Security Engineer

Veeam

San Jose (CA)

On-site

USD 180,000 - 240,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage
Paid parental leave
Professional training and education

Job summary

Veeam is seeking a Security Engineer III to own threat detection and response across our cloud estate. You will design a security data lake ingesting telemetry from Azure, AWS, SaaS, and endpoints, and build guardrails in multi-tenant environments.

You will write detections as code, automate triage and enrichments, and push secure configurations through Terraform in a production CI/CD workflow.

Qualifications

  • 5+ years in security engineering, cloud operations, or detection engineering.
  • Fluency with cloud security concepts, IAM, network boundaries, and incident response.

Responsibilities

  • Own the detection engineering and cloud security surface end to end.
  • Design and build the security data lake to collect telemetry from Azure, AWS, SaaS, and endpoints.
  • Write, tune, and version-control detections as code across CI/CD pipelines.

Job description

  • We’re looking for a Security Engineer III to own how we detect and respond to threats across our cloud estate, and to build the security data lake that makes that possible
  • Our cloud-native SaaS platform runs on Microsoft Azure and AWS, delivering high-trust, secure data protection services to customers across regulated industries
  • This role sits in Platform Security and owns the detection engineering and cloud security surface end to end: the pipelines that get security telemetry into one queryable place, the detections that fire off it, and the guardrails in Azure and AWS that stop the finding from recurring
  • You’ll partner closely with SRE, Product Engineering, and the rest of Security Engineering, and your work is based on shipped mechanisms rather than on advice given
  • Design and build our security data lake: decide what telemetry we ingest from Azure, AWS, SaaS, and endpoint sources, how it’s normalized and retained, and what it costs, so that detection engineers and incident responders can answer questions in minutes instead of days
  • Write, tune, and version‑control detections as code. Own the full lifecycle: hypothesis, query, test, deploy through CI/CD, measure false‑positive rate, and retire what stops earning its keep
  • Build the response side with the detections. Automate triage and enrichment, wire runbooks into the tooling, and cut mean‑time‑to‑detect and mean‑time‑to‑respond on the alert classes that matter most
  • Hands on hardening our Azure and AWS environments: identity and RBAC boundaries, network egress, key and secret handling, logging coverage, and public‑exposure control across multiple tenants and accounts
  • Deliver cloud security controls as Terraform. Anything you fix once should land in the modules and pipelines so it stays fixed, in every environment, without a human remembering
  • Turn cloud security posture findings into a prioritized, owned, and closing queue. Partner with the teams that own the resources and make remediation the path of least resistance
  • Run detection coverage assessments against a recognized threat framework, find the gaps that matter for our platform and threat model, and close them
  • Set direction on detection and cloud security tooling: what to adopt, what to retire, and what we build ourselves
  • Technologies You’ll Work With
  • Microsoft Sentinel, Log Analytics, and KQL for detection authoring and hunting
  • Azure security services: Defender for Cloud, Entra ID, Key Vault, Azure Policy, Azure Monitor, Event Hubs
  • AWS security services: CloudTrail, GuardDuty, Security Hub, IAM, Config, CloudWatch
  • Terraform for all cloud security and detection infrastructure, with GitHub Actions and Azure DevOps as the delivery path
  • Wiz for cloud security posture, attack‑path analysis, and vulnerability signal
  • Security data lake and pipeline components: object storage (ADLS / S3), OCSF‑style normalization, Azure Data Explorer or an equivalent query engine, and Azure Functions / Lambda for glue
  • Python for detection tooling, enrichment, and automation, with comfort reading PowerShell and Bash
  • Sigma and detection‑as‑code patterns, plus Git‑based review for every rule change
Benefits
  • Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
  • Unlimited paid time off, plus 3 global VeeaMe Days for self‑care
  • Medical, dental, and vision coverage from day one
  • Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
  • Mental health support, therapy sessions, and digital wellness tools via SupportLinc EAP
  • 401(k) retirement plan with matching contributions up to annual limits
  • Legal services, identity protection, and supplemental health insurance options
  • AirVet: 24/7 virtual veterinary care at no cost
  • Professional training and education, including courses and workshops, internal meetups, and unlimited access to our online learning platforms (LinkedIn Learning, Athena, O’Reilly) and mentoring through our MentorLab program
  • Tax‑advantaged spending accounts for healthcare, dependent care, and commuting

Scripting and automation ability in Python or a comparable language, enough to build and maintain tooling rather than only configure vendor productsStrong cloud security fundamentals: RBAC and least privilege, secret and key management, egress control, and public‑exposure preventionProduction Terraform experience. You’ve written and maintained modules other teams consume, and you know why a security control belongs in code rather than in a runbookReal operational depth in both Azure and AWS: identity models, logging and audit sources, network boundaries, and where each provider’s defaults leave you exposedDemonstrated detection building. You’ve written detections against real telemetry, tuned them against real false positives, and can explain a specific rule you shipped and how you validated it5+ years in security engineering, cloud operations, or detection engineering, with recent hands‑on ownership of production cloud security workFluency in at least one query language for security data (KQL, SQL, or equivalent) and the judgment to know when a query problem is actually a data‑model problemA track record of shipping production code or infrastructure you can point to. This is a hands‑on building role, not an advisory oneMicrosoft Sentinel at production scale: analytics rules, automation rules, ingestion cost management, and multi‑workspace designWiz experience, including turning posture and attack‑path findings into an owned remediation workflowIncident response experience in a cloud environment, on‑call or as an investigatorKubernetes and container security exposure (AKS, EKS) and runtime detection for containerized workloadsSecurity data lake or SIEM migration experience, including cost and retention tradeoffsFamiliarity with regulated‑industry audit expectations (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST) and what auditors want from logging and monitoring controlsRelevant certifications (Azure or AWS security specialty, GCIA, GCDA, or similar)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and Response Platform Engineer
Detection and Response Platform Engineer

Jobtailor • Sunnyvale (CA)

On-site
USD 150,000 - 230,000
Remote Principal Cloud Security Architect & CNAPP Leader
Remote Principal Cloud Security Architect & CNAPP Leader

RED SKY Consulting • United States

On-site
USD 170,000 - 260,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Confluent - Staff Security Engineer I - Detection & Response
Confluent - Staff Security Engineer I - Detection & Response

IBM • Armonk (NY)

On-site
USD 140,000 - 180,000
Confluent - Staff Security Engineer I - Detection & Response
Confluent - Staff Security Engineer I - Detection & Response

IBM • San Diego (CA)

On-site
USD 140,000 - 190,000
AI Platform Security Engineer
AI Platform Security Engineer

Kai • San Jose (CA)

On-site
USD 180,000 - 240,000
Network Security Engineer
Network Security Engineer

Jobtailor • Town of Florida (NY)

Hybrid
USD 90,000 - 130,000
Cyber Cloud Security Engineer
Cyber Cloud Security Engineer

Pierce • New York (NY)

On-site
USD 140,000 - 190,000
Cloud Engineer
Cloud Engineer

Advisor Group Inc. • Scottsdale (AZ)

Hybrid
USD 140,000 - 160,000
Health insurance
Dental insurance
401(k)
+2
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000