remote
Staff Security Engineer - SecOps & Threats - 6sense
Security Engineer
Lead advanced security operations, orchestrating threat detection, incident response, and cloud security across AWS environments. Drive automation, SIEM enhancements, and threat intelligence integration to protect enterprise assets and enable proactive defense.
About the role
Key Responsibilities
- Design, implement, and maintain security operations workflows for threat detection, investigation, and response across multi‑cloud environments.
- Lead incident response efforts, coordinating with engineering, product, and compliance teams to contain, remediate, and document security events.
- Develop and automate security tooling using Python, Terraform, and CI/CD pipelines to streamline alert triage, playbook execution, and evidence collection.
- Integrate threat intelligence feeds into SIEM and SOAR platforms, enhancing detection rules and reducing false positives.
- Collaborate with DevSecOps to embed security controls into the software development lifecycle, ensuring secure code, build, and deployment practices.
Requirements
- 10+ years of experience in security engineering, with a focus on threat hunting, incident response, and cloud security.
- Deep expertise in AWS security services (GuardDuty, Security Hub, IAM, KMS) and SIEM/SOAR platforms (Splunk, SentinelOne, Palo Alto Cortex).
- Proficiency in Python scripting, automation frameworks, and infrastructure-as-code tools.
- Strong analytical skills, ability to translate complex security data into actionable insights.
- Excellent communication and leadership abilities, with a track record of driving security initiatives across cross‑functional teams.