Senior Security Engineer

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Engineer hardening beverage-industry technology platforms across VIP’s U.S. operations. Leading segmentation, detection, vulnerability, identity, and incident-response engineering.

Responsibilities:

  • Redesign internal network zones, eliminate permissive “any-to-any” paths, and establish east–west traffic visibility during the Palo Alto migration
  • Own the SIEM/SOC relationship and extend detection coverage from VIP-core to cloud workloads and acquired business units
  • Build the alert-to-action pipeline
  • Unify Windows, Mac, Linux, and cloud vulnerability management into a risk-based find–fix–verify loop
  • Partner with IT on Okta expansion, privileged-access rollout, and remote/vendor access hardening, including customer VPN tunnel inventory, certificates, and least-privilege policy
  • Serve as internal technical lead during security incidents, coordinating evidence handling and containment with DFIR and vCISO partners
  • Run tabletop exercises
  • Mentor the junior security analyst and set the team’s technical bar
  • Achieve first-year goals including VPN inventory and hardening, elimination of priority-zone any-to-any paths, east–west monitoring, subsidiary and cloud telemetry integration, improved vulnerability MTTR, and tested incident-response exercises

Requirements:

  • 7+ years of hands-on security engineering across network, endpoint, and identity domains
  • Deep practical experience with enterprise firewalls and segmentation design (Palo Alto strongly preferred), SIEM operations, and EDR platforms
  • Demonstrated incident-response experience, including containing real events and working with forensic partners
  • Judgment to operate in a lean team: prioritize by risk, automate repetitive work, and communicate clearly to executives
  • Security certifications such as CISSP, GIAC (GCIA/GCIH/GDSA), or PCNSE are valued; experience is weighted over certifications
  • Experience integrating acquired companies or multi-entity environments (nice to have)
  • Exposure to iSeries/AS400 or long-lived enterprise platforms (nice to have)
  • Scripting/automation with Python or PowerShell for security operations (nice to have)