Apply Edge Start your job search

Senior Security Engineer

Talent Mappers · Denver Metropolitan Area

Apply & track with Apply Edge

About the RoleWe are seeking a Senior Security Engineer to design, implement, and continuously improve enterprise security capabilities across endpoint, cloud, network, data, and security operations environments.This is a hands-on senior engineering role responsible for the architecture, implementation, integration, and optimization of core security platforms, including Rapid7, Microsoft Defender, Microsoft Purview, Mimecast, and Zscaler. The engineer will serve as a technical owner for these platforms and translate security requirements and identified risks into scalable technical controls.The role works closely with Security Operations, Infrastructure, Network, Cloud, and Application Engineering teams and requires the ability to independently lead complex technical initiatives and solve problems across multiple technology domains.This position is hybrid 4 days a week in office.Key ResponsibilitiesSecurity Platform & Architecture EngineeringServe as a senior technical owner for enterprise security platforms, leading complex implementations, integrations, migrations, and major technology changes.Establish scalable security architectures, engineering standards, and configuration baselines aligned with secure-by-design, defense-in-depth, and Zero Trust principles.Evaluate existing and emerging capabilities to close security gaps, improve effectiveness, simplify the technology environment, and provide senior-level technical guidance across engineering teams.SIEM, Detection & Security Operations EngineeringEngineer and evolve Rapid7 InsightIDR and supporting SIEM capabilities, including telemetry, detection logic, correlation, alerting, and visibility across enterprise environments.Partner with Security Operations and MDR providers to improve detection coverage, reduce operational noise, and translate lessons from incidents into improved controls.Develop SOAR workflows and platform integrations that automate enrichment, investigation, response, remediation, and other security processes.Vulnerability Management EngineeringEngineer and evolve Rapid7 InsightVM capabilities to provide comprehensive and actionable vulnerability visibility across endpoints, servers, network infrastructure, and cloud workloads.Improve vulnerability prioritization and remediation by incorporating severity, exploitability, asset criticality, and environmental context.Partner with technology teams to identify coverage gaps, validate remediation, and improve vulnerability management through automation and platform integration.Microsoft Security & Data ProtectionEngineer and optimize Microsoft Defender capabilities across enterprise endpoints, servers, cloud workloads, and Microsoft 365 environments.Design and maintain preventative and detective controls, including endpoint protection, attack surface reduction, threat protection, and related security policies.Engineer Microsoft Purview Data Loss Prevention and information protection capabilities to protect sensitive information while balancing security requirements with legitimate business processes.Email Security EngineeringEngineer and optimize Mimecast or comparable Secure Email Gateway capabilities to protect against phishing, malware, business email compromise, impersonation, and other email-borne threats.Maintain layered email security controls and secure mail-flow architecture across Microsoft 365 and third-party security platforms, including SPF, DKIM, and DMARC.Continuously improve email security controls based on emerging threats, security events, and observed control effectiveness.Zero Trust & Network SecuritySupport the continued development of Zero Trust capabilities using Zscaler and related technologies.Partner with Network Engineering to strengthen secure internet access, traffic inspection, application control, and network security enforcement.Improve security controls through the effective use of identity, device posture, application, network, and threat context.QualificationsBachelor's degree in Computer Science, Engineering, Information Security, or a related field, or equivalent professional experience.7+ years of experience in security engineering, infrastructure security, cloud security, or a related technical discipline, with demonstrated experience independently designing and implementing enterprise security solutions.Strong hands-on experience across multiple security domains, including SIEM/detection engineering, vulnerability management, endpoint security, data protection, email security, and security automation.Experience with technologies such as Rapid7 InsightIDR/InsightVM, Microsoft Defender/Purview, Mimecast or comparable Secure Email Gateway technologies, and Zscaler or comparable SASE/Secure Web Gateway platforms.Strong scripting, automation, integration, and troubleshooting skills using technologies such as PowerShell, Python, REST APIs, and platform APIs.Strong understanding of enterprise security architecture, Zero Trust, defense-in-depth, and frameworks such as NIST CSF, CIS Controls, and MITRE ATT&CK.Preferred QualificationsExperience engineering security technologies within a large, distributed enterprise or hybrid cloud environment.Experience integrating SIEM, MDR, endpoint security, vulnerability management, email security, ticketing, and SOAR technologies.Relevant security or technology certifications such as CISSP, CCSP, GIAC, Microsoft, Rapid7, Zscaler, Mimecast, or comparable certifications.Salary Range: $140,000—$160,000 USD base