Tanium Logo

Tanium

Senior Cloud Cybersecurity (CCS) Detection and Response Engineer

Posted 2 Days Ago
Remote
Hiring Remotely in Canada
Senior level
Remote
Hiring Remotely in Canada
Senior level
Tanium is seeking a Senior Cloud Cybersecurity (CCS) Detection and Response Engineer to enhance security measures across Tanium Cloud's services. Responsibilities include building and improving detection systems in cloud environments, developing tailored detection policies, and collaborating across teams to address security threats. The role requires automation, analytical skills, and experience in cloud security and Kubernetes.
The summary above was generated by AI

The Basics:
The Senior Cloud Cybersecurity (CCS) Detection and Response Engineer will collaborate with Detection, Security, and Software Engineers to proactively defend Tanium Cloud's services. You will be an integral part of the Tanium Cloud security engineering processes, responsible for the design, implementation, and operation of preventative, detective, and responsive controls to identify, assess, and counter risks and threats before impacting Tanium Cloud. 
What you'll do:

  • Build and operate Tanium Cloud's detection and response engineering in Azure, AWS, and Kubernetes for detections, analysis, and responses as automation as code using DevOps methodologies
  • Continuously evaluate and enhance the design and effectiveness of Cloud and Kubernetes security measures and establish an ongoing program to advance security and close gaps in our defensive posture.
  • Proactively characterize unauthorized activity and malicious behaviors in our cloud and container infrastructure and systems through code, testing, and automation
  • Develop tailored detection policies, perform testing, and implement automation to observe, evaluate, enhance, and review security information using SecDataOps and best practices.
  • Proactively integrate the latest security threats, vulnerabilities, and industry trends to enhance security detection measures and generate intelligence driven hunts..
  • Work together with the engineering, IT, and other security groups to create solutions that are expandable and adaptable to protect Tanium Cloud against threats ranging from low-level actors to national cyber-threat agents.
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work
  • Be on periodic on-call for triage of critical events from detections and systems

We're looking for someone with:

Education:

  • Bachelor's degree or equivalent experience 
  • Cloud Security, IT Security, or related technical field preferred 

Locality

  • U.S. Candidates: In accordance with United States government customer requirements, applicants for this role must be a U.S. citizen, national, or resident pursuant to 8 U.S.C. 1101(a)(20) and 8 U.S.C. 1324b(a)(3)
    OR
  • Canadian Candidates: In accordance with Canadian government customer requirements, applicants for this role must undergo personnel security screening and maintain Protected B reliability status

Cloud Detection Engineering Experience

  • 5-7 years of experience in cloud security event prevention, detection, response for public cloud systems (e.g. AWS, Azure) within a DevOps environment
  • 3+ years of hands-on experience in Kubernetes environment, logging, and runtime security for sensitive container workloads, preferably on AKS and EKS
  • Experience in detection and response engineering methodologies, such as building detection cases, proactively identify known and unknown cyber threats, advisory behaviors
  • Experience in using security query or analytic tools for security data analysis, such as SQL, KQL, or SPL
  • Build and improve security playbooks and runbooks for automating security detection and response
  • Solid understanding of modern attacker tactics, techniques, and procedures (TTPs) against Kubernetes, Container, Serverless, Linux host, and Cloud services (e.g. MITRE ATT&CK, building threat intelligence, etc.)
  • Experience with security events and incident management in highly regulated hosting environments (such as ISO 27001, NIST SP 800-161r3, FedRAMP, Protected B)

Engineering Experience

  • Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigation.
  • Experience using high-level programming languages (Go, Python) to produce detection-as-code, tools, and automations
  • Experience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform, CloudFormation, ARM, Pulumi)
  • Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins, GitHub Actions) 

Other 

  • Deliver quality and velocity of contributions using DevOps principles
  • Relentless desire to automate the mundane to focus on solving the harder problems
  • Experienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the future

About Tanium 

Tanium delivers the industry's only true real-time cloud-based endpoint management and security offering. Its platform is real-time, seamless, and autonomous, allowing security-conscious organizations to break down silos between IT and Security operations that results in reduced complexity, cost, and risk. Securing more than 32M endpoints around the world, Tanium's customers include Fortune 100 organizations, top US retailers, top US commercial banks, and branches of the U.S. Military. It also partners with the world's biggest technology companies, system integrators, and managed service providers to help customers realize the full potential of their IT investments. Tanium has been named to the Forbes Cloud 100 list for nine consecutive years and ranks on the Fortune 100 Best Companies to Work For. For more information on The Power of Certainty™, visit www.tanium.com and follow us on LinkedIn and X. 

On a mission. Together. 

At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions.   

We are an organization with stakeholders around the world and it’s imperative that the diversity of our customers and communities is reflected internally in our team members. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things. 

Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.   

What you’ll get 

The annual base salary range for this full-time position is $C95,000 to $C280,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.


For more information on how Tanium processes your personal data, please see our Privacy Policy.


Top Skills

Go
Python

Tanium Calgary, Alberta, CAN Office

Calgary, AB, Canada

Similar Jobs

4 Days Ago
Remote
3 Locations
Expert/Leader
Expert/Leader
Big Data • Cloud • Software • Analytics
The Distinguished Cloud Cybersecurity Architect will lead the secure design and implementation of cloud-based cybersecurity solutions for telecom systems, overseeing risk assessments, security incident responses, and compliance with cybersecurity regulations while staying informed about evolving threats.
Top Skills: Google Cloud Platform
2 Days Ago
Remote
Canada
Senior level
Senior level
Cloud • Fintech • Cryptocurrency • NFT • Web3
As a Senior Infrastructure Security Engineer at Coinbase, you will design and implement security controls, conduct security consultations, develop automation codes for threat detection, and partner with engineering teams to ensure secure architecture in cloud environments. The role demands expertise in cloud security, particularly in AWS and GCP, and experience in Terraform and programming languages such as Golang or Ruby.
Top Skills: GoRuby
16 Hours Ago
Remote
Hybrid
5 Locations
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Senior Security Researcher at CrowdStrike, you'll lead cloud security research initiatives, focusing on cloud infrastructure threats and vulnerabilities, conducting cutting-edge research in Linux security, and developing advanced security models. Your insights will guide product direction and improvement for customer security.
Top Skills: GoPython

What you need to know about the Calgary Tech Scene

Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account