Senior Cloud Security Engineer

JMJ PHILLIP

Turkey (TX)

On-site

USD 150,000 - 200,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

JMJ PHILLIP is seeking a hands-on Senior Cloud Security Engineer to establish and strengthen continuous security monitoring, detection engineering, incident response, and security operations across cloud, endpoints, network, and on-prem environments.

In this role you will own security monitoring, manage SIEM platforms such as Microsoft Sentinel, and coordinate with engineering, infrastructure, and leadership to reduce risk and improve incident response and security posture in a fast-paced

Qualifications

  • 5+ years in cybersecurity, security operations, cloud security, or related engineering roles.
  • Demonstrated experience with SIEM administration, detection engineering, alert investigation, and incident response.
  • Hands-on experience with Microsoft Sentinel or a comparable enterprise SIEM platform.
  • Experience with AWS security services, including GuardDuty, Security Hub, CloudTrail, IAM, and CloudWatch.
  • Experience with endpoint detection and response technologies.
  • Strong understanding of security logging, event correlation, threat detection, and incident investigation.
  • Experience operating in Microsoft Azure and AWS environments.
  • Working knowledge of network security, firewalls, identity systems, endpoints, and hybrid infrastructure.
  • Understanding of vulnerability management processes and common cybersecurity frameworks.
  • Strong technical documentation and communication skills.
  • Ability to work independently and take ownership of security operations from identification through resolution.

Responsibilities

  • Own continuous security monitoring across cloud, endpoint, network, and on-premises environments.
  • Administer and optimize Microsoft Sentinel or comparable SIEM platforms, including data connectors, analytics rules, alerting, dashboards, workbooks, and automation.
  • Monitor and manage AWS security services, including GuardDuty, Security Hub, CloudTrail, CloudWatch, and IAM.
  • Develop and maintain security detections, correlation rules, use cases, and alert thresholds.
  • Improve threat visibility while reducing false positives and alert fatigue.
  • Identify gaps in logging, monitoring, and detection coverage and implement corrective actions.
  • Support threat hunting, security analytics, and proactive identification of emerging risks.
  • Investigate security alerts, anomalous activity, potential compromises, and policy violations.
  • Lead incident triage, containment, eradication, recovery, and post-incident review activities.
  • Develop, maintain, and exercise incident response plans, playbooks, escalation procedures, and communication processes.
  • Ensure security incidents and events are properly documented with sufficient evidence for internal and external assessments.
  • Monitor endpoint security and EDR platforms and investigate suspicious endpoint activity.
  • Establish and maintain centralized security logging, retention, review, and audit capabilities.

Skills

SIEM administration
Detection engineering
Incident response
Microsoft Sentinel
AWS security services
EDR security
Cloud security
Azure/AWS environments

Tools

Microsoft Sentinel
GuardDuty
Security Hub
CloudTrail
CloudWatch
EDR tools

Job description

We are seeking a hands-on Senior Cloud Security Engineer to establish and strengthen continuous security monitoring, detection engineering, incident response, and security operations across cloud, endpoint, network, and on-premises environments. This individual will play a critical role in identifying, investigating, and resolving security events while working closely with engineering, infrastructure, networking, compliance, and leadership teams.

The ideal candidate combines strong technical security engineering experience with expertise in cloud security operations, SIEM platforms, threat detection, incident response, and federal cybersecurity requirements.

Position Responsibilities
Security Monitoring and Detection Engineering
  • Own continuous security monitoring across cloud, endpoint, network, and on-premises environments.
  • Administer and optimize Microsoft Sentinel or comparable SIEM platforms, including data connectors, analytics rules, alerting, dashboards, workbooks, and automation.
  • Monitor and manage AWS security services, including GuardDuty, Security Hub, CloudTrail, CloudWatch, and IAM.
  • Develop and maintain security detections, correlation rules, use cases, and alert thresholds.
  • Improve threat visibility while reducing false positives and alert fatigue.
  • Identify gaps in logging, monitoring, and detection coverage and implement corrective actions.
  • Support threat hunting, security analytics, and proactive identification of emerging risks.
Incident Response and Security Operations
  • Investigate security alerts, anomalous activity, potential compromises, and policy violations.
  • Lead incident triage, containment, eradication, recovery, and post-incident review activities.
  • Develop, maintain, and exercise incident response plans, playbooks, escalation procedures, and communication processes.
  • Ensure security incidents and events are properly documented with sufficient evidence for internal and external assessments.
  • Monitor endpoint security and EDR platforms and investigate suspicious endpoint activity.
  • Establish and maintain centralized security logging, retention, review, and audit capabilities.
Vulnerability and Risk Management
  • Coordinate vulnerability findings with infrastructure and application teams to prioritize remediation.
  • Track remediation activities and verify that identified security issues have been resolved.
  • Support risk assessments and identify gaps in security controls.
  • Provide technical recommendations to strengthen security posture and reduce operational risk.
Compliance and Assessment Support
  • Work with compliance and technical teams to align operational security activities with applicable cybersecurity requirements.
  • Support the operational execution and evidence collection associated with NIST SP 800-171 and related security frameworks.
  • Maintain documentation and evidence demonstrating that required security processes are actively operating.
  • Support government assessments, audits, customer security reviews, and other compliance activities.
  • Assist with the development and maintenance of security policies, procedures, standards, and operating documentation.
Security Architecture and Continuous Improvement
  • Provide technical input into security architecture, cloud deployments, network design, and new technology implementations.
  • Develop meaningful security operations metrics, including alert volumes, response times, incident trends, remediation status, and detection coverage.
  • Partner with engineering teams to improve security controls, processes, and operational capabilities.
  • Identify opportunities for automation, workflow improvements, and more efficient incident response processes.
  • Provide leadership with clear visibility into security posture, operational risk, and emerging threats.
Prerequisites
  • 5+ years of experience in cybersecurity, security operations, cloud security, or related engineering roles.
  • Demonstrated experience with SIEM administration, detection engineering, alert investigation, and incident response.
  • Hands- on experience with Microsoft Sentinel or a comparable enterprise SIEM platform.
  • Experience with AWS security services, including GuardDuty, Security Hub, CloudTrail, IAM, and CloudWatch.
  • Experience with endpoint detection and response technologies.
  • Strong understanding of security logging, event correlation, threat detection, and incident investigation.
  • Experience operating in Microsoft Azure and AWS environments.
  • Working knowledge of network security, firewalls, identity systems, endpoints, and hybrid infrastructure.
  • Understanding of vulnerability management processes and common cybersecurity frameworks.
  • Strong technical documentation and communication skills.
  • Ability to work independently and take ownership of security operations from identification through resolution.
  • Experience working in fast-paced environments with multiple technical stakeholders and priorities.
Certifications (Preferred, but not Required)
  • Certified Information Systems Security Professional (CISSP).
  • Certified Cloud Security Professional (CCSP).
  • CompTIA Security+.
  • GIAC certifications.
  • AWS Certified Security – Specialty.
  • Microsoft security certifications.
  • Other relevant certifications in cloud security, incident response, threat detection, or security operations.
What the Role Offers
  • Competitive salary range of $150,000 to $200,000, based on experience, qualifications, and technical expertise.
  • A highly visible, hands-on senior engineering role with significant ownership of security operations.
  • The opportunity to build and improve security monitoring, detection, incident response, and operational processes.
  • Exposure to cloud, endpoint, network, and hybrid infrastructure security environments.
  • The ability to work closely with engineering, infrastructure, compliance, and executive leadership.
  • Opportunities to contribute to security architecture, automation, threat detection, and continuous improvement initiatives.
  • Professional growth within a technically challenging environment supporting complex cybersecurity and compliance requirements.
Why Houston?

Houston offers a strong and diverse technology and business environment, with opportunities across energy, aerospace, manufacturing, engineering, healthcare, and government-related industries. The area is home to a large and growing technology workforce, providing access to experienced professionals and a broad range of industries facing increasingly complex cybersecurity challenges. Houston also offers a vibrant metropolitan lifestyle with diverse cultural, dining, entertainment, and recreational opportunities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Operations Analyst
Lead Security Operations Analyst

Ledgent Technology • Houston (TX)

On-site
USD 110,000 - 150,000
Work-from-home flexibility
Occasional in-person meetings
Cyber Security Engineer
Cyber Security Engineer

Attractivate Consulting Solutions • Houston (TX)

On-site
USD 140,000 - 175,000
Senior Security Engineer
Senior Security Engineer

Peyton Resource Group • Bethesda (MD)

On-site
USD 150,000 - 210,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Heath • Houston (TX)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Benefits
401k
PTO
+1
Senior Security Engineer
Senior Security Engineer

Emergent Professional Resources L.P. (EPR) • Houston (TX)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Arkadia Search Recruiting • Irving (TX)

On-site
USD 80,000 - 120,000
401(k)
Pet insurance
First day benefits
+1