Sr. Security Engineer, Threat Detection and Response

Cypress HCM

United States

On-site

USD 174,000 - 190,000

Full time

30 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Cypress HCM is seeking a senior Threat Detection and Response engineer in the United States to lead investigations, build detection models, and mentor teammates on the TDR team. You will design and optimize security capabilities, partner with Legal, Privacy, and Engineering, and help coordinate incident response across the organization.

You should bring 5+ years in security operations, strong Python/SQL/Pandas skills, and familiarity with Elasticsearch and AWS services.

Qualifications

  • 5+ years in security operations including detection engineering and incident response.
  • Proficiency in Python; SQL and Pandas are frequently used.
  • Familiarity with Elasticsearch preferred; AWS services experience helpful.
  • Self-motivated problem-solver able to work independently.
  • Ability to lead in complex situations through influence.

Responsibilities

  • Perform investigations of security incidents using forensics and data analytics.
  • Develop detection models and automation to identify threats at scale.
  • Hunt for threats in corporate and production environments.
  • Collaborate with Engineering, Legal, and Privacy for large-scale response.
  • Identify gaps in logging and detection, driving visibility improvements.
  • Support and mentor team members on threat detection and incident response.

Skills

Python
SQL
Pandas
Threat hunting
Incident response

Tools

Elasticsearch
AWS
EC2
S3
Lambda

Job description

  • The Threat Detection and Response team (TDR) is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity.
  • This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response.
  • The Difference You Will Make:
  • You will be a key member of our growing Threat Detection & Response (TDR) team.
  • You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents.
  • You will partner with cross-functional partners across the company to improve the overall security driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems.
Description
  • The Threat Detection and Response team (TDR) is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the incident lifecycle. This is the front-line team that detects, investigates, and responds to internal & external security threats and malicious activity.
  • This is a key role to help define and execute our vision for threat detection and incident response capabilities and process while mentoring other team members. As a senior engineer on the team, you will have direct impact building, optimizing, and growing securing capabilities as you help deliver world-class threat detection and incident response.
  • The Difference You Will Make:
  • You will be a key member of our growing Threat Detection & Response (TDR) team.
  • You will get an opportunity to define and execute on novel approaches to detecting, containing and mitigating threats and incidents.
  • You will partner with cross-functional partners across the company to improve the overall security driven by learnings and root cause analysis of investigations and incidents resulting in removal of entire classes of problems.
Duties
  • Perform investigations of security incidents using your knowledge of digital forensics and data analytics.
  • Use your coding, data analytics and investigation skills to hunt, detect and respond to threats.
  • Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale.
  • Hunt for threats in our corporate and production environments to proactively identify anomalous activity.
  • Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with partner teams to carry out complex investigations.
  • Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
  • Collaborate well with cross-functional partner teams, such as Legal, Privacy, and Engineering for efficient, large-scale response.
Requirements
  • 5+ years of hands-on in-depth knowledge and technical experience in security operations including detection engineering, threat hunting, incident response, digital forensics, threat intelligence, threat hunting, and/or detection engineering.
  • Proficiency in Python or other scripting language. We also use SQL and Pandas frequently.
  • Familiarity with Elasticsearch is preferred.
  • Self-motivated and creative problem-solver able to work independently with minimal guidance.
  • Ability to lead people in complex, ambiguous situations through influence and not authority.
  • Ability to work calmly and collaboratively in critical high-stress situations with expediency.
  • Outstanding organizational, prioritization, and multitasking skills.
  • Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the threat landscape.
  • Experience automating security detection and response.
  • Experience in AWS services (EC2, S3, Lambda, RDS) preferred
  • We are not focused on specific tools but we often use Python, AWS, SQL, and more
Compensation
  • $126.56-137.93/hr W-2
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Security Engineer, Insider Threat Detection & Response
Sr. Security Engineer, Insider Threat Detection & Response

Cypress HCM • United States

On-site
USD 169,000 - 190,000
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

samsara • United States

Hybrid
USD 150,000 - 190,000
Professional development stipend
Comprehensive health coverage
Parental leave plans
Security Tools Engineer
Security Tools Engineer

Total Quality Logistics • Cincinnati (OH)

On-site
USD 95,000 - 135,000
Performance bonus
Comprehensive benefits package
Health, dental, and vision coverage
+1
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Senior Threat Detection Engineer
Senior Threat Detection Engineer

ManpowerGroup Global, Inc. • New York (NY)

On-site
USD 65,000 - 70,000
Medical plans
Dental plan
Vision plan
+4
Detection Engineer/Threat Hunter
Detection Engineer/Threat Hunter

Partner Forces LLC • Arlington (VA)

On-site
USD 110,000 - 140,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Senior Detection Engineer (Next-Gen Threat Hunter)
Senior Detection Engineer (Next-Gen Threat Hunter)

Socket.dev • Longmont (CO)

On-site
USD 140,000 - 175,000
Detection & Response Engineering Manager
Detection & Response Engineering Manager

InfraTech Solutions • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan