Sr. Security Engineer

HISTOSONICS INCPlymouth, MN
$110,000 - $140,000Hybrid

About The Position

The Senior Security Engineer who has a focus on security operations is a senior individual contributor within the HistoSonics security operations function and is a member of a larger, multi-site Information Systems and Security team that supports HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role builds and owns the organization’s defensive security capability, including endpoint detection and response, security information and event management, insider risk management and data loss prevention, and centralized vulnerability management. The Senior Security Engineer provides the primary technical execution behind security operations engagement with the AI and R&D Infrastructure team, a partnership owned by the Senior Director, Information Systems and Security, serves a technical escalation for security incidents, and sets technical standards for the function.

Requirements

  • Bachelor’s degree in Information Technology, Information Security, Computer Science, or a related field, or equivalent experience, with 7+ years of progressive experience in security operations, security engineering, or incident response.
  • Demonstrated experience designing, implementing, and administering a security information and event management platform, including log ingestion, detection rule development, and tuning.
  • Advanced administration experience with an enterprise endpoint detection and response platform such as CrowdStrike, including policy design, response actions, and alert investigation across Windows and macOS.
  • Demonstrated experience leading security incident response end to end, and owning a vulnerability management program including scanner administration, prioritization, and remediation coordination.
  • Working knowledge of insider risk management or data loss prevention tooling, including the procedural considerations associated with monitoring user activity.
  • Advanced scripting and automation ability in PowerShell, Python, or comparable languages, and working knowledge of cloud security (AWS or Azure), enterprise identity and access management, and network security controls.
  • Working knowledge of a recognized adversary behavior framework such as MITRE ATT&CK, and experience making changes within an environment compliant with ISO 27001 and SOC 2 standards.

Nice To Haves

  • Experience in a regulated industry such as medical device, healthcare, or manufacturing, including quality management system processes and validation.
  • Experience with security orchestration and automation platforms, digital forensics, malware analysis, threat intelligence, and supporting product or connected device security.
  • Relevant industry certifications are a plus.

Responsibilities

  • Design, implement, and administer the security information and event management platform, including log source onboarding, retention and licensing, correlation rules, dashboards, and reporting.
  • Develop, tune, and maintain detection content mapped to a recognized adversary behavior framework such as MITRE ATT&CK, and document detection rationale and response guidance.
  • Design and implement security automation and orchestration workflows, and develop supporting scripts and tooling in PowerShell, Python, or comparable languages.
  • Own the design, deployment, and administration of the endpoint detection and response platform across Windows, macOS, and server infrastructure, including policy configuration, coverage validation, and response actions.
  • Administer email and messaging security controls in coordination with the System Administration and Network Engineering functions, and conduct proactive threat hunting across endpoint, identity, network, and cloud telemetry.
  • Lead the implementation and administration of the insider risk management and data loss prevention program, including telemetry sources, monitoring policies, risk indicators, and alert triage.
  • Investigate potential data exfiltration and intellectual property loss events under established procedures and in coordination with Human Resources, Legal, and the Senior Director, Information Systems and Security.
  • Own centralized vulnerability management across endpoints, servers, cloud workloads, and network infrastructure, including scanner administration, risk-based prioritization, remediation tracking, and exception handling.
  • Facilitate internal and external penetration testing and security assessments through closure of findings and operationalize threat intelligence into detection and blocking controls.
  • Serve as the senior technical responder for security incidents, leading triage, investigation, containment, and recovery, and conducting root cause analysis with corrective and preventive actions.
  • Author and maintain security incident response procedures, runbooks, and escalation paths, participate in tabletop exercises, and participate in an on-call rotation for critical after-hours support.
  • Define alerting thresholds, response targets, and operational metrics for the function, and report on detection coverage and response performance to leadership.
  • Serve as a senior internal escalation point for security operations matters and provide technical mentorship, work review, and knowledge transfer to current and future security operations staff.
  • Serve as the primary security operations resource to the AI and R&D Infrastructure team and to product engineering, providing consultation, design review, and escalation support.
  • Serve as control owner for assigned IT controls, provide audit evidence, partner with the governance, risk, and compliance function on control design and security maturity, and support validation under the HistoSonics Quality Management System.
  • Escalate cross-organizational governance conflicts, scope disputes, and resourcing trade-offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement security tooling, including assessment of functionality, integration requirements, and licensing costs.

Benefits

  • health, dental, and vision insurance
  • life, short-term and long-term disability insurance
  • 401(k)
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service