Sr. Security Engineer

HistoSonics, Inc.

Minneapolis (MN)

Hybrid

USD 130,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401(k)
Paid time off

Job summary

HistoSonics, Inc. in Plymouth, MN is seeking a Senior Security Engineer focused on security operations. You will own the organization’s defensive security capabilities, including SIEM, EDR, data loss prevention, and vulnerability management, in a collaborative, multi-site IS& Security team.

The role requires strong incident response leadership and automation skills. Hybrid work arrangement; 7+ years in security operations, with CrowdStrike experience and knowledge of MITRE ATT&CK, ISO 27001, and

Qualifications

  • Bachelor's degree or equivalent with 7+ years in security operations, engineering, or incident response.
  • Design, implement, and administer SIEM with log ingestion, detection rules, and dashboards.
  • Advanced administration of CrowdStrike or comparable endpoint security platforms across Windows and macOS.
  • Lead security incident response end-to-end and manage vulnerability programs.

Responsibilities

  • Design, implement, and administer SIEM platform with log onboarding, retention, and dashboards.
  • Develop and tune detection content aligned to MITRE ATT&CK; document rationale and guidance.
  • Build security automation and workflows using PowerShell and Python.

Skills

Security Operations
Incident Response
PowerShell
Python
Endpoint Security
MITRE ATT&CK
Cloud Security
ISO 27001 / SOC 2
Vulnerability Management
Team Mentorship

Education

Bachelor's degree in information technology, Information Security, Computer Science, or related field

Tools

CrowdStrike

Job description

HistoSonics is a commercial-stage medtech company advancing the Edison® System, a novel non‑invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non‑invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women’s health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties.

We offer an exciting work culture where cutting‑edge science meets real‑world application, and each team member’s contribution is important to our success in ensuring our physicians and their patients get what they need most.

Location

Plymouth, MN

Position Summary (Why This Role Matters)

The Senior Security Engineer who has a focus on security operations is a senior individual contributor within the HistoSonics security operations function and is a member of a larger, multi‑site Information Systems and Security team that supports HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role builds and owns the organization’s defensive security capability, including endpoint detection and response, security information and event management, insider risk management and data loss prevention, and centralized vulnerability management. The Senior Security Engineer provides the primary technical execution behind security operations engagement with the AI and R&D Infrastructure team, a partnership owned by the Senior Director, Information Systems and Security, serves a technical escalation for security incidents, and sets technical standards for the function.

Key Responsibilities (What You’ll Do)
Security Monitoring and Detection Engineering
  • Design, implement, and administer the security information and event management platform, including log source onboarding, retention and licensing, correlation rules, dashboards, and reporting.
  • Develop, tune, and maintain detection content mapped to a recognized adversary behavior framework such as MITRE ATT&CK, and document detection rationale and response guidance.
  • Design and implement security automation and orchestration workflows, and develop supporting scripts and tooling in PowerShell, Python, or comparable languages.
Endpoint, Email, and Threat Protection
  • Own the design, deployment, and administration of the endpoint detection and response platform across Windows, macOS, and server infrastructure, including policy configuration, coverage validation, and response actions.
  • Administer email and messaging security controls in coordination with the System Administration and Network Engineering functions, and conduct proactive threat hunting across endpoint, identity, network, and cloud telemetry.
Insider Risk and Data Protection
  • Lead the implementation and administration of the insider risk management and data loss prevention program, including telemetry sources, monitoring policies, risk indicators, and alert triage.
  • Investigate potential data exfiltration and intellectual property loss events under established procedures and in coordination with Human Resources, Legal, and the Senior Director, Information Systems and Security.
Vulnerability and Threat Management
  • Own centralized vulnerability management across endpoints, servers, cloud workloads, and network infrastructure, including scanner administration, risk‑based prioritization, remediation tracking, and exception handling.
  • Facilitate internal and external penetration testing and security assessments through closure of findings and operationalise threat intelligence into detection and blocking controls.
Incident Response and Operations
  • Serve as the senior technical responder for security incidents, leading triage, investigation, containment, and recovery, and conducting root cause analysis with corrective and preventive actions.
  • Author and maintain security incident response procedures, runbooks, and escalation paths, participate in tabletop exercises, and participate in an on‑call rotation for critical after‑hours support.
  • Define alerting thresholds, response targets, and operational metrics for the function, and report on detection coverage and response performance to leadership.
Leadership and Collaboration
  • Serve as a senior internal escalation point for security operations matters and provide technical mentorship, work review, and knowledge transfer to current and future security operations staff.
  • Serve as the primary security operations resource to the AI and R&D Infrastructure teamand toproduct engineering, providing consultation, design review, and escalation support.
  • Serve as control owner for assigned IT controls, provide audit evidence, partner with the governance, risk, and compliance function on control design and security maturity, and support validation under the HistoSonics Quality Management System.
  • Escalate cross‑organizational governance conflicts, scope disputes, and resourcing trade‑offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement security tooling, including assessment of functionality, integration requirements, and licensing costs.
Required
Qualifications and Skills
  • Bachelor’s degree in information technology, Information Security, Computer Science, or a related field, or equivalent experience, with 7+ years of progressive experience in security operations, security engineering, or incident response.
  • Demonstrated experience designing, implementing, and administering a security information and event management platform, including log ingestion, detection rule development, and tuning.
  • Advanced administration experience with an enterprise endpoint detection and response platform such as CrowdStrike, including policy design, response actions, and alert investigation across Windows and macOS.
  • Demonstrated experience leading security incident response end to end, and owning a vulnerability management program including scanner administration, prioritization, and remediation coordination.
  • Working knowledge of insider risk management or data loss prevention tooling, including the procedural considerations associated with monitoring user activity.
  • Advanced scripting and automation ability in PowerShell, Python, or comparable languages, and working knowledge of cloud security (AWS or Azure), enterprise identity and access management, and network security controls.
  • Working knowledge of a recognized adversary behavior framework such as MITRE ATT&CK, and experience making changes within an environment compliant with ISO 27001 and SOC 2 standards.
Preferred
  • Experience in a regulated industry such as medicaldevice, healthcare, or manufacturing, including quality management system processes and validation.
  • Experience with security orchestration and automation platforms, digital forensics, malware analysis, threat intelligence, and supporting product or connected device security.
  • Relevant industry certifications are a plus.
Key Competencies
  • Strong analytical and problem‑solving skills, with sound judgment, discretion, and composure when responding to security incidents and sensitive investigations, and a bias toward automation and durable documentation.
  • Excellent communication and interpersonal skills, with the ability to explain security risks and trade‑offs to technical and non‑technical audiences, and to prioritize tasks and manage time effectively while working independently and as part of a team.
  • Ability to set technical direction and influence outcomes across teams and departments without direct reporting authority.
Benefits

We offer a comprehensive benefits package for full‑time employees. This includes health, dental, and vision insurance, life, short‑term and long‑term disability insurance, 401(k), paid time off, and more.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

U.S. Work Authorization & Sponsorship

Employer will not sponsor visas for position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Analyst, Governance Risk, and Compliance
Principal Security Analyst, Governance Risk, and Compliance

HistoSonics, Inc. • Minneapolis (MN), Saint Paul (MN)

Hybrid
USD 140,000 - 190,000
Health, dental, vision insurance
401(k) plan
Paid time off and generous benefits
Principal Security Analyst, Governance Risk, and Compliance
Principal Security Analyst, Governance Risk, and Compliance

HISTOSONICS INC • Plymouth (MN)

Hybrid
USD 140,000 - 175,000
Health, dental, and vision insurance
Life insurance
Short-term and long-term disability
+2
Principal System Administrator
Principal System Administrator

HISTOSONICS INC • Plymouth (MN)

Hybrid
USD 150,000 - 185,000
Health insurance
Dental insurance
Vision insurance
+4
Senior IT Support Specialist
Senior IT Support Specialist

HistoSonics, Inc. • Minneapolis (MN)

Hybrid
USD 85,000 - 120,000
Health insurance
Dental insurance
401(k)
Sr. Manager – AI and R&D Infrastructure
Sr. Manager – AI and R&D Infrastructure

HistoSonics, Inc. • Minneapolis (MN)

On-site
USD 140,000 - 190,000
Health, dental & vision insurance
Life and disability insurance
401(k) with company match
+1
Principal Network Engineer
Principal Network Engineer

HistoSonics, Inc. • Minneapolis (MN)

Hybrid
USD 140,000 - 200,000
Health, dental, and vision insurance
401(k) with company match
Paid time off
Principal Network Engineer
Principal Network Engineer

HISTOSONICS INC • Plymouth (MN)

Hybrid
USD 150,000 - 185,000
Health insurance
401(k)
Paid time off
+1
Senior IT Support Specialist
Senior IT Support Specialist

HistoSonics, Inc. • Ann Arbor (MI)

Hybrid
USD 70,000 - 100,000
Health, dental, vision insurance
401(k)
Paid time off
IT Support Specialist
IT Support Specialist

HistoSonics, Inc. • Ann Arbor (MI)

Hybrid
USD 55,000 - 75,000
Health, dental and vision insurance
Life insurance
Short-term disability insurance
+2
Sr. Product Engineer
Sr. Product Engineer

HistoSonics, Inc. • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Health, dental, and vision insurance
401(k)
Paid time off