Sr. Cloud Cybersecurity Engineer
Durham, NC - USA
Job Summary
The Basics:
The Senior Cloud Cybersecurity (CCS) Detection and Response Engineer will collaborate with Detection Security and Software Engineers to proactively defend Tanium Clouds services. You will be an integral part of the Tanium Cloud security engineering processes responsible for the design implementation and operation of preventative detective and responsive controls toidentify assess and counter risks and threats beforeimpactingTanium Cloud.
Whatyoulldo:
- Build andoperateTanium Clouds detection and response engineering in Azure AWS and Kubernetes for detections analysis and responses as automation as code using DevOps methodologies
- Continuously evaluate and enhance the design and effectiveness of Cloud and Kubernetes security measures and establish an ongoing program to advance security and close gaps in our defensive posture.
- Proactively characterize unauthorized activity and malicious behaviors in our cloud and container infrastructure and systems through code testing and automation
- Develop tailored detection policies perform testing and implement automation to observe evaluate enhance and review security information using SecDataOps and best practices.
- Proactively integrate the latest security threats vulnerabilities and industry trends to enhance security detection measures and generate intelligence driven hunts.
- Work together with the engineering IT and other security groups to create solutions that are expandable and adaptable to protect Tanium Cloud against threats ranging from low-level actors to national cyber-threat agents.
- Build cultivate and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the teams work
- Be on periodic on-call for triage of critical events from detections and systems
Werelooking for someone with:
Education:
- Bachelors degree or equivalent experience
- Cloud Security IT Security or related technical field preferred
Locality
- U.S. Candidates:In accordance withUnited States government customer requirements applicants for this role must be a U.S. citizen national or residentpursuant to8 U.S.C. 1101(a)(20) and 8 U.S.C. 1324b(a)(3)
OR
- Canadian Candidates:In accordance withCanadian government customer requirements applicants for this role must undergo personnel security screening andmaintainProtected B reliability status
Cloud Detection Engineering Experience
- 5-7 years of experience in cloud security event prevention detection response for public cloud systems ( Azure) within a DevOps environment
- 3 years of hands-on experience in Kubernetes environment logging and runtime security for sensitive container workloads preferably on AKS and EKS
- Experience in detection and response engineering methodologies such as building detection cases proactively identify known and unknown cyber threats advisory behaviors
- Experience in using security query or analytic tools for security data analysis such as SQL KQL or SPL
- Build and improve security playbooks and runbooks for automating security detection and response
- Solid understanding of modern attacker tactics techniques and procedures (TTPs) against Kubernetes Container Serverless Linux host and Cloud services (e.g. MITRE ATT&CK building threat intelligence etc.)
- Experience with security events and incident management in highly regulated hosting environments (such as ISO 27001 NIST SP 800-161r3 FedRAMP Protected B)
Engineering Experience
- Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigation.
- Experience using high-level programming languages (Go Python) to produce detection-as-code tools and automations
- Experience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform CloudFormation ARM Pulumi)
- Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins GitHub Actions)
Other
- Deliver quality and velocity of contributions using DevOps principles
- Relentless desire to automate the mundane to focus on solving the harder problems
- Experienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the future
Tanium is an Equal Opportunity and Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race color religion sex national origin age gender identity sexual orientation disability protected Veteran status or other legally protected categories. If you require a reasonable accommodation in searching for a job opening completing an application interviewing or completing any pre-employment testing or requirements please contact. For more information refer to the Know Your Rights poster which is available here - be aware of job offers coming from people claiming to be Tanium employees. Tanium employees will only use @ email addresses to communicate with you will have video interviews with you and will never ask you for money.
For more information on how Tanium processes your personal data please see our.
Required Experience:
Senior IC
About Company
We protect security-conscious organizations as the real-time platform for AI that delivers autonomous solutions, empowers the AI ecosystem, and enables organizations to mitigate risk and maintain the highest levels of operational confidence.