SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Semperis is seeking a hands-on Senior Security Operations Engineer to strengthen threat detection, incident response, vulnerability management, and cloud security operations. This is an engineering-focused role that goes beyond alert monitoring—you will identify security problems, understand root causes, and work directly with teams to implement fixes.
Key responsibilities include:
Threat Detection & Incident Response: Operate and improve SIEM, EDR, cloud, identity, and email monitoring. Develop and tune detection rules, analytics, dashboards, and investigation playbooks. Investigate security alerts and incidents, including scoping, evidence collection, containment, and remediation coordination.
Vulnerability & Cloud Security: Lead SecOps triage of vulnerability, exposure, endpoint patching, and CSPM/CWP findings. Validate findings, assess risk, assign ownership, establish remediation priorities, and track corrective actions. Partner with Cloud Security on posture-management rules and alert tuning.
Automation & Engineering: Build scripts, integrations, workflows, and playbooks to improve triage, enrichment, and remediation tracking. Monitor log-source and connector health. Maintain metrics covering MTTD, MTTR, alert quality, and detection coverage.
AI Security: Assess AI tools, agents, and integrations for data access and execution risk. Design and operate guardrails for least-privilege identities and sandboxed execution. Monitor prompts and model outputs for prompt injection, data exposure, and policy violations. Build detections and response playbooks for rogue tools and agent compromise.
Cross-Functional Collaboration: Translate security findings into clear actions and priorities. Provide practical security guidance to engineering and IT teams. Mentor analysts through technical reviews and incident walkthroughs.
Required: 5+ years in Security Operations, Security Engineering, Detection Engineering, or Incident Response. Strong SIEM, detection engineering, and incident response experience. Practical vulnerability management and CSPM/CWP experience. Azure, AWS, or multi-cloud experience. Strong understanding of identity and access risks.