Security Engineer
- Location
- New York City
- Work type
- Full Time · Remote
- Posted
- 2026-08-03
Job description
WHAT YOU’LL DO 🚀
Monitor, triage, and investigate security alerts across SIEM, EDR, email security, cloud security, identity, and application security tools.
Lead hands-on investigation of security events involving AWS, Okta, endpoints, SaaS platforms, infrastructure, and application logs.
Perform incident response activities: scoping, containment, evidence collection, root cause analysis, remediation support, and post-incident reviews.
Develop and improve detection logic, correlation rules, alert tuning, and use cases across cloud, identity, endpoint, and application layers.
Analyze logs and telemetry from sources such as AWS CloudTrail, GuardDuty, Security Hub, Okta, EDR, WAF, DNS, VPN, and business systems.
Create and maintain incident response playbooks, investigation runbooks, escalation procedures, and operational documentation.
Partner with Infrastructure, IT Operations, and Engineering teams to validate findings, remediate risks, and improve security controls.
Support vulnerability, misconfiguration, and threat investigations by correlating signals from multiple security tools.
Contribute to threat hunting activities based on known attacker techniques, suspicious behavioral patterns, and emerging threats.
Help improve visibility across cloud, endpoint, identity, and application environments.
Support security incident reporting, timelines, post-mortems, and lessons-learned documentation.
Contribute to compliance evidence and operational controls related to SOC 2 and ISO 27001 incident response requirements.
Help automate repetitive investigation and response tasks where practical.
TO SHINE IN THIS ROLE 💥You’ll need:
5+ years of hands-on experience in security operations, incident response, detection engineering, SOC, cloud security, or related technical security roles.
Practical experience investigating security alerts and incidents across cloud, identity, endpoint, and network/application layers.
Strong experience working with SIEM platforms, including log analysis, alert triage, rule tuning, and investigation workflows.
Hands-on experience with EDR tools and endpoint investigation across macOS and/or Windows environments.
Experience investigating identity-related events, ideally using Okta or a comparable IAM/SSO platform.
Solid understanding of common attacker techniques, MITRE ATT&CK, phishing, credential compromise, malware, lateral movement, and cloud misconfiguration risks.
Ability to perform structured incident response: scope the issue, identify impact, coordinate containment, support remediation, and document findings clearly.
Experience writing and maintaining incident response playbooks, detection logic, and investigation runbooks.
Strong analytical mindset with the ability to connect signals across different tools and data sources.
Good communication skills — able to explain technical findings, risk, and recommended actions clearly to both technical and non-technical stakeholders.
Fluent English communication skills, both written and verbal.