Information Security Engineer

Intuitive Surgical, Inc.

Peachtree Corners (GA)

On-site

USD 146,000 - 210,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Intuitive Surgical, Inc. is seeking a Security Analyst to join the IT Security team in Georgia, responsible for DLP, EDR, SOAR orchestration, and ZTNA enforcement.

You will protect data, endpoints, and users from exfiltration and threats while improving security posture and dashboards in Elasticsearch. The role requires hands-on experience with DLP, EDR, SIEM, and SOAR, plus strong collaboration with cross-functional teams.

Qualifications

  • Minimum of 2 years of experience.
  • Hands-on experience administering enterprise DLP and SASE/CASB solutions.
  • Experience deploying, managing, and troubleshooting EDR across Windows, macOS, Linux.
  • Understanding OS internals for Windows, macOS, Linux in security tooling.
  • Knowledge of ZTNA concepts and least-privilege network policies.
  • Experience building security automation and orchestration workflows.
  • Familiarity with SIEM and Elasticsearch for log analysis and dashboards.
  • Strong communication skills to convey findings to diverse audiences.
  • Ability to handle confidential information with discretion.

Responsibilities

  • Administer and tune DLP policies across endpoints and cloud applications.
  • Deploy, configure, and troubleshoot EDR on Windows, macOS, Linux endpoints.
  • Build automated incident response workflows using SOAR platforms.
  • Support ZTNA policy implementation with least-privilege access controls.
  • Investigate DLP alerts and document findings for compliance and audit purposes.
  • Triage and classify endpoint events with SIEM and DLP collaboration.
  • Collaborate with Detection Engineering to tune SIEM rules.
  • Partner with Incident Response during escalated security events.

Skills

DLP administration
EDR management
SOAR automation
ZTNA concepts
SIEM & Elasticsearch
Endpoint troubleshooting
Security analytics
Communication skills
Investigation & forensics

Education

Technical degree or related experience

Tools

Active Directory (AD)
Group Policy (GPO)
SOAR platforms
SASE/CASB
Elasticsearch
SIEM platforms

Job description

Company Description

It started with a simple idea: what if surgery could be less invasive and recovery less painful? Nearly 30 years later, that question still fuels everything we do at Intuitive. As a global leader in robotic-assisted surgery and minimally invasive care, our technologies-like the da Vinci surgical system and Ion-have transformed how care is delivered for millions of patients worldwide.

We're a team of engineers, clinicians, and innovators united by one purpose: to make surgery smarter, safer, and more human. Every day, our work helps care teams perform with greater precision and patients recover faster, improving outcomes around the world.

The problems we solve demand creativity, rigor, and collaboration. The work is challenging, but deeply meaningful-because every improvement we make has the potential to change a life.

If you're ready to contribute to something bigger than yourself and help transform the future of healthcare, you'll find your purpose here.

Job Description
Primary Function of the Position

This position operates within the IT Security organization and focuses on data loss prevention (DLP), endpoint detection and response (EDR), incident management orchestration, security automation, and zero trust network access (ZTNA). The analyst administers and tunes DLP policies, triages and responds to endpoint security events across Windows, macOS, and Linux, builds automated response workflows, and contributes to the continuous improvement of Intuitive's security posture. Responsible for protecting company information, systems, and users from data exfiltration, unauthorized access, and threat exposure.

Essential Job Duties
  • Administer, tune, and maintain DLP policies and rules within enterprise DLP and SASE/CASB platforms to prevent unauthorized data exfiltration across endpoints, cloud applications, and network egress points.
  • Deploy, configure, and troubleshoot EDR agents across Windows, macOS, and Linux endpoints, ensuring consistent sensor health, policy enforcement, and telemetry collection.
  • Build and maintain automated incident response and orchestration workflows using SOAR platforms to accelerate alert triage, enrichment, containment, and escalation across the security tooling stack.
  • Support ZTNA policy implementation and enforcement in coordination with Network Security, ensuring least-privilege access controls align with zero trust architecture principles.
  • Investigate and respond to DLP alerts, performing root cause analysis, classifying data at risk, coordinating with business stakeholders on policy exceptions, and documenting findings for compliance and audit purposes.
  • Triage and classify endpoint security events by severity and business impact, correlating telemetry from EDR, SIEM, and DLP platforms to identify threats and data exposure risks.
  • Perform endpoint troubleshooting across Windows, macOS, and Linux, including agent deployment issues, policy conflicts, OS‑specific behavioral anomalies, and sensor communication failures.
  • Develop and refine operational metrics and dashboards in Elasticsearch to track DLP policy effectiveness, endpoint coverage gaps, automation ROI, and incident response performance.
  • Collaborate with Detection Engineering to create and tune SIEM detection rules that address DLP bypass techniques, EDR evasion, and insider threat indicators.
  • Partner with Incident Response and Investigations teams during escalated security events, providing endpoint forensic data, DLP event context, and automation support throughout the incident lifecycle.
  • Conduct and support internal security investigations, including insider threat cases, policy violations, and unauthorized data handling, using DLP, EDR, and SIEM platforms for evidence collection and forensic analysis.
  • Maintain strict confidentiality and discretion when handling sensitive investigation materials, personnel matters, and privileged findings throughout the investigative lifecycle.
Required Skills and Experience

Minimum of 2 years of experience.

  • Hands‑on experience administering and tuning enterprise DLP and SASE/CASB solutions across endpoint, cloud, and network enforcement points.
  • Experience deploying, managing, and troubleshooting EDR platforms across Windows, macOS, and Linux environments.
  • Demonstrated competence in endpoint troubleshooting across Windows, macOS, and Linux, including agent lifecycle management, OS‑level diagnostics, and policy conflict resolution.
  • Understanding of underlying operating system internals for Windows, macOS, and Linux, including file systems, process management, registry/plist configuration, logging subsystems, and kernel‑level behaviors relevant to security tooling.
  • Working knowledge of ZTNA concepts and technologies, including identity‑aware access controls, micro‑segmentation, and least‑privilege network policies.
  • Experience building security automation and orchestration workflows using SOAR platforms to streamline incident triage, enrichment, and response.
  • Familiarity with SIEM platforms and Elasticsearch for log analysis, alert correlation, and dashboard development.
  • Strong communication skills with the ability to convey technical findings to IT teams, engineering stakeholders, and business partners in a matrixed organization.
  • Demonstrated ability to handle sensitive and confidential information with discretion, including investigation findings, personnel data, and legal hold materials.
  • Investigative mindset: intellectual curiosity, attention to detail, methodical evidence handling, objectivity, and the ability to construct a factual narrative from disparate data sources.
Required Education and Training
  • Degree in a technical related field (or additional related experience)
Working Conditions
  • None
Preferred Skills and Experience
  • Experience working within a SOC, incident response, or DLP operations function supporting enterprise-level environments.
  • SANS/GIAC certification(s) strongly preferred (e.g., GCFE, GCFA, GCED, GCIH, GCIA, GDSA, or GREM). Other certifications such as CISSP or CompTIA Security+ are a plus.
  • Experience operating across a mature enterprise security stack spanning EDR, DLP, SASE/CASB, SOAR, SIEM, ZTNA, next‑generation firewalls, identity providers, and email security gateways.
  • Demonstrated experience developing automated playbooks for DLP incident handling, endpoint isolation, or threat enrichment workflows.
  • Understanding of insider threat detection methodologies, data classification frameworks, and regulatory requirements relevant to medical device or healthcare organizations (e.g., HIPAA, FDA).
  • Prior experience conducting or supporting workplace investigations, forensic examinations, or e‑discovery processes in a corporate environment.
  • Familiarity with chain‑of‑custody procedures, legal hold requirements, and evidence preservation standards.
  • Prior systems administration experience across Windows, macOS, or Linux environments, with a working understanding of Active Directory, group policy, endpoint management, and OS‑level security hardening.
Additional Information

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19. Details can vary by role.

Intuitive is an Equal Opportunity Employer. We provide equal employment opportunities to all qualified applicants and employees, and prohibit discrimination and harassment of any type, without regard to race, sex, pregnancy, sexual orientation, gender identity, national origin, color, age, religion, protected veteran or disability status, genetic information or any other status protected under federal, state, or local applicable laws.

Mandatory Notices

U.S. Export Controls Disclaimer: In accordance with the U.S. Export Administration Regulations (15 CFR §743.13(b)), some roles at Intuitive Surgical may be subject to U.S. export controls for prospective employees who are nationals from countries currently on embargo or sanctions status.

Certain information you provide as part of the application will be used for purposes of determining whether Intuitive Surgical will need to (i) obtain an export license from the U.S. Government on your behalf (note: the government's licensing process can take 3 to 6+ months) or (ii) implement a Technology Control Plan (“TCP”) (note: typically adds 2 weeks to the hiring process).

For any Intuitive role subject to export controls, final offers are contingent upon obtaining an approved export license and/or an executed TCP prior to the prospective employee's start date, which may or may not be flexible, and within a timeframe that does not unreasonably impede the hiring need. If applicable, candidates will be notified and instructed on any requirements for these purposes.

We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.

Preference will be given to qualified candidates who do not reside, or plan to reside, in Alabama, Arkansas, Delaware, Florida, Indiana, Iowa, Louisiana, Maryland, Mississippi, Missouri, Oklahoma, Pennsylvania, South Carolina, or Tennessee.

This position may be filled at a different job level than listed here depending on business need and/or on the selected candidate's experience, knowledge and skills.

Compensation will be based primarily on the job level at which the role is filled and the candidate's qualifications, consistent with applicable law.

We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target compensation ranges are listed.

Accommodation & Accessibility Notice:

Intuitive is committed to providing reasonable accommodations to qualified individuals with disabilities. If you require assistance or an accommodation during any part of the application or interview process, please contact People Services at (email protected) .

Base Compensation Range Region 1: $146,100 USD - $210,300 USD

Base Compensation Range Region 2: $124,200 USD - $178,800 USD

Shift: Day

Workplace Type: Set Schedule - This job will be onsite weekly, the percentage of onsite work will be defined by the leader.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Architecture
Staff Software Engineer, Architecture

Intuitive Surgical, Inc. • Sunnyvale (CA)

On-site
USD 224,000 - 322,000
Manager, Product Security Analysis
Manager, Product Security Analysis

Intuitive • Sunnyvale (CA)

On-site
USD 171,000 - 201,000
Senior Full-Stack / AI Platform Engineer
Senior Full-Stack / AI Platform Engineer

Worky • Sunnyvale (CA)

On-site
USD 170,000 - 260,000
Software Quality Engineering - CoE structure
Software Quality Engineering - CoE structure

Intuitive Surgical, Inc. • Sunnyvale (CA)

On-site
USD 140,000 - 210,000
Logistics Manager - Systems
Logistics Manager - Systems

Intuitive Surgical, Inc. • San Francisco (CA)

On-site
USD 125,000 - 195,000
Senior Software Engineer
Senior Software Engineer

Intuitive Surgical, Inc. in • Sunnyvale (CA)

On-site
USD 190,000 - 270,000
Field Service Engineer 2 - Wknd Shift
Field Service Engineer 2 - Wknd Shift

Intuitive Surgical, Inc. in • Fort Lauderdale (FL)

On-site
USD 56,000 - 76,000
Sr. Robotic Software Engineer
Sr. Robotic Software Engineer

Intuitive Surgical, Inc. • Sunnyvale (CA)

On-site
USD 189,000 - 271,000
Sr Director Privacy & Data Protection Legal
Sr Director Privacy & Data Protection Legal

Intuitive • Sunnyvale (CA)

On-site
USD 263,000 - 465,000
Corporate Development Director - Digital Product
Corporate Development Director - Digital Product

Intuitive Surgical, Inc. in • Sunnyvale (CA)

On-site
USD 150,000 - 254,000