Sabre Corporation

Sr. Cyber Security Engineer

Sabre Corporation$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in SOC or threat response roles
  • Proficient with Palo Alto Cortex XSIAM
  • Deep knowledge of Windows OS internals
  • Understanding of Linux file systems and logs
  • Familiar with offensive security techniques.

Responsibilities

  • Conduct rapid host-level triage on enterprise endpoints
  • Analyze Palo Alto Cortex XSIAM telemetry to validate threats
  • Identify adversary techniques across multiple platforms
  • Trace execution paths on Windows and Linux systems
  • Provide actionable intelligence for incident response.

Benefits

  • Flexible work options
  • Comprehensive healthcare coverage
  • Generous PTO and holidays
  • Strong retirement planning support
  • Family-friendly benefits
  • Professional development opportunities
Full Job Description
Sr. Cyber Security Engineer

We are seeking a Sr. Cyber Security Engineer to join our global Cybersecurity team, where innovation knows no borders. This team protects Sabre's critical architecture, cloud environments, and travel technology platforms from emerging threats while enabling secure business innovation. With an inclusive culture and flexible work environment, we work together with boldness, curiosity and commitment so we can all win together.

As a Sr. Cyber Security Engineer, you will focus on the rapid triage, correlation, and validation of security alerts across multi-platform environments to accelerate threat detection and containment. You will evaluate telemetry through both defensive monitoring and an attacker's perspective to trace execution paths and identify host-level weak points. This role requires strong host analysis capabilities, operational proficiency in log correlation tools, and the technical confidence to isolate and neutralize active threats across enterprise systems.

What you'll do
  • Conduct rapid host-level triage on enterprise endpoints and servers following alert detection, evaluating events through an adversary's perspective.
  • Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains, validate threats, and differentiate legitimate administrative behavior from active exploitation.
  • Identify adversary tradecraft, host persistence mechanisms, credential theft attempts, and local privilege escalation vectors across Windows, Linux, and macOS platforms.
  • Analyze Windows and Linux host telemetry, file system architecture, administrative structures, and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging.
  • Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams.


What you'll bring

Required qualifications
  • Minimum 4 years of hands-on security operations center (SOC) or threat response experience.
  • Operational proficiency with Palo Alto Cortex XSIAM for log correlation, threat hunting, and incident triage.
  • Firm understanding of Windows OS internals, file system architecture, and host telemetry to evaluate security alerts and trace execution paths.
  • Solid grasp of Linux file system hierarchies, administrative structures, and native logging mechanisms to investigate server anomalies and host-level misconfigurations.
  • Practical understanding of offensive methodologies, including local host enumeration, credential harvesting techniques, and privilege escalation pathways.


Preferred qualifications
  • 6+ years of experience in a dedicated SOC, Threat Management, Incident Response, or Penetration Testing role.
  • Practical experience conducting penetration tests, security assessments, or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins).
  • Practical familiarity with macOS file system layout, native configuration file formats, and common host persistence vectors.
  • Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks.
  • Professional industry certifications such as OSCP, PNPT, GPEN, GCIH, GCFA, GCFE, CySA+, or equivalent offensive/defensive credentials.


Benefits that support you

We know support looks different for everyone. That is why Sabre offers benefits beyond medical and financial coverage, with programs designed to support your well-being, growth and life outside work:
  • Competitive pay and performance-based bonuses
  • Flexible work options
  • Comprehensive healthcare coverage
  • Generous PTO and holidays
  • Strong retirement planning support
  • Family-friendly benefits
  • Professional development opportunities

Similar Jobs

More Jobs at Sabre Corporation

More Information Technology Jobs

Find similar Sr. Cyber Security Engineer jobs: