Senior Cyber Threat Defense - Security Operations Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Cyber Threat Defense - Security Operations Engineer (Cybersecurity): Leading high-severity incident response and threat hunting across global operations with an accent on L3 escalations, security automation, and AI-enabled SOC workflows. Focus on developing detection rules, managing complex investigations, and implementing AI-driven data loss prevention controls.
Location: Draper, UT. U.S. citizenship is strictly required.
Salary: $101,600 – $159,720
Company
is a global leader in human- and agent-centric cybersecurity protecting organizations from advanced threats across email, cloud, and collaboration tools.
What you will do
- Act as the L3 escalation point for high-severity incidents, leading investigations into malware, ransomware, and APTs.
- Proactively hunt for threats across endpoints, networks, and cloud environments using behavioral analytics.
- Develop and maintain detection rules, hunting queries, and response playbooks aligned with the MITRE ATT&CK framework.
- Implement security automation strategies using SOAR platforms and scripting in Python, PowerShell, or Bash.
- Support emerging AI capabilities, including Agentic SOC workflows and AI Data Loss Prevention (AI DLP) controls.
- Conduct root-cause analysis and mentor SOC analysts to raise overall technical capabilities.
Requirements
- U.S. citizenship.
- 8+ years of experience in cybersecurity incident response, threat detection, or security operations.
- Expertise in SIEM, SOAR, EDR/XDR, and digital forensics.
- Strong proficiency in scripting languages such as Python, PowerShell, or Bash.
- Deep understanding of MITRE ATT&CK and threat modeling methods (STRIDE, attack trees).
- Experience with cloud security across AWS, Azure, or GCP.
- Ability to participate in a scheduled on-call rotation, including nights and weekends.
Nice to have
- Experience with Agentic SOC or AI-assisted investigation tools.
- Knowledge of identity, cloud, or data detection and response technologies.
- Certifications such as CISSP, GCIH, GCFA, OSCP, or CISM.
- Experience leading purple-team exercises or adversary emulation.
Culture & Benefits
- Competitive compensation and comprehensive benefits package.
- Flexible work environment.
- Three-week "Work from Anywhere" annual option.
- Annual wellness and community outreach days.
- Global collaboration opportunities within a values-driven team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →