Senior Security Engineer
Quick Summary
Infrastructure Design and Maintenance: Design, improve, and maintain secure, durable, and performant infrastructure to power applications, security tooling, log collection,
Professional Experience: At least 5 years of professional experience in a DevOps, Security Engineering, or Detection Engineering role maintaining relevant production infrastructure.
SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud’s solutions thwart cyberattacks and protect more than 4 billion accounts worldwide. Cybersecurity is an exciting, evolving space, and being at the forefront of the fight to disrupt cybercrime makes SpyCloud a special place to work. If you’re driven to align your career with a fantastic mission, look no further!
We are seeking an experienced Security Engineer to join our internal security team who thrives in a fast-paced environment. You have a passion for innovation, solid design principles, and high-quality development. You bring strong infrastructure and detection engineering fundamentals, a security-first mindset, and a deep understanding of cloud and networking concepts.
Responsibilities
~2 min read- →Infrastructure Design and Maintenance:
- →Design, improve, and maintain secure, durable, and performant infrastructure to power applications, security tooling, log collection, and data mining/ETL workflows.
- →Evolve log collection, processing, and storage infrastructure enabling security monitoring and investigations.
- →Support multi-account and multi-region AWS networking architectures with security-first principles.
- →Detection Engineering and Automation:
- →Develop and maintain Splunk detection content aligned to the relevant frameworks and evolving threat intelligence.
- →Administer the Splunk Cloud platform, including search health, log health, and app, platform, and content updates.
- →Design and implement SOAR playbooks to automate investigation and response workflows.
- →Integrate infrastructure security tooling and automation to enhance detection, prevention, and response capabilities.
- →Build and maintain detection-as-code and automated deployment pipelines to ensure consistency, repeatability, and auditability.
- →Continuously refine detection logic to reduce false positives and increase signal quality.
- →Security and Compliance:
- →Implement and operate security technologies across the enterprise, such as an endpoint security platforn.
- →Support incident response and investigation escalations.
- →Proactively meet standards for information security and compliance, such as SOC 2/ISO27001.
- →Implement and uphold security measures across all infrastructure components.
- →Work cross-functionally with Product, IT, DevOps, and Engineering teams to drive secure-by-default practices.
- →Technical Leadership
- →Drive architectural and design decisions for SpyCloud’s detection program and platforms.
- →Mentor junior engineers and establish best practices across infrastructure and detection engineering domains.
Requirements
~1 min read- Professional Experience:
- At least 5 years of professional experience in a DevOps, Security Engineering, or Detection Engineering role maintaining relevant production infrastructure.
- Technical Proficiency:
- Strong working knowledge of AWS services such as EC2, ECS or EKS, Lambda, ELBs, Transit Gateway, VPC, CloudWatch, S3, Code/Build/Pipeline/Deploy, etc.
- Strong working knowledge of Terraform or similar tools, AWS CLI/SDK, Boto.
- Extensive experience with SIEM content engineering, data transformation, and log onboarding.
- Proficiency with scripting languages such as Python, Bash, etc.
- Proficiency integrating systems via API and their respective authentication mechanisms.
- Strong understanding of networking fundamentals and troubleshooting techniques for bare metal and containerized workloads.
- Experience with best practice build pipelines, including Git/GitHub.
Nice to Have
~1 min read- Experience with EDR tools, such as CrowdStrike Falcon and Sentinel One.
- Experience with SOAR playbook building and automation, such as Tracecat and Chronicle SecOps.
- Experience with Cribl Stream.
- Familiarity with Cloud Security Posture Management, such as Crowdstrike and Wiz.
What We Offer
~1 min readWhat We Offer
~1 min readWhat We Offer
~1 min readSpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud's data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.
To learn more and see insights on your company’s exposed data, visit spycloud.com.
Our mission is to make the internet a safer place by disrupting the criminal underground. Together with our customers and partners, we aim to end criminals’ ability to profit from stolen information.
SpyCloud is a place for innovative, collaborative, and problem-solvers to thrive. Individually, we’re amazing, but together, we’re unstoppable. We celebrate diversity and various perspectives and aim to create an inclusive and supportive environment for all. We are proud to be an Equal Employment Opportunity and Affirmative Action employer of choice. All aspects of employment decisions will be based on merit, performance, and business needs. We do not discriminate on the basis of any status protected under federal, state, or local law. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Women, minorities, individuals with disabilities, and protected veterans are encouraged to apply. SpyCloud complies with applicable state and local laws governing nondiscrimination in employment. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
SpyCloud expressly prohibits any form of workplace harassment. Improper interference with the ability of SpyCloud's employees to perform their job duties may result in discipline up to and including discharge. SpyCloud shares the right to work and participates in the E-Verify program in all locations.
If you need assistance or accommodation due to a disability, you may contact us.
Our culture is something really special. We’re all driven to disrupt the cybercriminal economy as we keep customer accounts safe from compromise. We support a truly worthy and serious mission, but we have fun doing it together. If you are driven, inventive, and collaborative, you’ll fit right in.
We will never ask an applicant for sensitive or personal financial information during the recruitment process. We advise all applicants seeking employment with SpyCloud to review available information on recruitment fraud. Anyone who suspects that they have been contacted by someone falsely representing SpyCloud should email careers@spycloud.com.
What We Offer
~1 min readAt SpyCloud, we believe in transparency and fairness in compensation. We strive to ensure that all employees are fairly compensated for their contributions, and we openly discuss our compensation philosophy and structure. We are committed to providing competitive salaries and benefits packages to attract and retain top talent, and we encourage open dialogue and feedback regarding compensation matters.
Learn more and apply: SpyCloud Careers
Listing Details
- Posted
- March 28, 2026
- First seen
- March 26, 2026
- Last seen
- April 19, 2026
Posting Health
- Days active
- 24
- Repost count
- 0
- Trust Level
- 36%
- Scored at
- April 20, 2026
Signal breakdown

SpyCloud transforms recaptured darknet data to protect businesses from identity-based cyberattacks, offering solutions for ransomware prevention, account takeover protection, and cybercrime investigations.
View company profilePlease let Spycloud know you found this job on Jobera.
4 other jobs at Spycloud
View all →Explore open roles at Spycloud.
Similar Senior Security Engineer jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.