SonicJobs Logo
Left arrow iconBack to search

Staff Security Engineer

Red Cup IT, Inc.
Posted 4 months ago, valid for a day
Location

Los Angeles, CA 90053, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • We are looking for a Staff Security Engineer with 8 to 12 years of experience in Information Security, particularly in multi-client consulting or MSP environments.
  • The role requires expertise in scalable multi-tenancy security architecture, incident response, and automation using tools like Python and Terraform.
  • Candidates should have a deep understanding of compliance frameworks such as HIPAA and SOC 2, and hold certifications like CISSP, CISM, or CCSP.
  • This position emphasizes technical leadership rather than people management, focusing on strategic security architecture and high-stakes advisory roles.
  • The salary for this position is competitive and commensurate with experience, reflecting the seniority and technical demands of the role.

We are seeking a Staff Security Engineer who operates at the nexus of high-level strategy and multi-tenant operational excellence. While a traditional internal role secures a single enterprise perimeter, you are responsible for the integrated defense fabric of a vast portfolio of diverse client environments.

You will navigate the complexities of varied compliance needs and legacy technical debt, transforming them into a unified, scalable security posture. This is a technical leadership role designed for an expert who prefers the keyboard and the whiteboard over a people-management track, focusing on the "big picture" of our global security product stack.

Core Responsibilities

1. Strategic Security Architecture & Product Strategy

  • Scalable Multi-tenancy: Architect and maintain hardened, isolated security stacks (SIEM, EDR, XDR) designed to scale across hundreds of distinct client environments.
  • Product Vetting: Serve as the technical lead for vendor evaluations, "battle-testing" emerging tech to define our global standard offerings.
  • Global Standardization: Engineer "Gold Image" baselines and automated deployment templates based on CIS and NIST frameworks to ensure rapid, secure onboarding.

2. Tier 4 Escalation & Forensic Mastery

  • Final Authority: Serve as the ultimate technical escalation point for the SOC, leading the response to sophisticated APTs and complex breaches.
  • Post-Mortem Leadership: Conduct deep-dive Root Cause Analysis (RCA) and translate incident findings into systemic, fleet-wide preventative measures.

3. Security Engineering & Hyper-Automation

  • Security as Code: Build the automation tissue that connects our stack, utilizing Python, PowerShell, and Terraform to automate threat containment and patch management.
  • Integration Engineering: Develop custom API integrations to bridge gaps between vulnerability scanners, RMM tools, and ticketing systems for seamless auto-remediation.

4. High-Stakes Advisory & Governance

  • Strategic vCISO: Act as a high-level advisor for key accounts, translating abstract risk into actionable business roadmaps for C-suite stakeholders.
  • Compliance Orchestration: Oversee technical evidence collection and governance for HIPAA, SOC 2, and CMMC, ensuring our clients remain audit-ready.

Technical Profile

CategoryCompetencies
Cloud & IdentityExpert-level AWS/Azure security; Zero Trust Architecture (ZTA); Advanced IAM/Entra ID.
SecOps & IntelligenceAdvanced SOAR/SIEM engineering (Sentinel, Splunk, CrowdStrike); MITRE ATT&CK mapping.
Network DefenseDeep-packet inspection; BGP security; SD-WAN; SASE; Micro-segmentation.
Automation / IaCProficiency in Python, Terraform, or Ansible for infrastructure-as-code.
CertificationsCISSP (Highly Preferred), CISM, CCSP, or specialized GIAC (GCIH/GCFA).

Experience & Qualifications

  • 8–12+ Years in Information Security, with a significant background (3+ years) in multi-client consulting or MSP environments.
  • Force Multiplier: Proven track record of leading cross-functional projects and mentoring senior engineers without direct-report authority.
  • Bilingual Communication: The rare ability to pivot from a deep-dive technical audit with an engineer to a risk-based ROI presentation for a CEO.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.