Sr. Cybersecurity Engineer

DocuSign DocuSign · Enterprise · Atlanta, GA · Information Technology

This role focuses on cybersecurity incident response and engineering, emphasizing automation, observability, and resilience through a code-first approach. The engineer will act as an Incident Commander, develop automation scripts and SOAR workflows, enhance threat detection, lead post-mortems, and build integrations between security and DevOps tools. Experience in Incident Response, DevOps, SRE, or Infrastructure Engineering is valued, along with scripting proficiency and cloud-native infrastructure knowledge.

What you'd actually do

  1. Act as the primary Incident Commander for critical cybersecurity events. You will drive technical bridges, manage cross-functional resources, and ensure clear communication streams to minimize business downtime.
  2. Pivot from reactive "fire-fighting" to proactive "fire-proofing." operationalize "Security as Code" by developing automation scripts and SOAR workflows to handle repetitive threats.
  3. Enhance our threat detection capabilities by treating logs as data pipelines. Work with engineering teams to ensure our monitoring tools provide high-fidelity signals, not just noise.
  4. Lead comprehensive After-Action Reviews (AARs) with a focus on root cause analysis. Translate findings into architectural improvements rather than policy patches.
  5. Bridge the gap between Security and DevOps. Build and refine integrations between our security stack (SIEM, EDR) and infrastructure tools (CI/CD, Cloud providers) to streamline response capabilities.

Skills

Required

  • Incident Response
  • scripting (Python, Go, or PowerShell)
  • automation platforms
  • cloud-native infrastructure (AWS/GCP/Azure)
  • containerized (Kubernetes/Docker) environments
  • incident handling lifecycles (NIST 800-61)
  • attacker TTPs (MITRE ATT&CK)

Nice to have

  • DevOps
  • SRE
  • Infrastructure Engineering

What the JD emphasized

  • Incident Response is critical