Jobs · Information Technology · California

Senior Security Engineer

Guardant Health · Palo Alto, CA · 1 wk ago
Information Technology$130k–$179k/yrFull-time

Duties And Responsibilities

  • Design, implement, operate, and continuously improve enterprise security tools across Endpoint, Cloud, Identity, Network, SaaS, Vulnerability Management, Logging, and Response platforms.
  • Oversee and optimize Managed Detection and Response (MDR), as well as Security Orchestration, Automation, and Response (SOAR), capabilities and related integrations.
  • Serve as a technical owner for SIEM operations, including log source onboarding, data normalization, detection support, performance tuning, cost optimization, and regulatory logging requirements.
  • Develop, tune, and maintain high-value Threat Detection content, including SIEM rules, behavioral analytics, endpoint detections, cloud detections, and identity-based alerts.
  • Analyze security events, threat intelligence, and attacker tradecraft to improve detection coverage, validate alert effectiveness, and support incident response investigations.
  • Support and participate in Incident Response activities, including triage, investigation, containment, eradication, recovery, evidence collection, and post-incident reviews.
  • Provide expertise on EDR tooling including policy configuration, telemetry ingestion, detections, response actions, host containment, and integrations with other security systems.
  • Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.
  • Build dashboards, metrics, and reports to measure Security Tool health, detection coverage, Vulnerability Management posture, Incident Response effectiveness, and overall security program maturity.
  • Evaluate AI-assisted security capabilities for detection, response, vulnerability management, and automation, while helping define how AI systems, agents, and usage are logged, monitored, and assessed for risk.
  • Provide technical leadership, mentorship, and guidance to junior engineers, analysts, and cross-functional partners.
  • Stay current on emerging threats, attacker tradecraft, vulnerability trends, Security Tooling, Cloud Security practices, and Security Engineering best practices.

Qualifications

  • 5+ years of experience in Security Engineering, Security Operations, Incident Response, Vulnerability Management, Detection Engineering, or a related security role.
  • Broad hands-on experience administering and improving enterprise security tools.
  • Experience supporting Incident Response in a SOC or enterprise security environment.
  • Strong experience with SIEM platforms, including log ingestion, alerting, detection content, dashboards, and operational support.
  • Experience with EDR platforms, including investigation, containment, policy management, and response workflows.
  • Experience with Vulnerability Management platforms and processes, including vulnerability scanning, prioritization, remediation tracking, and reporting.
  • Hands-on experience securing and monitoring AWS or other cloud environments.
  • Experience working with identity and access logs, preferably including Okta or similar identity platforms.
  • Strong understanding of endpoint, cloud, identity, network, SaaS, and infrastructure security telemetry.
  • Experience developing documentation, runbooks, playbooks, and repeatable operational procedures.
  • Experience modernizing SIEM, Logging, or Security Monitoring architectures.
  • Experience with detection engineering frameworks such as MITRE ATT&CK.
  • Experience building or managing SOAR workflows, response automation, or security orchestration.
  • Experience with cloud security posture management, cloud workload protection, container security, or infrastructure-as-code security tools.
  • Experience in healthcare, biotech, life sciences, or other regulated environments a plus.
  • Familiarity with compliance and regulatory requirements that influence Security Logging, Monitoring, Vulnerability Management, and Incident Response a plus.
  • Understanding of AI and machine-learning use cases in security, including detection, automation, monitoring, and governance considerations.
  • Strong written and verbal communication skills, with the ability to explain security risks and technical issues to both technical and non-technical stakeholders.
  • AI & Digital Fluency: Demonstrate curiosity, sound judgment, and the ability to critically evaluate and responsibly leverage AI-enabled tools in accordance with company policies, ethical standards, and regulatory requirements to improve the efficiency, effectiveness, and quality of work.

Similar jobs