Job Description
The Senior Security Engineer will support day-to-day Security Operations, with a focus on investigating security events and responding to complex security incidents. This person will lead containment, eradication, and recovery efforts across endpoint, cloud, and identity-related incidents and serve as an escalation point for more complex security events.
This is a senior-level individual contributor role requiring strong Security Operations experience, critical thinking, attention to detail, and the ability to communicate effectively in high-pressure situations. The ideal candidate will be able to break down complex technical information and communicate clearly with both technical and non-technical stakeholders.
Requirements:
Strong experience in Security Operations, security investigations, and incident response
Hands-on experience investigating and responding to security events and incidents
Experience supporting containment, eradication, and recovery activities
Experience with security alerts and detections
Experience developing or maintaining security playbooks and/or runbooks
Understanding of Security Operations tooling such as SIEM/SOAR, EDR, email security gateways, and firewalls
Strong critical-thinking and problem-solving skills
Ability to break down complex technical topics and communicate them clearly to technical and non-technical audiences
Strong written and verbal communication skills
Demonstrated leadership within an individual contributor role
Experience mentoring junior team members
Nice-to-Haves:
Experience with detection engineering
Experience with rule or alert tuning
Familiarity with the MITRE ATT&CK framework, including mapping security activity or detections to relevant tactics and techniques
Experience with cloud environments such as Azure, GCP, or AWS
Familiarity with Google Security Operations
Experience contributing to tabletop exercises or security audits
Key Responsibilities
Lead containment, eradication, and recovery efforts for endpoint, cloud, identity, and other security incidents
Serve as an escalation point for complex security events and incidents
Investigate security events and determine appropriate response actions
Contribute to the development and improvement of security playbooks and runbooks
Provide feedback to the Detection team to improve the quality of detections, enrichment, and automated response
Collaborate with cross-functional teams to improve logging visibility and response readiness
Contribute to operational maturity through playbooks, mentoring, tabletop exercises, detections, and audits
Mentor junior team members and help build their Security Operations capabilities
Communicate technical information effectively to both technical and non-technical stakeholders
Notes:
To Vendors
This is a 12%2B month contract to hire opportunity, supporting Corporate Information Security for KTD.
Candidates will be required to be on-site 5 days/week at the BTC (11450 Grooms Road, Blue Ash, OH, 45242).
Preference for local candidates. If not local but can relocate day 1, please indicate in the summary.
This is a senior-level individual contributor role with no direct reports.
Candidates should have directly relevant Security Operations and investigation experience. Lack of relevant hands-on experience will be a disqualifier.
Pre-screen consists of 5 unique questions specific to the role
A max rate has not been specified. Please refer to market rates for this skill set.
| Location | Blue Ash, OH |
| Job Type | Contractor |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder