[Remote] Sr. Cloud Cybersecurity Engineer
Note: The job is a remote job and is open to candidates in USA. Tanium is the Autonomous IT company, and they are seeking a Senior Cloud Cybersecurity Detection and Response Engineer to enhance the security of their cloud services. The role involves designing and implementing security measures, collaborating with various teams to counter risks and threats, and maintaining positive relationships with internal customers.ResponsibilitiesBuild and operate Tanium Cloud's detection and response engineering in Azure, AWS, and Kubernetes for detections, analysis, and responses as automation as code using DevOps methodologiesContinuously evaluate and enhance the design and effectiveness of Cloud and Kubernetes security measures and establish an ongoing program to advance security and close gaps in our defensive postureProactively characterize unauthorized activity and malicious behaviors in our cloud and container infrastructure and systems through code, testing, and automationDevelop tailored detection policies, perform testing, and implement automation to observe, evaluate, enhance, and review security information using SecDataOps and best practicesProactively integrate the latest security threats, vulnerabilities, and industry trends to enhance security detection measures and generate intelligence driven huntsWork together with the engineering, IT, and other security groups to create solutions that are expandable and adaptable to protect Tanium Cloud against threats ranging from low-level actors to national cyber-threat agentsBuild, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's workBe on periodic on-call for triage of critical events from detections and systemsSkillsBachelor's degree or equivalent experience5-7 years of experience in cloud security event prevention, detection, response for public cloud systems (e.g. AWS, Azure) within a DevOps environment3+ years of hands-on experience in Kubernetes environment, logging, and runtime security for sensitive container workloads, preferably on AKS and EKSExperience in detection and response engineering methodologies, such as building detection cases, proactively identify known and unknown cyber threats, advisory behaviorsExperience in using security query or analytic tools for security data analysis, such as SQL, KQL, or SPLBuild and improve security playbooks and runbooks for automating security detection and responseSolid understanding of modern attacker tactics, techniques, and procedures (TTPs) against Kubernetes, Container, Serverless, Linux host, and Cloud services (e.g. MITRE ATT&CK, building threat intelligence, etc.)Experience with security events and incident management in highly regulated hosting environments (such as ISO 27001, NIST SP 800-161r3, FedRAMP, Protected B)Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigationExperience using high-level programming languages (Go, Python) to produce detection-as-code, tools, and automationsExperience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform, CloudFormation, ARM, Pulumi)Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins, GitHub Actions)Deliver quality and velocity of contributions using DevOps principlesRelentless desire to automate the mundane to focus on solving the harder problemsExperienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the futureCloud Security, IT Security, or related technical field preferredBenefitsEquity awardsMedical, dental and vision planFamily planning benefitsHealth savings accountFlexible spending accountTransportation savings account401(k) retirement savings plan with company matchLife, accident and disability coverageBusiness travel accident insuranceEmployee assistance programsDisability insuranceOther well-being benefitsEach of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.Company OverviewTanium is an IT security firm that provides risk management, incident response, EDR, and patch management services. It was founded in 2007, and is headquartered in Kirkland, Washington, USA, with a workforce of 1001-5000 employees. Its website is http://www.tanium.com.