Senior Security Engineer
Job Description
Gordon Food Service is building security capability across enterprise, cloud, and hybrid environments, and this role is a core technical leadership position within the Security Operations (SecOps) team. You will design, automate, and maintain the organization’s enterprise security architecture while advancing threat hunting, detection engineering, security validation, and analyst enablement.
What you’ll do
- Provide strategic leadership for cybersecurity strategies, policies, and frameworks.
- Partner with senior stakeholders to align security initiatives with organizational goals.
- Stay current on emerging cybersecurity trends, threats, and technologies to inform expert guidance and recommendations.
- Lead the SecOps threat hunting program across multi-platform operating systems, enterprise cloud, virtualized infrastructure, and network environments.
- Correlate open-source and proprietary threat intelligence (TTPs) into proactive, baseline, and reactive threat hunts.
- Maintain and expand automated hunt dashboards and threat hunting automation frameworks.
- Assist with designing, implementing, and maintaining secure network architectures and infrastructure.
- Manage SIEM/SOAR platform health, including log ingestion pipelines, custom parsers, data normalization models, and feed integrations.
- Collaborate with cross-functional teams to evaluate and select security technologies and solutions.
- Serve as the Tier 2 technical escalation point and mentor Security Analysts.
- Participate in critical Incident Response efforts, including root-cause investigations and the SecOps On-Call rotation.
- Conduct detailed investigations, perform root cause analysis, and drive remediation actions.
- Design, build, and tune custom detections using vendor-neutral rule languages and native SIEM/SOAR/EDR logic to reduce false positives while maintaining detection quality.
- Execute automated and manual threat emulation or attack chains using open-source testing frameworks to validate log ingestion, rule efficacy, and controls.
- Support external Red Team engagements and remediate identified visibility and control gaps.
- Build and manage Infrastructure-as-Code (IaC) configurations via version-controlled CI/CD pipelines for security workspaces and validation environments.
- Write and maintain automation scripts (for example, Python, PowerShell) and SOAR playbooks to streamline analyst triage and system workflows.
- Support the development and integration of modern AI agent platforms and operational workflows into core SecOps pipelines.
What you bring
- Bachelor’s Degree in Computer Science, Information Systems, or a related field (required).
- Five to eight years of related experience, or an equivalent combination of education, training, and experience.
- Professional certifications such as CISSP, CISM, GIAC, or CCSP (preferred).
- Proficiency administering Enterprise SIEM, SOAR, EDR, and NDR platforms.
- Extensive knowledge of cybersecurity principles, technologies, and best practices.
- Expertise writing custom detection logic, complex queries, and log normalization.
- Strong understanding of enterprise IT infrastructure: Windows, Linux, Enterprise Cloud (IaaS/PaaS), IAM, and enterprise networking.
- Experience writing automation scripts in Python, PowerShell, or Bash.
- Incident response experience, including forensic analysis, malware analysis, and threat intelligence.
- Experience with threat hunting frameworks (for example, MITRE ATT&CK) and security validation tools.
- Excellent leadership and communication skills for technical discussions with stakeholders at all levels.
- Proven ability to lead and mentor junior team members.
- Good customer service and time management skills.
- Ability to develop solutions to complex problems by referencing established precedents and policies.
Technologies you’ll work with
- Security Operations (SecOps), SIEM, SOAR, EDR, NDR
- CI/CD, Infrastructure-as-Code (IaC)
- Python, PowerShell, Bash, AI workflows
- Windows, Linux, Enterprise Cloud (IaaS/PaaS)
- Identity & Access Management (IAM)
- MITRE ATT&CK
Schedule and work location
- Monday to Friday, 8am to 5pm
- Hybrid schedule: 4 days in office in Wyoming, MI or Atlanta, GA, with 1 day remote
Workplace requirements and accommodations
- Gordon Food Service locations are tobacco-free.
- Gordon Food Service is a drug-free workplace and conducts pre-employment drug tests.
- Equal Employment Opportunity is a matter of policy at Gordon Food Service, Inc.
- If you need reasonable accommodation for any part of the application or hiring process due to a disability, email [email protected] and include the words “Accommodation Request” in the subject line.
- If you are employed by a Gordon Food Service customer, you must provide a letter of support from your management if selected for the interview process.