Information Security Engineer
Job Description
At SkyWest Airlines, you will help strengthen cybersecurity across the organization by implementing and improving security technologies and operational capabilities. This onsite role in Saint George, UT supports practical, measurable security outcomes through security engineering, security operations support, automation, incident response, and continuous improvement.
What you’ll work on
- Implement, maintain, and improve cybersecurity controls and technologies across the environment.
- Support the evaluation, testing, deployment, and ongoing use of security solutions.
- Assist with security reviews for infrastructure, network, and application projects.
- Develop and maintain security standards, procedures, technical documentation, and operational runbooks.
- Identify opportunities to enhance the organization’s security posture through technology and process improvements.
- Investigate security alerts, suspicious activity, and potential incidents.
- Participate in incident containment, response, recovery, and lessons-learned activities.
- Support forensic analysis, including evidence collection and documentation when required.
- Develop and maintain incident response procedures and operational playbooks.
- Collaborate with technical teams to resolve security issues and improve response readiness.
Automation, integrations, and AI-enabled analysis
- Design, implement, and maintain automation that improves security operational efficiency.
- Develop and support integrations between security and operational platforms.
- Build and maintain SOAR (Security Orchestration, Automation, and Response) workflows and playbooks.
- Automate repetitive security tasks, including alert enrichment, ticket creation, and response actions where appropriate.
- Measure the value and effectiveness of automation and recommend further improvements.
- Evaluate and use approved AI capabilities to improve security analysis, investigation, and response.
- Develop responsible AI-assisted workflows for relevant security use cases and validate AI-generated findings before operational use.
- Monitor emerging AI-related threats, risks, and defensive capabilities.
- Identify practical ways AI can improve quality, consistency, speed, or visibility.
Monitoring, investigation support, and continuous improvement
- Assist with monitoring and analysis of security events and telemetry.
- Tune security alerts and controls to improve effectiveness and reduce unnecessary noise.
- Contribute to threat hunting, detection improvement, and security tool optimization.
- Develop operational dashboards, reporting, and documentation as needed.
- Research emerging threats, security trends, and industry practices, and recommend practical solutions that improve efficiency, visibility, resilience, and security outcomes.
- Own assigned initiatives and drive them through completion.
- Share knowledge and contribute to team documentation and operational maturity.
Required experience
- Minimum 3 years of related information security experience.
- Working knowledge of security operations, incident response, and security monitoring concepts.
- Experience administering, supporting, or integrating enterprise security technologies.
- Experience with scripting, automation, APIs, or workflow orchestration.
- Understanding of endpoint, network, email, web application, and infrastructure security concepts.
- Ability to troubleshoot complex technical issues and communicate findings clearly.
- Ability to work independently, manage priorities, and collaborate across technical teams.
Technologies you may work with
- SOAR (Security Orchestration, Automation, and Response)
- EDR (Endpoint Detection and Response)
- SentinelOne
- Illumio
- Cloudflare
- ServiceNow
Benefits
- 401(k) match
- Performance Rewards and Profit Sharing
- Health care - medical, dental, and vision
- Discounted worldwide flight benefits, including discounts and free standby travel on available open seating for you and your family with all four of our major airlines (Delta, United, Alaska, and American)
Preferred experience
- Endpoint Detection and Response (EDR) platforms.
- Firewall, network security, microsegmentation, or Zero Trust technologies.
- Web application security and Web Application Firewall (WAF) technologies.
- Security orchestration, automation, and response platforms.
- Threat hunting, digital forensics, or incident response investigations.
- Security platform integrations, API-based workflows, or automated response actions.
- Enterprise security tools such as SentinelOne, Illumio, Cloudflare, or ServiceNow.
Measures of success
- Security improvements are implemented effectively and maintained reliably.
- Manual operational effort is reduced through useful, sustainable automation.
- Security incidents and alerts are investigated and addressed promptly and thoroughly.
- Security tools, integrations, and workflows deliver measurable operational value.
- Documentation, playbooks, and procedures remain accurate and usable.
- Risks and improvement opportunities are identified proactively and driven toward resolution.
Physical and other requirements
- Possess a valid, unrestricted, state-issued driver’s license
- Ability to sit and work at a computer for extended periods of time
- Ability to travel, when required
- Legally authorized to work in the United States for any employer without sponsorship
- Pass a background check
- This is not a Department of Transportation safety-sensitive position
Additional interview requirement: This job posting may have an additional phone/video interview requirement. Please monitor your email and junk folder for additional instructions.