← Back to results

mitre-att-ck jobs in San Diego

Posted 1 day ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements. Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen today
$80,000 – $110,000 · Posted 3 days ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines. The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 3 days ago
$80,000 – $110,000 · Posted 4 days ago

This role is a hands-on cybersecurity engineer responsible for securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications. Key duties include vulnerability scanning and penetration testing, threat modeling, Web Application Firewall (WAF) deployment and tuning, CI/CD security integration (SAST, DAST, SCA), incident response, and compliance support. The engineer will work closely with DevOps and application teams to embed security controls, conduct code and architecture reviews, and provide risk-based guidance. Required experience includes 3–5+ years in cybersecurity or security engineering, hands-on SIEM/EDR/vulnerability management tools, cloud platforms, WAF configuration, and scripting (Python, Bash, PowerShell).

San DiegoLast seen 1 day ago
Posted 8 days ago

This is a hands-on security engineering role focused on running Saronic's cyber threat intelligence program. The engineer will track nation-state and advanced criminal adversaries targeting the defense industrial base, operationalize indicators and TTPs into detections and hunts, produce finished intelligence products, and fuse external threat feeds with internal telemetry to prioritize real exposures. The role requires 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis with demonstrable experience tracking sophisticated or state-sponsored adversaries.

San DiegoLast seen 6 days ago