Security Engineer III
$208,500–$347,500 year
On-siteSan Jose, California, United States
Job Summary
Design and build the security data lake by ingesting, normalizing, and retaining telemetry from Azure, AWS, SaaS, and endpoint sources to enable rapid threat detection. Write, tune, and version-control detections as code through CI/CD pipelines, automating triage, enrichment, and runbook integration to reduce mean-time-to-respond. Harden cloud environments by defining identity boundaries, network egress controls, and secret management in Terraform modules that enforce least privilege across all tenants. Prioritize and close cloud security posture findings by turning Wiz and audit framework assessments into owned remediation queues. Set direction on detection and tooling adoption while partnering with SRE and Product Engineering to ship production mechanisms rather than advisory guidance.
Required Qualifications
- 5+ years in security engineering, cloud operations, or detection engineering, with recent hands-on ownership of production cloud security work
- Production Terraform experience. You've written and maintained modules other teams consume, and you know why a security control belongs in code rather than in a runbook
- Real operational depth in both Azure and AWS: identity models, logging and audit sources, network boundaries, and where each provider's defaults leave you exposed
- Demonstrated detection building. You've written detections against real telemetry, tuned them against real false positives, and can explain a specific rule you shipped and how you validated it
- Strong cloud security fundamentals: RBAC and least privilege, secret and key management, egress control, and public-exposure prevention
- Fluency in at least one query language for security data (KQL, SQL, or equivalent) and the judgment to know when a query problem is actually a data-model problem
- Scripting and automation ability in Python or a comparable language, enough to build and maintain tooling rather than only configure vendor products
- A track record of shipping production code or infrastructure you can point to. This is a hands-on building role, not an advisory one
Desired Qualifications
- Microsoft Sentinel at production scale: analytics rules, automation rules, ingestion cost management, and multi-workspace design
- Wiz experience, including turning posture and attack-path findings into an owned remediation workflow
- Incident response experience in a cloud environment, on-call or as an investigator
- Security data lake or SIEM migration experience, including cost and retention tradeoffs
- Kubernetes and container security exposure (AKS, EKS) and runtime detection for containerized workloads
- Familiarity with regulated-industry audit expectations (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST) and what auditors want from logging and monitoring controls
- Relevant certifications (Azure or AWS security specialty, GCIA, GCDA, or similar)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.