Skip to content
← Back to job listings

Senior Information Security Engineer (Detection, Automation & AI)

Zoox · Foster City, CA, United States

CybersecuritySenior LevelExternal listingfull-time4 days ago

About The Role

In This Role, You Will...

Detection Engineering & SIEM Operations

  • Design, build, test, and maintain high-fidelity detection logic within our SIEM platform.
  • Map detections to the MITRE ATT&CK framework to ensure comprehensive visibility across threat vectors.
  • Continuously tune alerts to minimize false positives and reduce alert fatigue for the operations team.

Automation & Tooling (SOAR & APIs)

  • Architect and implement automated playbooks within our SOAR platform to drive down Mean Time to Respond (MTTR).
  • Develop custom Python scripts, tools, and integrations leveraging REST APIs to connect disparate security tools and data sources.
  • Treat infrastructure and configuration as code, ensuring automated deployments and consistency.

Next-Gen Triage & AI Integration

  • Design and implement workflows that leverage LLMs (Large Language Models) to automatically analyze, summarize, and add context to incoming security alerts.
  • Build prompt engineering pipelines or agentic workflows that assist analysts during active investigations, drastically cutting down initial triage time.

Incident Response & Cloud Infrastructure

  • Act as a senior escalation point for security incidents, guiding the team through containment, eradication, and recovery according to established Incident Response procedures.
  • Monitor and secure workloads across AWS and on-premise environments with various operating systems.
  • Conduct post-incident reviews to identify root causes and build automated preventions/detections to ensure the same incident doesn't happen twice.

Qualifications

  • 8+ years of dedicated experience in Information Security, Security Operations, or DevSecOps engineering roles.
  • Deep, hands-on experience with either Splunk (SPL, Enterprise Security) or ElasticSIEM (ES|QL, KQL, Kibana) for log analysis and detection creation.
  • Strong proficiency in Python and a proven track record of building security tools, scripts, and automation pipelines via APIs.
  • Proven experience designing and maintaining automated playbooks in a modern SOAR platform (e.g., Cortex XSOAR, Tines, etc.)
  • Practical experience (or highly advanced personal projects) utilizing LLM APIs (e.g., OpenAI, Anthropic, AWS Bedrock) to ingest, process, or summarize textual data—specifically applied to security logs or triage workflows.
  • Solid understanding of core AWS security services (GuardDuty, CloudTrail, IAM, VPC Flow Logs).
  • Strong familiarity with industry-standard Incident Response lifecycles (NIST SP 800-61, SANS PICERL). Experience as an Incident Commander, Incident Handler strongly desired.

Bonus Qualifications

  • Certifications such as CISSP, GCIA, GCIH, or AWS Certified Security - Specialty.
  • Experience with Infrastructure as Code (IaC) tools like Terraform.
  • Contributions to the open-source security community (tools, Sigma rules, etc.).

This is an external listing. JobSpring does not represent or verify the employer. Report this listing