Information Security Engineer
Job Description
In the IT Security organization at Intuitive Surgical, this role administers and optimizes DLP controls, manages EDR operations and incident response orchestration, and supports zero trust network access enforcement across endpoints, cloud, and network environments.
Key Responsibilities
- Administer, tune, and maintain DLP policies and rules within enterprise DLP and SASE/CASB platforms to prevent unauthorized data exfiltration across endpoints, cloud applications, and network egress points.
- Deploy, configure, and troubleshoot EDR agents across Windows, macOS, and Linux to ensure consistent sensor health, policy enforcement, and telemetry collection.
- Build and maintain SOAR-driven automated incident response and orchestration workflows to support faster alert triage, enrichment, containment, and escalation.
- Coordinate with Network Security to implement and enforce ZTNA policy controls, aligning least-privilege access with zero trust architecture principles.
- Investigate and respond to DLP alerts, conduct root cause analysis, classify data at risk, coordinate with business stakeholders on policy exceptions, and document findings for compliance and audit needs.
- Triage and classify endpoint security events by severity and business impact, correlating telemetry from EDR, SIEM, and DLP systems to identify threats and data exposure risks.
- Perform endpoint troubleshooting across Windows, macOS, and Linux, including agent deployment issues, policy conflicts, OS-specific behavioral anomalies, and sensor communication failures.
- Develop and refine operational metrics and dashboards in Elasticsearch to track DLP policy effectiveness, endpoint coverage gaps, automation ROI, and incident response performance.
- Collaborate with Detection Engineering to create and tune SIEM detection rules addressing DLP bypass techniques, EDR evasion, and insider threat indicators.
- Support Incident Response and Investigations teams during escalated security events by providing endpoint forensic data, DLP event context, and automation support throughout the incident lifecycle.
- Conduct and support internal security investigations, including insider threat cases, policy violations, and unauthorized data handling, using DLP, EDR, and SIEM platforms for evidence collection and forensic analysis.
- Maintain strict confidentiality and discretion when handling sensitive investigation materials, personnel matters, and privileged findings throughout the investigative lifecycle.
Required Qualifications
- Minimum 2 years of experience.
- Hands-on experience administering and tuning enterprise DLP and SASE/CASB solutions across endpoint, cloud, and network enforcement points.
- Experience deploying, managing, and troubleshooting EDR platforms across Windows, macOS, and Linux.
- Demonstrated competence in endpoint troubleshooting across Windows, macOS, and Linux, including agent lifecycle management, OS-level diagnostics, and policy conflict resolution.
- Understanding of OS internals for Windows, macOS, and Linux, including file systems, process management, registry/plist configuration, logging subsystems, and kernel-level behaviors relevant to security tooling.
- Working knowledge of ZTNA concepts and technologies, including identity-aware access controls, micro-segmentation, and least-privilege network policies.
- Experience building security automation and orchestration workflows using SOAR platforms for incident triage, enrichment, and response.
- Familiarity with SIEM platforms and Elasticsearch for log analysis, alert correlation, and dashboard development.
- Strong communication skills to convey technical findings to IT teams, engineering stakeholders, and business partners in a matrixed organization.
- Demonstrated ability to handle sensitive and confidential information with discretion, including investigation findings, personnel data, and legal hold materials.
- Investigative mindset: attention to detail, methodical evidence handling, objectivity, and the ability to construct a factual narrative from disparate data sources.
- Degree in a technical related field (or additional related experience).
Technologies
- DLP, SASE/CASB, EDR, SOAR
- ZTNA, Elasticsearch, SIEM
- Windows, macOS, Linux
Location and Schedule
- Location: Peachtree Corners, GA, United States (onsite)
- Shift: Day
- Workplace type: Set schedule. Onsite weekly, with the percentage of onsite work defined by the leader.
Compensation
- Salary range: USD 124,200 - 210,300 per yearly
- Base compensation range (Region 1): $146,100 USD - $210,300 USD
- Base compensation range (Region 2): $124,200 USD - $178,800 USD
Preferred Skills and Experience
- Experience working within a SOC, incident response, or DLP operations function supporting enterprise-level environments.
- SANS/GIAC certifications strongly preferred (e.g., GCFE, GCFA, GCED, GCIH, GCIA, GDSA, or GREM). Other certifications such as CISSP or CompTIA Security+ are a plus.
- Experience operating across a mature enterprise security stack spanning EDR, DLP, SASE/CASB, SOAR, SIEM, ZTNA, next-generation firewalls, identity providers, and email security gateways.
- Demonstrated experience developing automated playbooks for DLP incident handling, endpoint isolation, or threat enrichment workflows.
- Understanding of insider threat detection methodologies, data classification frameworks, and regulatory requirements relevant to medical device or healthcare organizations (e.g., HIPAA, FDA).
- Prior experience conducting or supporting workplace investigations, forensic examinations, or e-discovery processes in a corporate environment.
- Familiarity with chain-of-custody procedures, legal hold requirements, and evidence preservation standards.
- Prior systems administration experience across Windows, macOS, or Linux, including working knowledge of Active Directory, group policy, endpoint management, and OS-level security hardening.
Additional Information
- Due to the nature of the business and the role, Intuitive and/or its customer(s) may require proof of vaccination against certain diseases (including COVID-19), depending on role requirements.
- Intuitive is an Equal Opportunity Employer.
- U.S. Export Controls Disclaimer: Some roles may be subject to U.S. export controls for prospective employees who are nationals from countries currently on embargo or sanctions status.
- Accommodation & Accessibility Notice: Intuitive provides reasonable accommodations to qualified individuals with disabilities. For assistance during application or interview processes, contact [email protected].