Senior Security Operations Engineer

Gong Gong · Enterprise · San Francisco, CA · Information Security

Senior Security Operations Engineer role focused on building automated defenses, threat detection, and managing cloud security posture across AWS, GCP, and Azure. The role involves orchestrating SIEM/SOAR tools, developing custom detection logic, and mentoring junior analysts.

What you'd actually do

  1. Orchestrate SIEM/SOAR tools like a digital Mozart. Help the analysts out by automating the boring tasks
  2. Proactively look for threats that haven’t even decided to move in yet. You’re not just reacting; you’re predicting!
  3. You don’t wait for an antivirus to beep. You build custom logic, YARA rules, and Sigma signatures that catch attackers before they realize they’ve been spotted.
  4. AWS, GCP, Azure. You’re the gatekeeper of our cloud kingdom, ensuring our posture is tighter than a drum across every environment.
  5. You spend time in the dark corners of the web, so we don’t have to. You ingest feeds, analyze adversary actions, and turn exploit rumors into actionable defense strategies

Skills

Required

  • 5+ years of experience in security operations
  • Proficiency with EDR/XDR (CrowdStrike, SentinelOne, MS Defender)
  • Proficiency with Cloud Security Posture Management (Wiz, Prisma Cloud, Orca)
  • Proficiency with WAFs (Cloudflare, Akamai)
  • Proficiency in deploying and maintaining Zero Trust security platforms and controls
  • Experience building data ingestion pipelines using CI/CD methodologies
  • Proven experience building, testing, and tuning custom detection logic
  • Familiarity with Query Languages (KQL, SQL, SPL) for automation needs
  • Familiarity with attack frameworks (MITRE ATT&CK) and mitigation strategies
  • Strong analytical and problem-solving skills
  • Excellent communication and teamwork abilities

Nice to have

  • Security certifications like GXPN, GCIA, GCTI, GCDA, or similar
  • Experience architecting stateful automation pipelines using Python, Go, and enterprise SOAR platforms
  • Ability to read/audit Terraform, Pulumo, or CloudFormation
  • Experience with Infrastructure as a code(IaC)
  • Experience with securing and monitoring containers within cloud environments

What the JD emphasized

  • 5+ years of experience
  • Proficiency with EDR/XDR
  • Proficiency in deploying and maintaining Zero Trust security platforms and controls
  • Experience building data ingestion pipelines using CI/CD methodologies.
  • Proven experience building, testing, and tuning custom detection logic
  • Strong analytical and problem-solving skills.