Job Title: Information Technology Security Engineer
Location Requirements: Hybrid
Job Type: Contract
Role Overview:
Support detection and platform engineering within threat operations. Build pipelines, automate tasks, develop detection workflows, and manage security incident response tools. Collaborate with the SOC team to improve detection and response processes, applying AI and standard frameworks to enhance security operations.
Responsibilities:
- Administer and enhance the Security Incident Response module: workflows, rules, SLA definitions, UI configuration, and integrations.
- Design, build, and maintain the Detection-as-Code pipeline: detection development, version control, CI/CD testing, and deployment automation.
- Develop and tune detections across EDR, cloud, network, email, and DLP telemetry.
- Build SOAR playbooks, API integrations, and automation workflows.
- Support SIEM/SOAR platform administration and optimization.
- Contribute to AI SOC initiatives: investigation expansion, alert triage automation, and platform health.
- Apply MITRE ATT&CK, FP-rate gating, and detection lifecycle standards to deployed content.
- Partner with SOC analysts to translate operational gaps into engineering solutions.
Required Qualifications:
- Proven SOC experience in detection engineering, security engineering, or senior analyst roles with an engineering mindset.
- Hands‑on experience administering ServiceNow Security Incident Response (SIR): configuring workflows, business rules, assignment logic, and integrations in a production environment.
- Hands‑on automation and scripting experience, primarily in Python.
- Experience building or contributing to Detection-as-Code pipelines.
- Strong knowledge of MITRE ATT&CK, Pyramid of Pain, Cyber Kill Chain, and incident response phases.
- Deep understanding of at least one: endpoint security (macOS and Windows detection and telemetry) or cloud infrastructure (cloud‑native services, Kubernetes).
- Knowledge of networking fundamentals, including DNS.
- Working knowledge of IAM, SSO (SAML/OIDC), and Zero Trust concepts.
- Working knowledge of Data Loss Prevention concepts and detection use cases.
- Understanding of AI Detection & Response, including securing and monitoring AI/LLM usage in enterprise settings.
- Familiarity with agentic AI frameworks and AI integration into SOC workflows.
Extra Data Context
This role is based in Dallas, with options for San Diego or Mountain View. Onsite 3 days per week required; not available fully remote.
Equal Employment Opportunity Statement
Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.
IT Security Engineer IV (371) in mountain view at Unknown Company
This position is listed as contract and able to be worked remotely.