hunting or detection programs.
  • Background in threat intelligence or red/purple teaming.
  • Certifications such as GCFA, GCIH, CISSP, CISM, or OSCP.

Culture & Benefits

  • Comprehensive benefits and flexible time off.
  • Flexible work environment with a three-week Work from Anywhere option.
  • Two paid Wellbeing Days and two paid Volunteer Days per year.
  • Annual wellness and community outreach days.
  • Career development, recognition, and global collaboration opportunities.

Hiring process

  • Submit an application with supporting information.
  • Accommodation is available during the application or interview process upon request.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →