Sr. IT Security Engineer (Hybrid)

Belk Ecommerce LLC

Charlotte (NC)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Belk Ecommerce LLC in Charlotte, NC is seeking a Senior Security Engineer to drive security tool deployments, monitoring, and automation across cloud and AI/ML systems. You will lead incident response, threat hunting, and SOC improvements while mentoring the security team.

This role is onsite in Charlotte three days a week. The ideal candidate has 10+ years in IT and Cyber Security, strong experience with NIST CSF/Mitre ATT&CK, and hands-on SIEM/EDR tooling.

Qualifications

  • Bachelor’s degree in Computer Science or related field or equivalent combination of industry related professional experience and education.
  • 10 – 15 years combined experience in IT and Cyber Security.
  • Experience with NIST 2.0 CSF and MITRE ATT&CK frameworks.
  • Hands-on with diverse security control stacks and tools.
  • 5+ years scripting with Python or PowerShell.
  • 5+ years writing SIEM queries, parsers and alerts.

Responsibilities

  • Lead automation development for detection, incident response playbooks, and tool orchestration across SIEM, XDR, EDR, and other tools.
  • Design defensive solutions to secure enterprise AI tools and pipelines against prompt injections and data leakage.
  • Lead incident response, threat hunting, and SOC operational efficiency improvements.
  • Safely deploy AI-powered security tools and agents to streamline threat triage and SOC workflows.
  • Organize, lead, and mentor the security team members.
  • Position is onsite in Charlotte 3 days a week.

Skills

Identity & Access Management
Security Automation & SOAR
Blue Team Leadership
Incident Response Lifecycle
SIEM Platform Management
EDR/XDR Deployment
AI Security & LLM Security
AI Agent Operations
Proactive Threat Hunting
Detection-as-Code
MITRE ATT&CK Mapping
Cloud Infrastructure Security
Vulnerability Management

Education

Bachelor’s degree in Computer Science or related field

Tools

Splunk
Microsoft Sentinel
Elastic
CrowdStrike Falcon
SentinelOne
Palo Alto Cortex XSOAR
Swimlane

Job description

The Sr Security Engineer is responsible for security system deployments, configuration, monitoring, and automation of security tools and processes. The role will also be responsible for security operations, including the protection of cloud infrastructure and AI/ML systems.

Provides support to planning and implementing security controls which safeguard and monitor events for information systems, enterprise applications, cloud environments, outsourced services, and data. Provides Tier II support for security related incidents and issues.

  • Lead automation development for detection, incident response playbooks, and tool orchestration across SIEM, XDR, EDR, and other security and compliance tools.
  • Design defensive solutions to secure enterprise generative AI tools, LLM pipelines, MCPs and autonomous AI agents against prompt injections, data leakage, and unauthorized access.
  • Lead incident response, threat hunting, and SOC operational efficiency improvements.
  • Safely deploy AI-powered security tools and agents to streamline threat triage and SOC workflows.
  • Organize, lead, and mentor the security team members.
  • Position is onsite in Charlotte 3 days a week
Education / Experience Requirements
  • Bachelor’s degree in Computer Science or related field or equivalent combination of industry related professional experience and education
  • 10 – 15 years combined experience working in both IT and Cyber Security.
  • Experience working within the NIST 2.0 CSF and Mitre Att&ck frameworks.
  • Hands-on experience working with diverse security control stacks and tools.
  • 5+ years experience with scripting languages like Python or Powershell.
  • 5+ years experience in writing SIEM queries, parsers and alerts.

Preferred Education & Experience:

  • Incident Response & Forensics: Mastery of the full IR lifecycle—from containment and eradication to root-cause analysis, digital forensics, and post-incident remediation across enterprise environments.
  • SIEM & Log Analytics: Hands-on experience architecting, managing, and optimizing SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic) to write custom detection rules, parser logic, and correlation queries.
  • EDR/XDR Engineering: Expertise in deploying, fine-tuning, and managing Endpoint Detection & Response solutions (e.g., CrowdStrike Falcon, SentinelOne, Microsoft Defender) to minimize false positives and maximize coverage.
  • AI Security & Governance: Hands-on experience evaluating, securing, and monitoring enterprise AI tools, LLM pipelines, and autonomous AI agents against risks like prompt injection, data poisoning, and unauthorized tool execution.
  • AI-Assisted Operations: Practical skill in integrating AI assistants and agents into Blue Team workflows to accelerate threat hunting, log analysis, and alert triage
Knowledge / Skills Requirements
  • Identity & Access Management (IDAM): Deep knowledge of securing IDAM and PAM ecosystems (e.g., Azure AD/Entra ID, Okta, CyberArk), enforcing Zero Trust principles, RBAC, and conditional access policies.
  • Security Automation & SOAR: Proficiency in automating manual operational tasks and incident response playbooks using SOAR tools (e.g., Palo Alto Cortex XSOAR, Swimlane) or custom scripting in Python and PowerShell.
  • Blue Team Leadership: Directing, organizing, and mentoring security operation teams.
  • Incident Response Lifecycle: Managing containment, eradication, forensics, and post-incident remediation.
  • SIEM Platform Management: Architecting and tuning platforms like Splunk, Microsoft Sentinel, or Elastic.
  • EDR/XDR Deployment: Engineering and optimizing agents (CrowdStrike, SentinelOne) to reduce false positives.
  • AI & LLM Security: Securing enterprise AI systems and pipelines against prompt injections and data leakage.
  • AI Agent Operations: Governing and monitoring autonomous AI agents and execution permissions.
  • Proactive Threat Hunting: Hypothesis-driven querying of telemetry to spot undetected adversaries.
  • Detection-as-Code: Managing detection logic and alert rules using Git and CI/CD pipelines.
  • MITRE ATT&CK Mapping: Aligning defensive coverage and gap analysis against known adversary TTPs.
  • Cloud Infrastructure Security: Securing workloads, IAM, and configurations across AWS, Azure, or GCP.
  • Vulnerability Management: Prioritizing asset exposure and orchestrating risk remediation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Town of Charlotte (NY)

On-site
USD 150,000 - 210,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Information Security Analyst - Hybrid
Information Security Analyst - Hybrid

Commscope Holding • Honolulu (HI)

Hybrid
USD 110,000 - 140,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Security Engineer
Security Engineer

SentriLock • Olde West Chester (OH)

On-site
USD 110,000 - 160,000
Security Engineer
Security Engineer

Sentrilock • West Chester Township (OH)

On-site
USD 110,000 - 150,000
IT Security - Sr. Analyst
IT Security - Sr. Analyst

CKE Restaurants, Inc. • Franklin (TN)

On-site
USD 85,000 - 110,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

SentriLock • Northern (KY)

Hybrid
USD 110,000 - 170,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Burlington Stores, Inc. • Beverly (NJ)

On-site
USD 100,000 - 130,000