- Company Name
- Trident Consulting
- Job Title
- (W2 Contract)- Security Engineer
- Job Description
-
**Job Title:** Security Engineer (W2 Contract)
**Role Summary:**
A seasoned security professional responsible for threat intelligence, proactive hunting, incident response, digital forensics, and vulnerability management across cloud, endpoint, network, and application environments. Works closely with SOC, DevSecOps, and infrastructure teams to detect, contain, and remediate security incidents, and supports red team, purple team, and SIEM tuning initiatives.
**Expectations:**
- Deliver daily threat analysis, hunting, and investigation activities.
- Maintain high‑availability of security tooling and zero‑day detectors.
- Provide clear, concise incident reports and executive briefings.
- Advocate continuous improvement of security controls and detection coverage.
**Key Responsibilities:**
- Conduct OSINT‑driven threat intelligence and internal telemetry analysis.
- Lead proactive threat‑hunting campaigns on networks, endpoints, and cloud environments.
- Carry out incident response investigations: root‑cause analysis, containment, eradication, and lessons‑learned documentation.
- Perform digital forensics for compromised hosts, email threats, and insider incidents.
- Triage and remediate security events alongside SOC, DevSecOps, and infrastructure teams.
- Collaborate with red team to simulate APT attacks, identify detection gaps, and advise mitigations.
- Assist vulnerability management by prioritizing high‑risk findings and validating remediation.
- Engineer and tune SIEM rules, develop custom alerts, and enhance threat‑detection capabilities.
- Serve as SME on network protocols, firewall log analysis, lateral movement, and data exfiltration prevention.
**Required Skills:**
- 5+ years in Information Security with deep experience in cloud security, incident response, and application security.
- Proficiency in Azure (primary) and AWS cloud architectures, Windows L2/L3, Linux L2/L3, and network L2/L3 operations.
- Hands‑on with: Tanium, CrowdStrike, Google SecOps, Proofpoint, Palo Alto Demisto, Axonius, Extra Hop.
- Scripting/automation: Python, PowerShell, or Bash.
- Mastery of MITRE ATT&CK, Cyber Kill Chain, Diamond Model.
- Strong written and verbal communication for incident write‑ups and executive briefings.
- Experience in ecommerce protection/compliance, red team or purple team engagements, threat intelligence, and SIEM detection engineering.
- Familiarity with threat modeling, intel enrichment platforms, and containerization.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or a related technical field.
- Certifications such as CISSP, CISM, CEH, or equivalent are preferred.
---
California, United states
Hybrid
Mid level
10-03-2026