Senior Security Operations Engineer

3 months, 3 weeks ago
Full-time
Senior
Cybersecurity
SWORD Health

SWORD Health

SWORD Health provides AI-powered digital physical therapy solutions designed to prevent pain, support recovery, and enhance overall health, while also aiming to transform the rehabilitation industry through innovative technology and clinical oversight.

Health Care Providers & Services
251-1K
Founded 2015
$324M raised

Description

  • Design and continuously improve detection and alerting controls to reduce noise and improve response quality.
  • Build, test, and automate incident response playbooks and runbooks.
  • Prioritize alerts using a data-driven triage framework aligned with business impact and threat context.
  • Lead incident investigations, including root cause analysis and digital forensics, and turn findings into detection improvements.
  • Conduct threat intelligence and threat hunting to identify new TTPs and enrich security controls.
  • Own incident handling from detection through resolution in collaboration with engineering, IT, and business teams.
  • Define and maintain operational metrics for incident response and use them to drive continuous improvement.
  • Leverage AI to automate and optimize security operations workflows, including alert triage, enrichment, and incident classification.
  • Design and maintain AI-assisted runbooks with human-in-the-loop validation for critical decisions.
  • Integrate security tooling with AI platforms and APIs to streamline investigation, response, and reporting.

Requirements

  • Must be able to obtain and maintain a US Public Trust clearance.
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • Solid experience in cloud environments such as AWS, GCP, or Azure, with strong understanding of cloud-native threats.
  • Proficiency in scripting languages such as Python and Bash for automation and tooling development.
  • Hands-on experience with SOC tools and platforms, including SIEM tools such as Splunk or Sentinel, SOAR, EDR/XDR, and log management.
  • Strong understanding of incident containment and eradication strategies and experience coordinating response with technical teams.
  • Familiarity with security frameworks and standards including NIST 800-61, CIS Controls, MITRE ATT&CK, and ISO 27001.
  • Experience with threat modeling, adversary emulation, and risk-based alert tuning.
  • Forensics experience, including investigating incidents and preserving digital evidence.
  • Ability to communicate security risks and actions to both technical and non-technical audiences.
  • Proven track record of leading cross-functional efforts in high-pressure situations.
  • Ability to foster collaboration across InfoSec, IT, and engineering teams.
  • Ability to consume and synthesize intelligence about actors, techniques, or situations to identify emerging risks.
  • Experience improving processes and operational workflows.
  • Ability to evaluate the accuracy, reliability, and security implications of AI-assisted decisions in operational environments.

Benefits

  • Competitive salary and career development opportunities.
  • Remote-first or hybrid work policy with flexible working hours.
  • Unlimited vacation / discretionary PTO plan.
  • Comprehensive health, dental, and vision insurance.
  • Equity shares.
  • 401(k) retirement plan.
  • Parental leave.
  • Health and well-being support, including free digital therapist sessions for employees and family.
  • Financial advisory services and supplemental insurance benefits.
  • Paid company holidays.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Customer Support Engineer - Endpoint/MTD (Device) & Cybersecurity

Zimperium 251-1K Professional Services

Zimperium is hiring a Customer Support Engineer to provide technical support for its mobile security platform, helping enterprise customers troubleshoot issues and resolve product problems in coordination with internal teams.

Android Android Studio AWS Cybersecurity Docker iOS Java JIRA JUnit Kafka Linux Machine Learning PostgreSQL Python SIEM Splunk SQL Unix Xcode
1 day, 12 hours ago

Director , Information Security and IT

Luna Physical Therapy 251-1K Health Care Providers & Services

Luna is hiring a Director of Information Security & IT to lead enterprise technology and security programs supporting secure operations and patient care in a HIPAA-regulated environment.

AWS Azure GCP HIPAA Penetration Testing
1 day, 12 hours ago

Senior MS Intune & Cloud Security Specialist (Freelance)

Coderio 51-250 Internet Software & Services

Coderio is seeking a Senior Cloud Security Architect / MS Intune Specialist to lead a greenfield Microsoft Intune, Entra ID, and Defender for Endpoint implementation for a multi-cloud environment spanning Google Workspace, AWS, and DevOps pipelines.

Active Directory Android AWS Bash GitHub GitLab iOS macOS PowerShell
1 day, 12 hours ago

Senior Security Engineer

Hummingbird 1K-5K Professional Services

Hummingbird is hiring a Senior Security Engineer to own and strengthen security for its remote-first SaaS platform that helps financial institutions fight financial crime.

AWS Azure CircleCI Docker Encryption GraphQL JavaScript Network Security PostgreSQL Python React Redis Ruby Ruby on Rails Terraform TypeScript
3 days, 12 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers