Staff Security Platform Engineer

Aurora

San Francisco (CA)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Deepstreamtech is seeking a Staff Security Platform Engineer to join our Enterprise Security Engineering team. This role involves ensuring our security tools are effectively operational, continuously tuned, and fully leveraged to protect our cloud environment.

We require a seasoned security operator with extensive experience in enterprise security platforms, capable of leading investigations and proactively hunting threats. If you thrive on mastering security tools and mitigating risks, we want you on our team.

Qualifications

  • 12+ years in enterprise security operations or SOC engineering roles.
  • Expert in administering multiple enterprise security platforms.
  • Strong skills in incident investigations and communicating findings.

Responsibilities

  • Own the operational health and configuration of security tool stack.
  • Conduct proactive threat hunting across security telemetry.
  • Lead investigations into security alerts and incidents.

Skills

Enterprise security operations experience
Security platform administration
Log analysis
Threat hunting
Scripting for automation
Familiarity with MITRE ATT&CK

Tools

CrowdStrike
Splunk
AWS Security Tools

Job description

Requirements
  • 12+ years of hands‑on experience in enterprise security operations, security platform administration, or a senior SOC engineering role — with a career built on deep operational ownership of security tooling rather than software development
  • Expert‑level proficiency administering and operating at least two enterprise security platforms (e.g., CrowdStrike, SentinelOne, Splunk, Panther, Sentinel, Jamf, Kandji/Iru, Puppet, WorkspaceONE, Intune, Zscaler, Okta, Proofpoint, Wiz, osquery), with strong working knowledge across several others
  • Demonstrated ability to tune and optimize security platforms beyond out‑of‑the‑box configurations — writing custom detection logic, adjusting policy sets, and validating control effectiveness
  • Strong log analysis and threat hunting skills: you know how to build a hypothesis, write the query, follow the thread, and know when to escalation
  • Experience conducting thorough incident investigations — triage, containment, root cause analysis, and post‑incident review — and communicating findings clearly to technical and non‑technical stakeholders
  • Ability to assess security control effectiveness: not just "is this tool deployed" but "is it configured correctly, covering the right scope, and generating actionable signal."
  • Comfort working under pressure in ambiguous, fast‑moving situations with competing priorities
  • (Desirable) Scripting ability for automation, log parsing, or workflow improvement (Python, Bash, or similar) — you don't need to be a software engineer, but you can write a script when it saves you an hour
  • (Desirable) Deep familiarity with MITRE ATT&CK as an operational tool for detection gap analysis and threat hunting hypothesis development
  • (Desirable) Experience with AWS security telemetry (CloudTrail, GuardDuty, Security Hub) and integrating cloud signals into a corporate SIEM
  • (Desirable) Familiarity with Zero Trust and identity‑centric security models as they apply to policy enforcement in IAM and endpoint platforms
  • (Desirable) Platform‑specific certifications such as CrowdStrike Certified Falcon Administrator, Splunk Core Certified Power User, or equivalent — or practitioner certifications like GCIH, GCIA, GCFE, or GCFA
What the job involves
  • Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all
  • We're searching for a Staff Security Platform Engineer to join our Enterprise Security Engineering team, reporting to the Technical Lead Manager of Security Engineering
  • Aurora is scaling its autonomous trucking operations, and we need someone who makes our security tools actually work, not just deployed, but deeply configured, continuously tuned, and fully leveraged
  • This role is for the practitioner who has spent their career living inside security platforms: the person who knows their EDR better than the vendor's own support team, who can write a SIEM query from memory, and who instinctively knows when an alert is misfiring and exactly why
  • This is not a software engineering role. It's a role for an elite security operator — someone with the instincts of a seasoned SOC analyst and the technical depth to own the platforms that power detection, response, and protection at enterprise scale
  • If you find deep satisfaction in mastering a tool, closing a coverage gap, or hunting down a threat that nobody else noticed, this role was written for you
  • Own the operational health, configuration, and continuous improvement of Aurora's enterprise security platform stack — including EDR/XDR, MDM, SIEM, DLP, IAM/IGA, DNS security, Email security, and PKI — ensuring each tool is tuned, policy‑complete, and delivering reliable signal
  • Develop and refine detection rules, correlation logic, and alert policies, reducing noise while ensuring Aurora maintains high‑fidelity coverage against real threats
  • Conduct proactive threat hunting across Aurora's security telemetry — forming hypotheses, querying logs, and investigating anomalies before they surface as incidents
  • Serve as the deepest internal expert on Aurora's enterprise security tooling, acting as the escalation point for complex platform issues, misconfigurations, and detection failures
  • Participate in the team's on‑call rotation, leading deep‑dive investigations into security alerts and incidents and driving triage, containment, and root cause analysis
  • Continuously audit and validate that existing security controls are configured to actually do what they're supposed to do — not just deployed and forgotten
  • Maintain operational runbooks, detection documentation, and platform configuration records, ensuring the team can operate consistently and scale institutional knowledge
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Aurora • San Francisco (CA)

On-site
USD 150,000 - 200,000
Staff Security Platform Engineer
Staff Security Platform Engineer

Aurora Innovation • San Francisco (CA)

On-site
USD 189,000 - 274,000
Annual bonus
Equity compensation
Health benefits
Staff Security Platform Engineer
Staff Security Platform Engineer

Aurora • Seattle (WA)

On-site
USD 189,000 - 274,000
Annual bonus
Equity compensation
Comprehensive benefits package
Staff Security Platform Engineer
Staff Security Platform Engineer

Aurora • Mountain View (CA)

On-site
USD 189,000 - 274,000
Bonus
Equity compensation
Health benefits
Staff Security Platform Engineer
Staff Security Platform Engineer

3M HEALTHCARE • Mountain View (CA)

On-site
USD 189,000 - 274,000
Annual bonus
Equity compensation
Flexible working environment
Staff Security Platform Engineer
Staff Security Platform Engineer

Aurora • Pittsburgh

On-site
USD 171,000 - 247,000
Annual bonus
Equity compensation
Comprehensive benefits
Staff Security Engineer
Staff Security Engineer

Aurora • Pittsburgh

On-site
USD 171,000 - 247,000
Annual bonus
Equity compensation
Comprehensive benefits
Staff Security Engineer, Cloud Detection & Response
Staff Security Engineer, Cloud Detection & Response

Pittsburgh Robotics Network • Pittsburgh

Hybrid
USD 171,000 - 273,000
Annual bonus
Equity compensation
Hybrid work environment
Staff Security Engineer, Cloud Detection & Response
Staff Security Engineer, Cloud Detection & Response

Auror Limited • Mountain View (CA)

On-site
USD 189,000 - 303,000
Hybrid work model
Bonus and equity
Benefits package
Staff Security Engineer
Staff Security Engineer

Aurora • Seattle (WA)

On-site
USD 189,000 - 274,000
Annual bonus
Equity compensation
Comprehensive benefits package