Senior Security Engineer
About this role
We are seeking a Senior Security Engineer to help monitor, investigate, and respond to security activity across cloud, identity, endpoint, and Linux-based environments. This role requires hands-on technical ability, strong scripting skills, and practical experience working with AWS, with GCP experience preferred.
- Monitor and investigate security alerts across cloud, identity, endpoint, and network environments.
- Review logs and activity from AWS, GCP, Active Directory, Linux systems, Windows systems, and security tools.
- Support incident response by gathering evidence, validating suspicious activity, and documenting findings.
- Write scripts to automate repetitive security tasks, log analysis, reporting, or enrichment.
- Assist with security reviews, including IAM, storage exposure, compute workloads, and network configurations.
- Investigate authentication activity, user behavior, privilege changes, and potential account compromise.
- Work with internal teams to understand systems, identify risks, and support remediation, compliance and audit activities.
- Be available for after-hours incident response when urgent security events require investigation or support.
- Experience with cloud security concepts, services, logs, and IAM.
- Strong scripting ability, preferably with Python, Bash, or PowerShell.
- Experience with SIEM platforms such as Splunk, Chronicle, Sentinel, or similar tools.
- Working knowledge of Linux and Windows systems, command line usage, permissions, processes, and logs.
- Basic to intermediate understanding of Active Directory, including users, groups, authentication, and privilege changes.
- Ability to read and interpret logs from cloud platforms, operating systems, and security tools.
- Understanding of common security concepts such as phishing, credential compromise, privilege escalation, lateral movement, and exposed services.
- Strong analytical, documentation, and communication skills.
Preferred Skills
- Experience with Google Cloud Platform security, including IAM, Cloud Logging, Compute Engine, Cloud Storage, VPCs, and service accounts.
- Exposure to Kubernetes, containers, or cloud-native workloads.
- Experience creating automation for security monitoring or response.
Minimum Qualifications
- 3-5 years of experience in security operations, incident response, systems administration, cloud operations, or a similar technical role.
- Hands-on experience using scripts to solve operational or security problems.
- Comfortable working in both cloud and Linux command-line environments.
Please note:
- Candidates must be available for after-hours incident response when urgent security events require investigation or support.
- The interview process will include a hands-on practical exercise conducted through screen sharing, where candidates will be asked to demonstrate relevant technical skills.
Company at a glance
Cision is the global leader in consumer and media intelligence, engagement, and communication solutions. We equip PR and corporate communications, marketing, and social media professionals with the tools they need to excel in today’s data-driven world. Our deep expertise, exclusive data partnerships, and award-winning brands and products, including CisionOne, Brandwatch, and PR Newswire, enable over 75,000 companies and organizations, including 84% of the Fortune 500, to see and be seen, understand and be understood by the audiences that matter most to them.
Interested in working for Cision? Visit cision.com/careers for available opportunities!
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?