Senior Security Engineer
Job Description
Senior Security Engineer is a core technical leadership role in the Security Operations (SecOps) team, focused on designing, automating, and operating enterprise security capabilities across enterprise, cloud, and hybrid environments.
Responsibilities
- Provide strategic leadership for cybersecurity strategies, policies, and frameworks
- Partner with senior stakeholders to align cybersecurity initiatives with organizational goals and objectives
- Stay current on emerging cybersecurity trends, threats, and technologies to deliver expert guidance and recommendations
- Lead SecOps threat hunting across multi-platform operating systems, enterprise cloud environments, virtualized infrastructure, and network environments
- Correlate open-source and proprietary threat intelligence (TTPs) into proactive, baseline, and reactive threat hunts
- Maintain and expand automated hunt dashboards and threat hunting automation frameworks
- Assist with design, implementation, and maintenance of secure network architectures and infrastructure
- Own SIEM/SOAR platform health by maintaining log ingestion pipelines, custom parsers, data normalization models, and feed integrations
- Collaborate cross-functionally to evaluate and select security technologies and solutions
- Serve as a Tier 2 technical escalation point and mentor for Security Analysts
- Support critical Incident Response activities, including root-cause investigations and SecOps On-Call participation
- Investigate security incidents, perform root cause analysis, and implement remediation measures
- Design, build, and tune custom detections using vendor-neutral rule languages and native SIEM/SOAR/EDR logic to reduce false positives while keeping strong detection coverage
- Run automated and manual threat emulation and attack chains using open-source testing frameworks to validate log ingestion, rule efficacy, and security controls
- Support external Red Team engagements and remediate visibility and control gaps
- Build and manage Infrastructure-as-Code (IaC) configurations through version-controlled CI/CD pipelines for security workspaces and validation environments
- Write, maintain, and integrate automation scripts (e.g., Python, PowerShell) and SOAR playbooks to streamline analyst triage and system workflows
- Assist in developing, tuning, and integrating modern AI agent platforms and operational workflows into core SecOps pipelines
Requirements
- Bachelor’s Degree in Computer Science, Information Systems, or a related field (required)
- 5 to 8 years of previous related experience (or an equivalent combination of education, training, and experience)
- Professional certifications such as CISSP, CISM, GIAC, or CCSP (preferred)
- Proficiency administering and engineering Enterprise SIEM, SOAR, EDR, and NDR platforms
- Extensive knowledge of cybersecurity principles, technologies, and best practices
- Expertise writing custom detection logic, complex queries, and log normalization
- Strong understanding of enterprise IT infrastructure: Windows, Linux, Enterprise Cloud (IaaS/PaaS), IAM, and enterprise networking
- Experience writing automation scripts in Python, PowerShell, or Bash
- Proficiency in security incident response, including forensic analysis, malware analysis, and threat intelligence
- Demonstrated experience with threat hunting frameworks (e.g., MITRE ATT&CK) and security validation tools
- Excellent leadership and communication skills, including communicating complex technical concepts to stakeholders at all levels
- Proven ability to lead and mentor junior team members
- Good customer service and time management skills
- Ability to develop solutions for complex problems while referencing established precedents and policies
Technologies
- Security Operations (SecOps)
- SIEM, SOAR, EDR, NDR
- CI/CD
- Infrastructure-as-Code (IaC)
- Python, PowerShell, Bash
- AI workflows
- Windows, Linux
- Enterprise Cloud (IaaS/PaaS)
- Identity & Access Management (IAM)
- MITRE ATT&CK
Work Schedule and Location
- Monday to Friday, 8am to 5pm
- Hybrid schedule: 4 days in office in Wyoming, MI or Atlanta, GA, with 1 day remote
Culture / Equal Employment / Accommodations / Workplace Requirements
- If you work for a Gordon Food Service customer, you must provide a letter of support from your management if selected for the interview process
- Equal Employment Opportunity is a matter of policy at Gordon Food Service, Inc.
- For reasonable accommodation during the application or hiring process, email [email protected] and include “Accommodation Request” in the subject line
- All Gordon Food Service locations are tobacco-free
- Gordon Food Service is a drug-free workplace and conducts pre-employment drug tests