Senior Security Engineer

Jobtailor

Palo Alto (CA)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior Security Engineer in Palo Alto to design, operate, and continuously improve enterprise security tooling across Endpoint, Cloud, Identity, and Network domains. You will own SIEM/EDR content, support incident response, and advance vulnerability management while collaborating with cross‑functional teams.

Ideal candidates bring 5+ years in security operations, strong SIEM/EDR experience, and hands‑on cloud security expertise (AWS, Okta).

Qualifications

  • 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, or related security role.
  • Broad hands‑on experience administering and improving enterprise security tools.
  • Experience supporting Incident Response in a SOC or enterprise security environment.
  • Strong experience with SIEM platforms, including log ingestion, alerting, detection content, dashboards, and operational support.
  • Experience with EDR platforms, including investigation, containment, policy management, and response workflows.
  • Experience with Vulnerability Management platforms and processes, including vulnerability scanning, prioritization, remediation tracking, and reporting.
  • Hands‑on experience securing and monitoring AWS or other cloud environments.
  • Experience working with identity and access logs, preferably including Okta or similar identity platforms.

Responsibilities

  • Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
  • Oversee and optimize MDR and SOAR capabilities and related integrations.
  • Serve as a technical owner for SIEM operations, including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
  • Develop, tune, and maintain high‑value Threat Detection content, including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity‑based alerts.
  • Analyze security events, threat intelligence, attacker tradecraft to improve detection coverage, validate alert effectiveness, and support incident response investigations.
  • Support and participate in Incident Response activities, including triage, investigation, containment, eradication, recovery, evidence collection, and post‑incident reviews.
  • Support security investigations involving endpoint activity, cloud events, identity logs, network telemetry, SaaS activity, and other relevant data sources.
  • Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations with other security systems.
  • Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
  • Manage threats from AWS and cloud‑native environments, including monitoring and responding to CloudTrail, VPC Flow Logs, workload logs, IAM activity, container activity, and cloud security findings.
  • Build dashboards, metrics, and reports to measure Security Tool health, detection coverage, Vulnerability Management posture, Incident Response effectiveness, and overall security program maturity.
  • Develop and maintain documentation, runbooks, incident response playbooks, engineering standards, and tool administration procedures.
  • Evaluate AI‑assisted security capabilities for detection, response, vulnerability management, and automation, while helping define how AI systems, agents, and usage are logged, monitored, and assessed for risk.
  • Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross‑functional partners.
  • Stay current on emerging threats, attacker tradecraft, vulnerability trends, Security Tooling, Cloud Security practices, and Security Engineering best practices.

Skills

SIEM platforms
EDR platforms
Threat detection
Incident Response
Cloud security

Tools

MDR
SOAR
AWS
Okta

Job description

Responsibilities
  • Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
  • Oversee and optimize Managed Detection and Response (MDR), as well as Security Orchestration, Automation, and Response (SOAR), capabilities and related integrations.
  • Serve as a technical owner for SIEM operations, including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
  • Develop, tune, and maintain high-value Threat Detection content, including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity-based alerts.
  • Analyze security events, threat intelligence, and attacker tradecraft to improve detection coverage, validate alert effectiveness, and support incident response investigations.
  • Support and participate in Incident Response activities, including triage, investigation, containment, eradication, recovery, evidence collection, and post-incident reviews.
  • Support security investigations involving endpoint activity, cloud events, identity logs, network telemetry, SaaS activity, and other relevant data sources.
  • Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations with other security systems.
  • Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
  • Manage threats from AWS and cloud-native environments, including monitoring and responding to CloudTrail, VPC Flow Logs, workload logs, IAM activity, container activity, and cloud security findings.
  • Build dashboards, metrics, and reports to measure Security Tool health, detection coverage, Vulnerability Management posture, Incident Response effectiveness, and overall security program maturity.
  • Develop and maintain documentation, operational runbooks, incident response playbooks, engineering standards, and tool administration procedures.
  • Evaluate AI-assisted security capabilities for detection, response, vulnerability management, and automation, while helping define how AI systems, agents, and usage are logged, monitored, and assessed for risk.
  • Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross‑functional partners.
  • Stay current on emerging threats, attacker tradecraft, vulnerability trends, Security Tooling, Cloud Security practices, and Security Engineering best practices.
Requirements
  • 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, Detection Engineering, or a related security role.
  • Broad hands‑on experience administering and improving enterprise security tools.
  • Experience supporting Incident Response in a SOC or enterprise security environment.
  • Strong experience with SIEM platforms, including log ingestion, alerting, detection content, dashboards, and operational support.
  • Experience with EDR platforms, including investigation, containment, policy management, and response workflows.
  • Experience with Vulnerability Management platforms and processes, including vulnerability scanning, prioritization, remediation tracking, and reporting.
  • Hands‑on experience securing and monitoring AWS or other cloud environments.
  • Experience working with identity and access logs, preferably including Okta or similar identity platforms.
  • Strong understanding of endpoint, cloud, identity, network, SaaS, and infrastructure security telemetry.
  • Experience developing documentation, runbooks, playbooks, and repeatable operational procedures.
Core Competencies

Demonstrates expertise in Security Engineering and Operations, with a strong focus on SIEM and EDR platforms, Vulnerability Management, and Incident Response. Proficient in developing detection content, managing cloud security, and providing technical leadership in security practices.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
IT Security Engineer
IT Security Engineer

Veriipro • Los Angeles (CA)

On-site
USD 70,000 - 90,000
Senior Security Engineer
Senior Security Engineer

Recru • Houston (TX)

On-site
USD 120,000 - 170,000
Senior Security Analyst
Senior Security Analyst

Jobtailor • Seattle (WA)

On-site
USD 150,000 - 180,000
Security Engineer
Security Engineer

RouteOne • Farmington Hills (MI)

On-site
USD 85,000 - 115,000
Security Engineer – Infrastructure
Security Engineer – Infrastructure

Jobtailor • California (MO)

On-site
USD 140,000 - 180,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Sandy (UT)

On-site
USD 110,000 - 170,000
Cyber Security Engineer
Cyber Security Engineer

Beta Eight • Hicksville (NY)

On-site
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

Jobtailor • Pittsburgh

On-site
USD 120,000 - 180,000