Job description
CipherGuard Security, a premier cybersecurity partner for enterprise clients, is looking for a Senior Cybersecurity Engineer to join our San Francisco security operations team. You will design, implement, and advance security controls across on premise and cloud environments, while mentoring junior engineers. This role blends hands-on security engineering with strategic security leadership, offering competitive compensation, stock options, comprehensive benefits, and a culture of continuous learning.
As a key contributor, you will collaborate with platform teams, product teams, and executives to reduce risk and strengthen our security posture in a fast-paced, high-impact environment.
Responsibility
- Design and implement robust security controls across on-premises and cloud environments (AWS, Azure, Google Cloud).
- Lead incident response and forensics activities, coordinating cross-functional teams to detect, contain, and remediate incidents.
- Develop and maintain threat models, risk assessments, and security architecture patterns for new initiatives.
- Manage and tune SIEM/SOC operations, perform proactive threat hunting, and optimize detection coverage.
- Collaborate on vulnerability management, patch prioritization, and remediation tracking with engineering teams.
- Enable secure DevSecOps practices by integrating security checks into CI/CD pipelines and infrastructure as code tooling.
- Contribute to governance, policy development, control design, and audit readiness in line with NIST and ISO 27001 standards.
Qualification
- 5+ years of hands-on cybersecurity experience in enterprise environments, with a track record of delivering secure, scalable solutions.
- Deep expertise in SIEM (eg, Splunk, QRadar), EDR, IDS/IPS, and incident response lifecycle.
- Strong cloud security experience across AWS, Azure, or Google Cloud and secure architecture design principles.
- Proficiency in scripting and automation (Python, PowerShell, Bash) to build security tooling and workflows.
- Experience with vulnerability management, threat modeling, and risk assessment frameworks (NIST, ISO 27001).
- Relevant certifications such as CISSP, CISM, or SANS GCIA/GCSP are highly preferred.
- Excellent communication, collaboration, and ability to work effectively in a fast-paced, cross-functional environment.