Senior Security Operations Engineer

4 months, 2 weeks ago
Full-time
Senior
Cybersecurity
SWORD Health

SWORD Health

SWORD Health provides AI-powered digital physical therapy solutions designed to prevent pain, support recovery, and enhance overall health, while also aiming to transform the rehabilitation industry through innovative technology and clinical oversight.

Health Care Providers & Services
251-1K
Founded 2015
$324M raised

Description

  • Design and continuously improve detection and alerting controls to reduce noise and improve response quality.
  • Build, test, and automate incident response playbooks and runbooks.
  • Prioritize alerts using a data-driven triage framework aligned with business impact and threat context.
  • Lead incident investigations, including root cause analysis and digital forensics, and turn findings into detection improvements.
  • Conduct threat intelligence and threat hunting to identify new TTPs and enrich security controls.
  • Own incident handling from detection through resolution in collaboration with engineering, IT, and business teams.
  • Define and maintain operational metrics for incident response and use them to drive continuous improvement.
  • Leverage AI to automate and optimize security operations workflows, including alert triage, enrichment, and incident classification.
  • Design and maintain AI-assisted runbooks with human-in-the-loop validation for critical decisions.
  • Integrate security tooling with AI platforms and APIs to streamline investigation, response, and reporting.

Requirements

  • Must be able to obtain and maintain a US Public Trust clearance.
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • Solid experience in cloud environments such as AWS, GCP, or Azure, with strong understanding of cloud-native threats.
  • Proficiency in scripting languages such as Python and Bash for automation and tooling development.
  • Hands-on experience with SOC tools and platforms, including SIEM tools such as Splunk or Sentinel, SOAR, EDR/XDR, and log management.
  • Strong understanding of incident containment and eradication strategies and experience coordinating response with technical teams.
  • Familiarity with security frameworks and standards including NIST 800-61, CIS Controls, MITRE ATT&CK, and ISO 27001.
  • Experience with threat modeling, adversary emulation, and risk-based alert tuning.
  • Forensics experience, including investigating incidents and preserving digital evidence.
  • Ability to communicate security risks and actions to both technical and non-technical audiences.
  • Proven track record of leading cross-functional efforts in high-pressure situations.
  • Ability to foster collaboration across InfoSec, IT, and engineering teams.
  • Ability to consume and synthesize intelligence about actors, techniques, or situations to identify emerging risks.
  • Experience improving processes and operational workflows.
  • Ability to evaluate the accuracy, reliability, and security implications of AI-assisted decisions in operational environments.

Benefits

  • Competitive salary and career development opportunities.
  • Remote-first or hybrid work policy with flexible working hours.
  • Unlimited vacation / discretionary PTO plan.
  • Comprehensive health, dental, and vision insurance.
  • Equity shares.
  • 401(k) retirement plan.
  • Parental leave.
  • Health and well-being support, including free digital therapist sessions for employees and family.
  • Financial advisory services and supplemental insurance benefits.
  • Paid company holidays.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Cloud Security Engineer

LastPass 251-1K IT Services

LastPass is seeking a Principal Cloud Security Engineer to partner with engineering, DevOps, CI/CD, architecture, and trust teams to embed secure-by-design practices across its cloud infrastructure and products.

AWS AWS CDK Docker Git GitLab GitLab CI Kubernetes LLM TCP/IP Terraform TLS
21 hours ago

Technical Lead Chief Security Architect / Engineer

9th Way Insignia 51-250 Internet Software & Services

9th Way Insignia is hiring a Hybrid Manager/Technical Lead Chief Security Architect/Engineer to provide senior cybersecurity architecture and engineering leadership for a federal Department of Veterans Affairs program, strengthening enterprise security and protecting critical systems and information.

Cybersecurity DevSecOps Encryption HIPAA
21 hours, 14 minutes ago

Senior Information Security Engineer

eMoney Advisor 251-1K Capital Markets

The Information Security Engineer at eMoney Advisor manages and strengthens the security operations of a 24x7x365 wealth-management technology infrastructure to protect the confidentiality, integrity, and availability of company data.

AWS Encryption Network Security Penetration Testing
21 hours, 29 minutes ago

Security Vulnerability Engineer (R-00224)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking a Security Vulnerability Engineer to develop and operate vulnerability management, threat detection, and predictive risk capabilities for secure, mission-critical environments.

Hugging Face Keras MLOps Python PyTorch SIEM TensorFlow
21 hours, 29 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers