SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Qualtrics is seeking a Senior Security Engineer to lead the Security Operations team's detection, triage, and incident response functions across the global environment. This is a hands-on leadership role where you will guide strategy while remaining actively involved in day-to-day security operations.
Key Responsibilities:
- Lead Tier 2 security operations including 24x7 monitoring, detection, triage, and incident response
- Develop and manage CDU (Cyber Defense Unit) metrics and KPIs (MTTD, MTTR, alert volume/fidelity, coverage) and report on program health to security leadership
- Drive continuous improvement of detection logic, playbooks, and automation in partnership with detection engineering and threat intelligence teams
- Serve as escalation point and incident commander for high-severity security incidents, coordinating cross-functional response
- Partner with Threat Intelligence, Detection Engineering, IT, Legal, and Product/Engineering teams to close visibility and response gaps
- Manage relationships with outsourced/MSSP or co-managed CDU partners, ensuring SLAs and quality standards are met
- Evaluate and help select CDU tooling (SIEM, SOAR, EDR, XDR, ticketing) and drive adoption of automation
- Own CDU-related audit, compliance, and customer trust requirements (SOC 2, ISO 27001, FedRAMP as applicable)
- Build and maintain incident response runbooks, tabletop exercises, and post-incident review processes
- Participate in on-call rotation for incidents and provide leadership presence during major security events
- Hire, develop, and retain security talent
You will be a strategic visionary with in-depth understanding of the cybersecurity threat landscape, a technical innovator driving continuous improvement through cutting-edge tools and automation, and a collaborative leader building strong cross-functional partnerships. The role requires resilience and adaptability in a dynamic environment managing complex security projects and leading teams through change.
Qualtrics operates a hybrid work model with three days per week in the office (Mondays, Thursdays, plus one day selected by your organizational leader).
Requirements:
- 5+ years in security operations, incident response, or related security discipline, including 2+ years in a people-management or team-lead role
- Demonstrated experience scaling a 24x7 CDU function, whether in-house, hybrid, or via MSSP oversight
- Strong technical grounding in SIEM/SOAR platforms, EDR/XDR, network and cloud security monitoring, and the MITRE ATT&CK framework
- Experience leading incident response for significant security events, including coordination with legal, communications, and executive stakeholders
- Track record of hiring, developing, and retaining security talent
- Excellent communication skills—able to translate technical detail into risk-based language for non-technical leaders
- Experience with cloud environments (AWS, Azure, or GCP) and SaaS security operations
Nice to Have:
- Experience in a SaaS or enterprise software company handling customer data at scale
- Familiarity with compliance frameworks (SOC 2, ISO 27001, FedRAMP, GDPR)
- Relevant certifications (CISSP, GCIH, GCFA, CISM, or similar)
- Experience building or maturing threat detection and threat hunting programs
- Background in scripting/automation (Python, PowerShell) to support SOAR workflows