Senior Cyber Threat Defense - Security Operations Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Draper, Utah, United States. The role requires U.S. citizenship and participation in an after-hours on-call rotation, including nights, weekends, and holidays.
Base pay for all other U.S. cities and states: $101,600–$159,720 USD annually. The role may also include variable compensation and/or equity.
Company
provides cybersecurity technologies and threat intelligence to protect organizations and individuals from phishing, malware, account compromise, insider threats, and data loss across email, cloud, collaboration tools, and AI workflows.
What you will do
- Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
- Lead investigations into malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, data loss, and advanced persistent threats.
- Direct containment, eradication, recovery, remediation, and post-incident improvement strategies across Security, IT, Cloud Engineering, Legal, Privacy, and business leadership.
- Hunt for threats and develop, test, tune, and maintain detection rules, hunting queries, correlations, and response playbooks using threat intelligence and MITRE ATT&CK.
- Define security automation using SOAR platforms, APIs, Python, PowerShell, Bash, and SIEM optimization.
- Support Agentic SOC workflows and AI DLP controls, mentor security staff, and drive improvements to telemetry, controls, processes, and architecture.
Requirements
- Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
- U.S. citizenship required.
- Experience leading major incidents and serving as the final technical escalation point for complex or high-severity events.
- Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, security monitoring, cloud security, and scripting.
- Experience with MITRE ATT&CK, the cyber kill chain, threat modeling methods, detection engineering, hunting queries, and response playbooks.
- Willingness and ability to participate in scheduled on-call coverage outside normal business hours.
Nice to have
- Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
- Experience with identity, cloud, or data detection and response technologies.
- Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
- Certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.
Culture & Benefits
- Flexible work environment and global collaboration opportunities.
- Competitive compensation and comprehensive benefits.
- Flexible time off, two paid Wellbeing Days, and two paid Volunteer Days annually.
- Annual wellness and community outreach days.
- Career development, recognition programs, and a three-week Work from Anywhere option.
Hiring process
- Submit an application with supporting information.
- Accommodation is available during the application or interview process upon request.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →