Senior Security Engineer
$154,000–$231,000 year
RemoteNorth Dakota, United States or Alaska, United States
Job Summary
Lead high-priority incident response and forensic investigations across Windows, macOS, Linux, and AWS environments, serving as the primary escalation point for advanced analysis, containment, recovery, and root cause determination. Drive threat detection and response using GuardDuty, Security Hub, Detective, and SentinelOne while conducting malware analysis, host forensics, and threat hunting to identify attack vectors and persistence mechanisms. Design automated security workflows and AI-assisted playbooks to improve detection accuracy and reduce response times, partnering with IT and DevOps teams to enhance security posture and mentor junior engineers.
Required Qualifications
- 5+ years of cybersecurity experience
- 2+ years in senior Incident Response, Security Operations, Threat Detection, or Digital Forensics roles
- Deep expertise securing and investigating AWS environments
- Experience conducting forensic investigations, evidence collection, log analysis, malware triage, and cloud-based incident investigations
- Strong scripting and automation skills with Python, PowerShell, and/or Bash
- Experience applying AI and ML technologies to security operations
- Strong communication and investigative skills
- Preferred certifications such as AWS Security Specialty, GCIH, GCFA, GCIA, OSCP, or CISSP
- Experience with digital forensics platforms such as AXIOM, F-Response, Timesketch, Volatility, Velociraptor, or other enterprise investigation tools
- Experience with additional EDR/XDR platforms such as CrowdStrike, Microsoft Defender, or Carbon Black
- Expertise building and maintaining SOAR platforms, automated response workflows, and cloud-native security operations
- Experience with AI security technologies including Amazon Bedrock, Microsoft Security Copilot, Google SecOps/Chronicle, or open-source LLM integrations
- Familiarity with multi-account AWS environments, AWS Organizations, CSPM solutions, and cloud security frameworks such as Prowler, Trusted Advisor, or CNAPP platforms
- This is a remote position
- You may occasionally visit a GoDaddy office to meet with your team for events or meetings
- This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands
- GoDaddy is not currently considering candidates for this role in California, Seattle, or NYC
Desired Qualifications
- Experience leveraging AI and machine learning technologies to improve detection, response, and operational efficiency
- Experience with GuardDuty, Security Hub, Detective, CloudTrail, IAM, VPC Flow Logs, and SentinelOne
- Experience with AWS security controls including Config, CloudWatch, S3 logging, and serverless security controls
- Experience with Lambda, Step Functions, and EventBridge
- Experience with AWS-native response capabilities
- Experience with technical reporting and executive presentations
- Experience mentoring junior security engineers
- Experience with cloud-based incident investigations while maintaining chain-of-custody best practices
- Experience with AWS Organizations, CSPM solutions, and cloud security frameworks such as Prowler, Trusted Advisor, or CNAPP platforms
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.