Senior Security Engineer,Detection & Incident Response

Posted 4 Days Ago
Be an Early Applicant
Prague, CZE
In-Office
Senior level
Software
The Role
Drive security operations through detection engineering, incident response, threat hunting, threat intelligence integration, security automation, and cloud security monitoring. Build and tune Splunk detections, investigate and contain complex incidents, develop Python and SOAR workflows, operationalize threat intelligence, monitor AWS, GCP, Azure, containers, and Kubernetes, and evaluate AI-assisted security workflows. The role also develops playbooks, detection-as-code infrastructure, testing frameworks, and response automation within a global 24/7 security operations environment.
Summary Generated by Built In

Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.

This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.

THE ROLE

Everpure is seeking a hands-on Senior Security Engineer to drive security operations from our Prague, Czech Republic location. In this role, you will contribute to operational excellence across incident response, threat hunting, threat intelligence integration, detection engineering, and security automation, bringing real-time visibility and rapid response to our 24/7 global security operations environment.

This is a technical delivery and execution role, not a traditional monitoring position. You will work closely with detection engineers, threat intelligence analysts, incident response leadership, and our global Security Operations teams to build and refine detections, improve signal quality, execute threat hunts, automate workflows, and respond to complex security incidents with speed and precision.

Success in this role is measured not by alert volume, but by signal quality, real threat detection, incident containment speed, automation maturity, and the effectiveness of response workflows.

WHAT YOU'LL DO

  • Detection Engineering: Design, implement, and maintain detections in Splunk and related security platforms. Develop detection-as-code content using formats such as YAML/JSON, incorporate unit and regression testing, map coverage to MITRE ATT&CK, and contribute to Sigma/YARA-L coverage expansion.
  • Incident Response & Triage: Investigate suspicious activity and participate in incident triage, scoping, containment, eradication, recovery, and post-incident reviews. Use lessons from investigations to continuously improve detection and response processes.
  • Threat Hunting: Execute hypothesis-driven threat hunts using MITRE ATT&CK, the Diamond Model, kill chains, threat intelligence, behavioral baselines, and anomaly detection. Correlate signals across endpoint, cloud, identity, SaaS, network, and other security telemetry to identify real threats and operational blind spots.
  • Detection Quality: Continuously tune detections to improve true-positive rates and reduce alert fatigue. Identify which signals provide meaningful security value and refine detection logic based on investigation outcomes and changes in the threat landscape.
  • Threat Intelligence Integration: Operationalize cyber threat intelligence (CTI) by mapping adversary tools, techniques, TTPs, and indicators to the Everpure environment and translating relevant intelligence into detection and hunting strategies.
  • Automation & Orchestration: Build Python scripts, API integrations, enrichment workflows, and SOAR automation using platforms such as Tines, XSOAR, or equivalent. Develop workflows that reduce manual effort and accelerate investigation and containment while maintaining appropriate guardrails and logging.
  • Cloud & Container Security Monitoring: Monitor and investigate security signals across AWS, GCP, and Azure, including CloudTrail, GuardDuty, and cloud audit logs. Identify container and Kubernetes runtime anomalies and contribute to monitoring cloud-native attack surfaces.
  • Agentic & AI-Assisted Workflows: Evaluate and implement AI-assisted security workflows, including LLM-based investigation and autonomous triage capabilities. Assess AI-generated detection logic while maintaining appropriate human oversight and guardrails.
  • Playbooks & Documentation: Develop and refine detection playbooks, investigation procedures, automated security playbooks, and operational runbooks to improve consistency, investigation rigor, and response effectiveness.
  • Security Operations Development: Help build detection content addressing threats such as credential abuse, privilege escalation, lateral movement, cloud misuse, insider risk, sensitive data movement, and unauthorized access.
  • Detection-as-Code & Automation Infrastructure: Contribute to Git-backed detection repositories, CI/CD processes, testing frameworks, enrichment pipelines, remediation workflows, and response automation designed to reduce analyst toil and improve response times.
  • Global Collaboration: Partner with global Security Operations teams and contribute to a SOC culture focused on operational excellence, collaboration, knowledge sharing, and continuous improvement.
  • We are primarily an in-office environment and therefore, you will be expected to work from the Prague, Czech Republic office in compliance with Everpure's policies, unless you are on PTO, work travel, or other approved leave.

WHAT YOU BRING

  • 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related security discipline.
  • 3+ years of hands-on experience executing threat hunts, complex incident investigations, or detection engineering within a SOC or SIEM environment.
  • Deep hands-on experience with Splunk, including search, dashboards, alerts, correlation searches, saved searches, deployment server, and forwarder management.
  • Strong understanding of the complete incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning.
  • Strong knowledge of networking, operating systems, cloud environments, and security architecture across identity, endpoint, network, and cloud.
  • Experience developing Python scripts for data processing, API integrations, security tooling, and automation.
  • Strong understanding of threat intelligence and attacker frameworks, including MITRE ATT&CK, the Diamond Model, kill chains, and TTPs.
  • Hands-on experience with threat hunting methodologies, including hypothesis-driven hunting, behavioral baselines, and anomaly detection.
  • Excellent written and verbal communication skills in English.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.

Strongly Preferred:

  • Detection-as-code experience, including Sigma, ECMA/JSON detection formats, Git-backed detection repositories, unit testing, MITRE ATT&CK coverage mapping, Splunk Security Content, or similar detection frameworks.
  • Hands-on experience with security automation and SOAR platforms such as Tines, XSOAR, Splunk SOAR, or equivalent, including API-driven enrichment and response workflows.
  • Cloud security operations experience across AWS, GCP, and/or Azure, including CloudTrail, GuardDuty, cloud audit logs, and cloud-native attack surfaces.
  • Container and Kubernetes security experience, including Falco, container runtime monitoring, image scanning, vulnerability management, or software supply chain security.
  • Experience evaluating or implementing agentic or AI-assisted security workflows, including LLM-assisted investigations, autonomous triage, or AI-generated detections, with an understanding of appropriate guardrails and human oversight.
  • Experience operationalizing threat intelligence, including PIRs, CTI-to-detection pipelines, and intelligence-driven threat hunting.
  • Experience with Python, Bash, Go, or similar languages and exposure to infrastructure-as-code technologies such as Terraform or CloudFormation.
  • Experience working within follow-the-sun security operations models and with security operations metrics such as MTTD, MTTA, and MTTC.
  • Experience with Attack Surface Management, including secret hygiene, identity attack surface, and Shadow AI.
  • Relevant certifications such as GCIH, GCIA, AWS Security Specialty, CKS, or equivalent.

#LI-ONSITE

WHAT YOU CAN EXPECT FROM US:

  • Innovation: We celebrate those who think critically, like a challenge, and aspire to be trailblazers.
  • Growth: We give you the space and support to grow along with us and to contribute to something meaningful. We have been named Fortune's Best Workplaces in Technology™, Fortune's Best Workplaces in the Bay Area™, and certified as a Great Place to Work®!
  • Team: We build each other up and set aside ego for the greater good.

And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out http://benefits.everpuredata.com/ for more information.

ACCOMMODATIONS AND ACCESSIBILITY:

Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at [email protected] if you’re invited to an interview.

OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM:

We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership.

Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire.

Join us and bring your best.

Bring your bold.

Pure and simple.

Skills Required

  • 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related security discipline.
  • 3+ years of hands-on experience executing threat hunts, complex incident investigations, or detection engineering within a SOC or SIEM environment.
  • Deep hands-on experience with Splunk, including searches, dashboards, alerts, correlation searches, saved searches, deployment server, and forwarder management.
  • Strong understanding of the complete incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning.
  • Strong knowledge of networking, operating systems, cloud environments, and security architecture across identity, endpoint, network, and cloud.
  • Experience developing Python scripts for data processing, API integrations, security tooling, and automation.
  • Strong understanding of threat intelligence and attacker frameworks, including MITRE ATT&CK, the Diamond Model, kill chains, and TTPs.
  • Hands-on experience with hypothesis-driven threat hunting, behavioral baselines, and anomaly detection.
  • Excellent written and verbal communication skills in English.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
  • Detection-as-code experience using Sigma, ECMA or JSON detection formats, Git-backed repositories, unit testing, and MITRE ATT&CK coverage mapping.
  • Hands-on experience with Tines, XSOAR, Splunk SOAR, or equivalent SOAR platforms and API-driven enrichment and response workflows.
  • Cloud security operations experience across AWS, GCP, or Azure, including CloudTrail, GuardDuty, cloud audit logs, and cloud-native attack surfaces.
  • Container and Kubernetes security experience, including Falco, container runtime monitoring, image scanning, vulnerability management, or software supply chain security.
  • Experience evaluating or implementing agentic or AI-assisted security workflows, including LLM-assisted investigations, autonomous triage, or AI-generated detections.
  • Experience operationalizing threat intelligence, including PIRs, CTI-to-detection pipelines, and intelligence-driven threat hunting.
  • Experience with Python, Bash, Go, or similar languages and infrastructure-as-code technologies such as Terraform or CloudFormation.
  • Experience working within follow-the-sun security operations models and with MTTD, MTTA, and MTTC metrics.
  • Experience with Attack Surface Management, secret hygiene, identity attack surface, and Shadow AI.
  • Relevant certifications such as GCIH, GCIA, AWS Security Specialty, CKS, or equivalent.

Everpure Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Everpure and has not been reviewed or approved by Everpure.

  • Equity Value & Accessibility — Equity and stock purchase programs are described as meaningful parts of total compensation, with RSUs and an ESPP highlighted as strengths.
  • Strong & Reliable Incentives — Sales compensation is structured to support long sales cycles, including policies that pay full commission until the first sale for new or white‑space accounts.
  • Healthcare Strength — Health coverage is portrayed as comprehensive, with multiple medical options, fully covered vision, dental PPO choices, mental‑health resources, and company HSA contributions.

Everpure Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Clara, CA
4,090 Employees
Year Founded: 2009

What We Do

Pure Storage (NYSE:PSTG) helps innovators build a better world with data. Pure's data solutions enable SaaS companies, cloud service providers, and enterprise and public sector customers to deliver real-time, secure data to power their mission-critical production, DevOps, and modern analytics environments in a multi-cloud environment. One of the fastest growing enterprise IT companies in history, Pure Storage enables customers to quickly adopt next-generation technologies, including artificial intelligence and machine learning, to help maximize the value of their data for competitive advantage. And with a Satmetrix-certified NPS customer satisfaction score in the top one percent of B2B companies, Pure's ever-expanding list of customers are among the happiest in the world.

Similar Jobs

Benchling Logo Benchling

Account Executive

Cloud • Healthtech • Social Impact • Software • Biotech
Remote or Hybrid
27 Locations
605 Employees

Pfizer Logo Pfizer

Director, AI Platform Product Management

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
163K-272K Annually

Academia.edu Logo Academia.edu

Peer Review Assistant

Consumer Web • Digital Media • Edtech • Information Technology • Social Impact • Software
Remote or Hybrid
26 Locations
110 Employees

Coupa Logo Coupa

Senior Product Manager

Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Hybrid
Prague, CZE
3000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account