About The Position

Perform security assessments of business-initiated projects and technologies (e.g., python-based web stacks) to drive the adoption of application and infrastructure security controls, ensuring security and privacy by design. Partner with technical teams on major technology initiatives to ensure security and "detection by design" principles are integrated at the outset of the system development lifecycle (SDLC). Advise on engineering solutions to protect the firm’s network and Cloud architectures (e.g., AWS or Azure) from security risks related to web services, mobile applications, and client/server environments. Review security controls across diverse systems to identify gaps and drive the implementation of technical mitigations, including cryptographic implementations and data model assessments. Collaborate with global teams to enhance detection effectiveness by providing technical input on sensory tool uplift, logging telemetry, and the tuning of SIEM/EDR detection logic. Execute hypothesis-driven threat hunting missions across enterprise infrastructure to identify undetected malicious activity using threat intelligence and statistical analysis (e.g., stack counting, outlier detection). Develop detection strategies and incident response playbooks to protect the firm from advanced persistent threats (APTs) targeting hybrid environments and mobile applications. Convey complex forensic and threat analyses via comprehensive presentations and incident post-mortems to senior stakeholders and engineering teams. Drive the implementation and optimization of security sensors and logging configurations across various platforms by collaborating with technology infrastructure teams to ensure full visibility for the SOC.

Requirements

  • Master’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Electrical Engineering, Computer Engineering or a related field and one (1) year of experience in the job offered or a related Security Engineering role OR Bachelor’s degree (U.S. or foreign equivalent) in Cyber Security, Computer Science, Electrical Engineering, Computer Engineering or a related field and three (3) years of experience in the job offered or a related Security Engineering role.
  • Designing and auditing technical security controls for enterprise-scale on-premise and Cloud-based architectures, including network segmentation, firewall optimization, and least-privilege enforcement
  • Utilizing industry-standard frameworks, such as MITRE CVE and CVSS to identify, classify, prioritize and drive the remediation of application and infrastructure vulnerabilities through technical controls
  • Performing structured attack surface analysis to identify potential entry points and threat vectors and implementing technical mitigation strategies to harden systems during deployment
  • Conducting comprehensive security risk assessments and maturity gap analyses aligned with industry-standard frameworks such as NIST CSF or CIS Controls
  • Collaborating with cross-functional engineering teams during the design phase to integrate security requirements and "Shift Left" principles into the system development lifecycle (SDLC)
  • Developing custom detections for SIEM/EDR platforms and executing proactive threat hunting missions using threat intelligence (e.g., MISP, industry collaborations) and deep analysis of security telemetry and logs.

Responsibilities

  • Perform security assessments of business-initiated projects and technologies
  • Ensure security and privacy by design
  • Partner with technical teams on major technology initiatives
  • Ensure security and "detection by design" principles are integrated at the outset of the system development lifecycle (SDLC)
  • Advise on engineering solutions to protect the firm’s network and Cloud architectures
  • Review security controls across diverse systems to identify gaps and drive the implementation of technical mitigations
  • Collaborate with global teams to enhance detection effectiveness
  • Execute hypothesis-driven threat hunting missions across enterprise infrastructure
  • Develop detection strategies and incident response playbooks
  • Convey complex forensic and threat analyses via comprehensive presentations and incident post-mortems
  • Drive the implementation and optimization of security sensors and logging configurations
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service