Senior Staff Security Engineer
Posted 14hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Staff Security Engineer architecting scalable security solutions for diverse clients. Leading technical strategy and compliance across multi-tenant environments while mentoring senior engineers.
Responsibilities:
- Strategic Security Architecture & Product Strategy
- Tier 4 Escalation & Forensic Mastery
- Security Engineering & Hyper-Automation
- High-Stakes Advisory & Governance
Requirements:
- 8–12+ Years in Information Security, with a significant background (3+ years) in multi-client consulting or MSP environments.
- Force Multiplier: Proven track record of leading cross-functional projects and mentoring senior engineers without direct-report authority.
- Bilingual Communication: The rare ability to pivot from a deep-dive technical audit with an engineer to a risk-based ROI presentation for a CEO.
- Expert-level AWS/Azure security; Zero Trust Architecture (ZTA); Advanced IAM/Entra ID.
- Advanced SOAR/SIEM engineering (Sentinel, Splunk, CrowdStrike); MITRE ATT&CK mapping.
- Deep-packet inspection; BGP security; SD-WAN; SASE; Micro-segmentation.
- Proficiency in Python, Terraform, or Ansible for infrastructure-as-code.
- Certifications CISSP (Highly Preferred), CISM, CCSP, or specialized GIAC (GCIH/GCFA).
Benefits:
- Scalable Multi-tenancy: Architect and maintain hardened, isolated security stacks (SIEM, EDR, XDR) designed to scale across hundreds of distinct client environments.
- Product Vetting: Serve as the technical lead for vendor evaluations, "battle-testing" emerging tech to define our global standard offerings.
- Global Standardization: Engineer "Gold Image" baselines and automated deployment templates based on CIS and NIST frameworks to ensure rapid, secure onboarding.
- Final Authority: Serve as the ultimate technical escalation point for the SOC, leading the response to sophisticated APTs and complex breaches.
- Post-Mortem Leadership: Conduct deep-dive Root Cause Analysis (RCA) and translate incident findings into systemic, fleet-wide preventative measures.
- Security as Code: Build the automation tissue that connects our stack, utilizing Python, PowerShell, and Terraform to automate threat containment and patch management.
- Integration Engineering: Develop custom API integrations to bridge gaps between vulnerability scanners, RMM tools, and ticketing systems for seamless auto-remediation.
- Strategic vCISO: Act as a high-level advisor for key accounts, translating abstract risk into actionable business roadmaps for C-suite stakeholders.
- Compliance Orchestration: Oversee technical evidence collection and governance for HIPAA, SOC 2, and CMMC, ensuring our clients remain audit-ready.



















