Job Title: Senior Security Engineer (Security Operations & GRC)
Role Overview
Our client is a fast-growing technology company where security is treated as a strategic business function rather than a support organization. They're seeking a Senior Security Operations Engineer to lead key initiatives across Security Operations, Governance, Risk & Compliance (GRC), and incident response while helping mature the organization's overall security posture.
This is a highly visible individual contributor role with broad ownership across detection engineering, security automation, compliance, incident response, and operational security. You'll work closely with Engineering, IT, Legal, and executive leadership to strengthen the company's security capabilities while influencing how security is embedded across the organization.
Key Responsibilities
- Own day-to-day Security Operations, including threat detection, alert triage, threat hunting, and incident response.
- Lead security investigations from initial detection through containment, root cause analysis, customer communications, and post-incident reviews.
- Configure, optimize, and maintain SIEM, SOAR, and Endpoint Detection & Response (EDR) platforms.
- Develop security detections, automation, response playbooks, and operational workflows that improve security effectiveness.
- Drive Zero Trust initiatives across identity, endpoint, and infrastructure security.
- Manage endpoint security policies and enterprise device protection strategies.
- Lead vulnerability management, remediation tracking, and patch governance programs.
- Build and maintain incident response runbooks, on-call procedures, and tabletop exercises.
- Own SOC 1 and SOC 2 audit readiness, including evidence collection, control mapping, and audit coordination.
- Conduct third-party vendor security assessments and support customer security reviews.
- Respond to customer security questionnaires and partner with internal teams on compliance initiatives.
- Administer security awareness training and phishing simulation programs.
- Manage relationships with security vendors, managed service providers, and strategic technology partners.
- Maintain secure web gateway and proxy security policies, including access controls and website governance.
Education & Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
- Extensive experience in Security Operations, Incident Response, or Security Engineering.
- Strong expertise with SIEM, SOAR, and Endpoint Detection & Response technologies.
- Experience leading SOC 1 and/or SOC 2 audit readiness and compliance initiatives.
- Hands-on experience managing vulnerability remediation and operational security programs.
- Experience implementing Zero Trust security principles.
- Strong understanding of endpoint security, identity management, and access governance.
- Experience conducting third-party vendor security assessments.
- Excellent communication skills with the ability to collaborate effectively across technical and business teams.
Preferred Experience
- Experience with CrowdStrike or comparable EDR platforms.
- Experience with Netskope or similar secure web gateway solutions.
- Familiarity with detection engineering and detections-as-code methodologies.
- Experience managing MSSPs and other security service providers.
- Cloud security experience within AWS, Azure, or GCP environments.
- Relevant certifications such as CISSP, GCIH, GCIA, Security+, or similar.
Compensation, Benefits & Perks
- Salary Range: $170,000 - $200,000
- Annual performance bonus.
- Equity participation.
- Comprehensive medical, dental, and vision benefits.
- Opportunity for significant technical ownership and long-term career growth.
- Flexible hybrid work environment.
Why Us
- Own security operations across a growing technology organization where security is a strategic priority.
- Lead initiatives spanning Security Operations, GRC, incident response, compliance, and detection engineering.
- Influence how security is designed, implemented, and continuously improved across the business.
- Collaborate with talented engineering and leadership teams committed to building secure, modern technology.
- Work with a broad range of security technologies while helping shape the organization's long-term security strategy.
- Join a collaborative, high-growth environment where your expertise will have visible, lasting impact.
Applicants must be currently authorized to work in the United States on a full-time basis now and in the future. This position does not offer sponsorship.