Senior Security Engineer

Socket.dev

Merrill (WI)

Hybrid

USD 140,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Socket.dev is seeking a Senior Security Engineer to lead major security initiatives and provide technical leadership across identity, endpoint, network, and cloud domains. The role requires hands-on expertise and mentoring of engineers on advanced investigations, detection, and incident response.

Responsibilities include initiating triage strategies, defining vulnerability processes, and driving enterprise security architecture improvements across the organization.

Qualifications

  • Proven leadership in detection engineering, IR, automation, or architecture.
  • Ability to design and maintain enterprise detection logic and automation workflows.
  • Advanced experience with security tooling including EDR, DLP, SIEM, identity security, VM and NDR.

Responsibilities

  • Investigate and report complex cyber incidents, setting standards for incident response.
  • Oversee cybersecurity operations and guide escalation protocols.
  • Lead initial cyber incident triage strategies and determine scope and urgency.
  • Set standards for vulnerability identification and documentation using advanced tools.
  • Direct data analysis using security telemetry and mentor others in analysis.
  • Lead root cause analyses for major incidents and influence investigative methodologies across the org.
  • Stay at the forefront of threats and drive process improvements and knowledge sharing.
  • Architect and optimize the security technology stack and drive strategic improvements.

Skills

Detection engineering
Incident response
Automation workflows
Enterprise architecture
EDR
DLP
SIEM
Identity security
VM
NDR
Cross-domain expertise

Education

CS/IS/Cybersecurity degree

Tools

EDR
SIEM

Job description

BASIC PURPOSE:

The Senior Security Engineer drives major security engineering initiatives and provide technical leadership across multiple domains, and works across teams to align security capabilities with business objectives. This role defines control enhancements. Leads advanced investigation, shapes engineering standards, and mentors Engineers and Administrators Must demonstrate advanced cross-domain capability (identity, endpoint, network, cloud) and lead complex detection and incident response activities. Individuals unable to lead hands‑on technical work will not meet expectations.


PRIMARY JOB RESPONSIBILITIES:


  • Exercise expert‑level judgment to independently investigate and report complex cyber incidents, setting standards for incident response and mentoring junior staff on advanced cases.

  • Oversee system cybersecurity operations, making high‑stakes decisions in ambiguous scenarios and shaping escalation protocols for critical issues.

  • Lead and define initial cyber incident triage strategies, determining scope and urgency with authority, and guiding the team through complex incidents.

  • Set organizational standards for vulnerability identification and documentation, utilizing advanced tools and methodologies, and influencing escalation practices for non‑standard or high‑risk findings.

  • Direct advanced data analysis using CND tools (IDS alerts, firewall logs, host system logs), recognizing sophisticated threat patterns and mentoring others in expert analysis.

  • Ensure the highest standards of incident documentation, reviewing and resolving discrepancies with expert judgment, and influencing documentation practices across the team.

  • Lead root cause analysis for major incidents, applying advanced analytical skills and shaping investigative methodologies for the organization.

  • Stay at the forefront of cybersecurity threats and best practices, driving process improvements and influencing team knowledge sharing.

  • Architect and optimize the Security technology stack, resolving advanced issues and leading strategic process improvements that impact enterprise security.

  • Lead response efforts to active attacks in cloud and on‑premises environments, exercising advanced judgment and authority in high‑stakes scenarios.

  • Provide expert input on threat protection, leading initiatives that drive team efficiency and influence organizational security practices.

  • Independently report and lead reviews of suspected policy violations, shaping investigative standards for cases requiring further scrutiny.

  • Lead risk mitigation efforts, making high‑stakes decisions to manage exposure and influencing improvements to organizational risk management processes.

  • Drive the development of enterprise‑wide security architectures and standards, leading strategic meetings and initiatives that influence organizational direction.

  • Oversee baseline and risk assessments, setting standards for data collection and analysis, and guiding the team through complex findings.

  • Provide advanced cybersecurity consultation, leading enterprise‑wide health checks and resolving complex questions that shape organizational security posture.

  • Lead research into emerging cybersecurity threats, applying deep functional knowledge and influencing investigative approaches for complex incidents.

  • Maintain and review the enterprise cybersecurity risk register, setting standards for risk documentation and resolving unusual entries with expert judgment.

  • Lead forensic investigations and advanced cybersecurity activities, setting standards for data collection and documentation, and mentoring junior analysts.

  • Manage intrusion prevention systems and define endpoint protection policies, leading strategic improvements and influencing routine security practices.

  • Triage advanced threat detection (ATD) alerts, exercising expert judgment and shaping team approaches to complex alerts.

  • Provide advanced advice and assistance on cybersecurity matters, mentoring junior analysts and influencing the resolution of complex questions.

  • Lead training sessions and drive adoption of new cybersecurity and communication technologies, shaping team efficiency and mentoring others.


Level Expectations (Performance and Scope Indicators)

The following outlines how performance is evaluated at this level. These are not additional job responsibilities, but indicators of scope, autonomy, impact, and influence expected of this role.


Scope:

Leads major security initiatives, projects, and engineering workstreams across multiple domains. Serves as subject‑matter expert for technical control architecture, detection logic design, investigation methodology, and enterprise security tooling.


Autonomy:

Operates with high autonomy. Makes technical decisions, designs solutions, and resolves complex issues. Escalates only when strategic trade‑offs or cross‑team impacts arise.


Impact:

Shapes security capabilities across the entire organization. Defines engineering patterns, raises maturity levels, and drives large‑scale improvements that reduce risk and improve operational efficiency.


People Influence:

Mentors engineers and administrators. Leads small technical squads or project teams. Provides input into workforce capability development. Influences Architecture, Infrastructure, and Ops.


QUALIFICATIONS:

Required


  • Proven leadership in detection engineering, IR, automation, or architecture.

  • Ability to design and maintain enterprise detection logic and automation workflows.

  • Advanced experience with EDR, DLP, SIEM, identity security, VM, and NDR at engineering depth.

  • Ability to act as escalation point for complex, multi‑vector incidents.

  • Expertise across identity, endpoint, cloud, network, and data security domains.

  • Degree in CS/IS/Cybersecurity or equivalent; 10+ years hands‑on experience.


Technical Competencies


  • Capability to evaluate and improve control architecture.

  • Ability to lead hunts, develop analytics, and guide complex IR cases.

  • Ability to drive technical initiatives requiring cross‑functional coordination.


Preferred


  • CISSP, SC‑300, GIAC certifications.

  • Experience influencing enterprise architecture and leadership decision‑making.


WORK ENVIRONMENT:

Office



  • Professional office environment. Regularly uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.

  • Regularly required to communicate; sit; stand; walk; use hands to finger, handle or feel; and reach with hands and arms.

  • Supervisory Responsibilities – None

  • CM Group Office – Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000
IT Security - Sr. Analyst
IT Security - Sr. Analyst

CKE Restaurants, Inc. • Franklin (TN)

On-site
USD 85,000 - 110,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Burlington Stores, Inc. • Beverly (NJ)

On-site
USD 100,000 - 130,000
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Town of Charlotte (NY)

Hybrid
CAD 207,000 - 276,000
Senior Manager, Detection and Response
Senior Manager, Detection and Response

Jobtailor • California (MO)

On-site
USD 200,000 - 260,000
Information Security Manager – Configuration Management
Information Security Manager – Configuration Management

Jobtailor • Minnesota

On-site
USD 150,000 - 190,000