Назад
Company hidden
обновлено 11 дней назад

Senior Cyber Threat Defense - Security Operations Engineer (AI)

101 600 - 159 720$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Threat Defense - Security Operations Engineer (AI): Leading complex cybersecurity incident investigations, threat hunting, detection engineering, and security automation across endpoints, identities, cloud environments, SaaS applications, and data repositories with an accent on Level 3 SOC escalation, MITRE ATT&CK, SIEM/SOAR, and AI-enabled security capabilities. Focus on containing sophisticated attacks, building automated response workflows, operating Agentic SOC and AI DLP use cases, and improving detection and response architecture.

Location: Draper, Utah, United States. The role requires U.S. citizenship and participation in an after-hours on-call rotation, including nights, weekends, and holidays.

Base pay for all other U.S. cities and states: $101,600–$159,720 USD annually. The role may also include variable compensation and/or equity.

Company

hirify.global provides cybersecurity technologies and threat intelligence to protect organizations and individuals from phishing, malware, account compromise, insider threats, and data loss across email, cloud, collaboration tools, and AI workflows.

What you will do

  • Own Level 3 escalation for high-severity and technically complex incidents within the global 24/7 SOC.
  • Lead investigations into malware, ransomware, phishing, identity attacks, insider threats, cloud compromise, data loss, and advanced persistent threats.
  • Direct containment, eradication, recovery, remediation, and post-incident improvement strategies across Security, IT, Cloud Engineering, Legal, Privacy, and business leadership.
  • Hunt for threats and develop, test, tune, and maintain detection rules, hunting queries, correlations, and response playbooks using threat intelligence and MITRE ATT&CK.
  • Define security automation using SOAR platforms, APIs, Python, PowerShell, Bash, and SIEM optimization.
  • Support Agentic SOC workflows and AI DLP controls, mentor security staff, and drive improvements to telemetry, controls, processes, and architecture.

Requirements

  • Eight or more years of hands-on experience in cybersecurity incident response, threat detection, threat hunting, or security operations.
  • U.S. citizenship required.
  • Experience leading major incidents and serving as the final technical escalation point for complex or high-severity events.
  • Strong knowledge of SOC operations, SIEM, SOAR, EDR/XDR, threat intelligence, digital forensics, security monitoring, cloud security, and scripting.
  • Experience with MITRE ATT&CK, the cyber kill chain, threat modeling methods, detection engineering, hunting queries, and response playbooks.
  • Willingness and ability to participate in scheduled on-call coverage outside normal business hours.

Nice to have

  • Experience with Agentic SOC, AI-assisted investigation, or AI DLP capabilities.
  • Experience with identity, cloud, or data detection and response technologies.
  • Experience leading incident simulations, purple-team exercises, or adversary-emulation activities.
  • Certifications such as GCIH, GCFA, CISSP, CISM, OSCP, GIAC, or cloud-security certifications.

Culture & Benefits

  • Flexible work environment and global collaboration opportunities.
  • Competitive compensation and comprehensive benefits.
  • Flexible time off, two paid Wellbeing Days, and two paid Volunteer Days annually.
  • Annual wellness and community outreach days.
  • Career development, recognition programs, and a three-week Work from Anywhere option.

Hiring process

  • Submit an application with supporting information.
  • Accommodation is available during the application or interview process upon request.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →