Senior Security Engineer
Guardant Health · Palo Alto, CA · 1 wk ago
Information Technology$130k–$179k/yrFull-time
Duties And Responsibilities
- Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
- Oversee and optimize Managed Detection and Response (MDR), as well as Security Orchestration, Automation, and Response (SOAR), capabilities and related integrations.
- Serve as a technical owner for SIEM operations, including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
- Develop, tune, and maintain high-value Threat Detection content, including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity-based alerts.
- Analyze security events, threat intelligence, and attacker tradecraft to improve detection coverage, validate alert effectiveness, and support incident response investigations.
- Support and participate in Incident Response activities, including triage, investigation, containment, eradication, recovery, evidence collection, and post-incident reviews.
- Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations with other security systems.
- Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
- Build dashboards, metrics, and reports to measure Security Tool health, detection coverage, Vulnerability Management posture, Incident Response effectiveness, and overall security program maturity.
- Evaluate AI-assisted security capabilities for detection, response, vulnerability management, and automation, while helping define how AI systems, agents, and usage are logged, monitored, and assessed for risk.
- Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross-functional partners.
- Stay current on emerging threats, attacker tradecraft, vulnerability trends, Security Tooling, Cloud Security practices, and Security Engineering best practices.
Qualifications
- 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, Detection Engineering, or a related security role.
- Broad hands-on experience administering and improving enterprise security tools.
- Experience supporting Incident Response in a SOC or enterprise security environment.
- Strong experience with SIEM platforms, including log ingestion, alerting, detection content, dashboards, and operational support.
- Experience with EDR platforms, including investigation, containment, policy management, and response workflows.
- Experience with Vulnerability Management platforms and processes, including vulnerability scanning, prioritization, remediation tracking, and reporting.
- Hands-on experience securing and monitoring AWS or other cloud environments.
- Experience working with identity and access logs, preferably including Okta or similar identity platforms.
- Strong understanding of endpoint, cloud, identity, network, SaaS, and infrastructure security telemetry.
- Experience developing documentation, runbooks, playbooks, and repeatable operational procedures.
- Experience modernizing SIEM, Logging, or Security Monitoring architectures.
- Experience with detection engineering frameworks such as MITRE ATT&CK.
- Experience building or managing SOAR workflows, response automation, or security orchestration.
- Experience with cloud security posture management, cloud workload protection, container security, or infrastructure-as-code security tools.
- Experience in healthcare, biotech, life sciences, or other regulated environments a plus.
- Familiarity with compliance and regulatory requirements that influence Security Logging, Monitoring, Vulnerability Management, and Incident Response a plus.
- Understanding of AI and machine-learning use cases in security, including detection, automation, monitoring, and governance considerations.
- Strong written and verbal communication skills, with the ability to explain security risks and technical issues to both technical and non-technical stakeholders.
- AI & Digital Fluency: Demonstrate curiosity, sound judgment, and the ability to critically evaluate and responsibly leverage AI-enabled tools in accordance with company policies, ethical standards, and regulatory requirements to improve the efficiency, effectiveness, and quality of work.