Job Summary
We are seeking an experienced Lead Security Engineer to serve as the senior technical resource within the security team. This role will provide technical leadership across security operations and incident response while owning security engineering standards and ensuring enterprise security platforms are properly configured, integrated, and optimized. The ideal candidate will have strong experience with security controls, incident investigation and remediation, security tooling, and enterprise security operations.
Key Responsibilities
• Serve as the technical lead for security operations and incident response.
• Assist with the investigation, containment, and remediation of security incidents, including high-severity events.
• Design, implement, maintain, and tune security controls across identity, endpoint, email, network, and SIEM platforms.
• Establish and maintain security engineering standards and best practices.
• Improve security detection quality, response playbooks, and operational processes.
• Maintain accurate technical and operational security documentation.
• Troubleshoot complex security platform and integration issues.
• Ensure security technologies are properly configured, integrated, and optimized to reduce organizational risk.
• Provide escalation leadership for complex security operations and incident response activities.
• Participate in an after-hours on-call rotation and provide security escalation support.
• Collaborate with security, infrastructure, identity, network, and other technology teams to strengthen enterprise security capabilities.
Required Qualifications
• 7-10+ years of experience in security engineering, security operations, or a related cybersecurity discipline.
• Strong hands-on experience with incident response, investigation, containment, and remediation.
• Proven experience designing, implementing, and maintaining enterprise security controls.
• Strong troubleshooting and problem-solving skills.
• Excellent written and verbal communication skills.
• Experience providing technical leadership within security operations or engineering teams.
Preferred Qualifications
• Experience with ServiceNow (SNOW).
• Experience with Palo Alto Firewalls and SASE technologies.
• Experience with Microsoft Defender.
• Experience with Microsoft 365 and Azure security technologies.
• Experience with Microsoft Copilot and other AI tools and technologies.
• Experience with Okta.
• Experience with Proofpoint.
• Experience with Cisco Umbrella.
• Experience with Securonix and/or Microsoft Sentinel.
• Experience with XM Cyber.