← Back to job listings

Senior Information Security Engineer (Detection, Automation & AI)
Zoox · Foster City, CA, United States
About The Role
In This Role, You Will...
Detection Engineering & SIEM Operations
- Design, build, test, and maintain high-fidelity detection logic within our SIEM platform.
- Map detections to the MITRE ATT&CK framework to ensure comprehensive visibility across threat vectors.
- Continuously tune alerts to minimize false positives and reduce alert fatigue for the operations team.
Automation & Tooling (SOAR & APIs)
- Architect and implement automated playbooks within our SOAR platform to drive down Mean Time to Respond (MTTR).
- Develop custom Python scripts, tools, and integrations leveraging REST APIs to connect disparate security tools and data sources.
- Treat infrastructure and configuration as code, ensuring automated deployments and consistency.
Next-Gen Triage & AI Integration
- Design and implement workflows that leverage LLMs (Large Language Models) to automatically analyze, summarize, and add context to incoming security alerts.
- Build prompt engineering pipelines or agentic workflows that assist analysts during active investigations, drastically cutting down initial triage time.
Incident Response & Cloud Infrastructure
- Act as a senior escalation point for security incidents, guiding the team through containment, eradication, and recovery according to established Incident Response procedures.
- Monitor and secure workloads across AWS and on-premise environments with various operating systems.
- Conduct post-incident reviews to identify root causes and build automated preventions/detections to ensure the same incident doesn't happen twice.
Qualifications
- 8+ years of dedicated experience in Information Security, Security Operations, or DevSecOps engineering roles.
- Deep, hands-on experience with either Splunk (SPL, Enterprise Security) or ElasticSIEM (ES|QL, KQL, Kibana) for log analysis and detection creation.
- Strong proficiency in Python and a proven track record of building security tools, scripts, and automation pipelines via APIs.
- Proven experience designing and maintaining automated playbooks in a modern SOAR platform (e.g., Cortex XSOAR, Tines, etc.)
- Practical experience (or highly advanced personal projects) utilizing LLM APIs (e.g., OpenAI, Anthropic, AWS Bedrock) to ingest, process, or summarize textual data—specifically applied to security logs or triage workflows.
- Solid understanding of core AWS security services (GuardDuty, CloudTrail, IAM, VPC Flow Logs).
- Strong familiarity with industry-standard Incident Response lifecycles (NIST SP 800-61, SANS PICERL). Experience as an Incident Commander, Incident Handler strongly desired.
Bonus Qualifications
- Certifications such as CISSP, GCIA, GCIH, or AWS Certified Security - Specialty.
- Experience with Infrastructure as Code (IaC) tools like Terraform.
- Contributions to the open-source security community (tools, Sigma rules, etc.).
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring