Senior Security Engineer
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Security Engineer hardening beverage-industry technology platforms across VIP’s U.S. operations. Leading segmentation, detection, vulnerability, identity, and incident-response engineering.
Responsibilities:
- Redesign internal network zones, eliminate permissive “any-to-any” paths, and establish east–west traffic visibility during the Palo Alto migration
- Own the SIEM/SOC relationship and extend detection coverage from VIP-core to cloud workloads and acquired business units
- Build the alert-to-action pipeline
- Unify Windows, Mac, Linux, and cloud vulnerability management into a risk-based find–fix–verify loop
- Partner with IT on Okta expansion, privileged-access rollout, and remote/vendor access hardening, including customer VPN tunnel inventory, certificates, and least-privilege policy
- Serve as internal technical lead during security incidents, coordinating evidence handling and containment with DFIR and vCISO partners
- Run tabletop exercises
- Mentor the junior security analyst and set the team’s technical bar
- Achieve first-year goals including VPN inventory and hardening, elimination of priority-zone any-to-any paths, east–west monitoring, subsidiary and cloud telemetry integration, improved vulnerability MTTR, and tested incident-response exercises
Requirements:
- 7+ years of hands-on security engineering across network, endpoint, and identity domains
- Deep practical experience with enterprise firewalls and segmentation design (Palo Alto strongly preferred), SIEM operations, and EDR platforms
- Demonstrated incident-response experience, including containing real events and working with forensic partners
- Judgment to operate in a lean team: prioritize by risk, automate repetitive work, and communicate clearly to executives
- Security certifications such as CISSP, GIAC (GCIA/GCIH/GDSA), or PCNSE are valued; experience is weighted over certifications
- Experience integrating acquired companies or multi-entity environments (nice to have)
- Exposure to iSeries/AS400 or long-lived enterprise platforms (nice to have)
- Scripting/automation with Python or PowerShell for security operations (nice to have)


















