Sr. Security Engineer, Threat Detection and Response

Posted 2 days ago

cypress hcmDenver (CO)

SENIORITY

Senior

SALARY

$126.56-137.93/hr

Apply

About the role

Description: The Threat Detection and Response team (TDR) is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity. This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response. The Difference You Will Make: You will be a key member of our growing Threat Detection & Response (TDR) team. You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents. You will partner with cross-functional partners across the company to improve the overall security driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems.
Duties: Perform investigations of security incidents using your knowledge of digital forensics and data analytics. Use your coding, data analytics and investigation skills to hunt, detect and respond to threats. Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale. Hunt for threats in our corporate and production environments to proactively identify anomalous activity. Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with partner teams to carry out complex investigations. Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection. Collaborate well with cross-functional partner teams, such as Legal, Privacy, and Engineering for efficient, large-scale response.
Requirements: 5+ years of hands-on in-depth knowledge and technical experience in security operations including detection engineering, threat hunting, incident response, digital forensics, threat intelligence, threat hunting, and/or detection engineering. Proficiency in Python or other scripting language. We also use SQL and Pandas frequently. Familiarity with Elasticsearch is preferred. Self-motivated and creative problem-solver able to work independently with minimal guidance. Ability to lead people in complex, ambiguous situations through influence and not authority. Ability to work calmly and collaboratively in critical high-stress situations with expediency. Outstanding organizational, prioritization, and multitasking skills. Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the threat landscape. Experience automating security detection and response. Experience in AWS services (EC2, S3, Lambda, RDS) preferred We are not focused on specific tools but we often use Python, AWS, SQL, and more Compensation$126.56-137.93/hr W-2 Req ID37574985

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this