Job Description
About the Role
An employer is seeking a Security Engineer III to advance our monitoring, detection, and incident response capabilities across the platform. Our platform provides a global, scalable, and secure way to deploy applications. In this role, you will design and enhance monitoring and audit solutions, improve detection quality, and strengthen our ability to respond to and investigate security incidents in a large-scale distributed environment.
Key Responsibilities
- Partner with Software Architects, Platform Engineering, Security Engineering, SRE/Operations teams, Compliance stakeholders, and business leaders to define system boundaries, critical assets, security controls, and monitoring requirements across cloud-native and hybrid environments.
- Design, implement, and continuously enhance observability solutions by leveraging AI-powered monitoring, telemetry analytics, logging, tracing, and metrics collection to improve platform reliability, security visibility, incident detection, response effectiveness, availability, and forensic readiness.
- Integrate and optimize logging, monitoring, and security telemetry pipelines with enterprise platforms such as SIEM, SOAR, EDR/XDR, APM, cloud-native security tools, and AI-assisted analytics solutions, ensuring comprehensive data quality, coverage, and usability.
- Utilize AI-driven operational insights and anomaly detection capabilities to proactively identify security threats, performance degradation, system failures, and emerging operational risks.
- Develop, tune, and automate alerts, correlation rules, and detection logic to reduce alert fatigue, minimize false positives, and maintain strong coverage for security, compliance, and operational events.
- Collaborate with Security Operations Center (SOC), Incident Response, Threat Detection, Vulnerability Management, and Engineering teams to establish and maintain effective escalation paths, communication workflows, and automated response mechanisms.
- Participate in and support the execution of the Incident Response Plan by providing actionable telemetry, threat intelligence, root-cause analysis, forensic evidence, and AI-assisted investigation insights throughout incident lifecycle activities and post-incident reviews.
- Drive DevSecOps practices across the software development lifecycle by integrating security controls, automated compliance checks, vulnerability scanning, policy enforcement, secret management, and threat detection into CI/CD pipelines.
- Partner with development and infrastructure teams to identify, prioritize, remediate, and validate vulnerabilities, ensuring timely patch management, security hardening, and compliance with organizational security standards.
- Implement Infrastructure as Code (IaC), Policy as Code, and Security as Code principles to automate deployment, governance, security controls, and compliance validation across cloud environments.
- Leverage Generative AI and AI-assisted security tooling to improve operational efficiency, accelerate investigations, automate repetitive tasks, enhance threat detection, and support security engineering workflows.
- Participate in on-call rotations and weekend support activities, as required, to ensure timely response to operational incidents, security events, and critical platform issues.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 4–6 years of experience in security operations, monitoring, detection engineering, or incident response.
- Strong hands-on experience with logging, monitoring, and SIEM/dashboarding tools such as AWS GuardDuty, Sumo Logic, Grafana, CrowdStrike, DataDog, Splunk, Thycotic, or similar.
- Working knowledge of at least one major cloud platform (e.g., AWS, Microsoft Azure, Google Cloud Platform), including native security and observability services.
- Solid understanding of log handling and telemetry pipelines: collection, normalization, integration with downstream systems, and alert configuration/tuning.
- Proficiency with at least one programming or scripting language (e.g., Python, Java, Shell).
- Experience with CICD and vulnerability scanning with Shift left mindset.
- Good understanding of security challenges in large-scale distributed systems and cloud-native architectures.
- Working knowledge of container orchestration and cloud platforms such as Kubernetes and/or OpenStack.
- Relevant certifications (e.g., Security+, GSEC, CISSP) are preferred. FedRAMP experience