Senior Cybersecurity Engineer
The job description
Tech stack. AWS and Azure security services, Terraform, Kubernetes security controls, Wiz or Prisma Cloud CSPM, Splunk, Python, Sigma and YARA for threat hunting, cloud audit logging pipelines
About the role
You will be a senior individual contributor on the detection and response team of a cloud infrastructure provider running multi-cloud production at significant scale. The team owns how the organization finds intruders, from telemetry pipelines to finished detections, and you will be expected to lead the hardest investigations personally. You will design detection strategy, review the work of mid-level engineers, and represent security in architecture discussions with platform teams. This role matters because you set the technical bar for intrusion detection across the whole company, and the quality of your detections determines whether attackers are caught in minutes or dwell undetected for months.
What you will achieve
- Lead end-to-end response for high-severity incidents, from initial containment through verified root cause, with thorough postmortems shipped within 5 business days of closure.
- Design and deploy more than 20 high-fidelity detections per quarter across cloud and endpoint telemetry, each shipped with documented tuning rationale and false positive analysis.
- Drive cloud misconfiguration findings down 70 percent by codifying preventive guardrails directly into the Terraform modules every team builds from.
- Mentor two to three engineers to full on-call readiness through detection reviews, shadow rotations, and structured incident debriefs after every major event.
- Cut alert noise 40 percent by retiring low-value legacy rules and re-tuning the noisiest data sources in partnership with their engineering owners.
What you will bring
Must-haves
- 5 to 8 years in security engineering, detection engineering, or incident response roles carrying real production responsibility.
- Deep knowledge of AWS or Azure IAM models, logging architectures, and network security controls.
- Proven record writing detections in SIEM or EDR query languages that survive contact with messy, high-volume production data.
- Threat hunting experience using frameworks like MITRE ATT&CK and the Cyber Kill Chain to drive testable hypotheses.
- Infrastructure as code skills with Terraform or CloudFormation sufficient to build and maintain security guardrails.
- Comfort leading incidents under genuine pressure and writing crisp, blameless postmortems that drive lasting fixes.
- Ability to explain complex attack chains to platform engineers and influence their roadmaps without formal authority.
Nice-to-haves
- GCIH, GCIA, or a cloud security specialty certification.
- YARA or Sigma rule development experience shared with the community or across internal teams.
- Background in digital forensics or malware analysis that deepens investigation quality.
- Experience building telemetry pipelines or detection-as-code workflows.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta