{"schemaVersion":"jobsearcher.job.v1","id":"1564d5eb4c8e5ddb3f7b35bb","url":"https://jobsearcher.com/jobs/1564d5eb4c8e5ddb3f7b35bb","canonicalUrl":"https://jobsearcher.com/jobs/1564d5eb4c8e5ddb3f7b35bb","title":"Advanced Security Engineer, Enterprise Security","description":"Posting Type\nRemote/Hybrid\nJob Overview\nThe Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design, deployment, implementation and optimization of AI-enabled security technologies at all layers. With the goal of enabling automated orchestration of security operations into day-to-day detection and response capabilities, hardening rigor, and rapid response. This role works closely with the Senior Manager of Enterprise Security and cross-functional engineering teams to reduce the organization’s attack surface, enable threat landscape adaptability, and improve detection and response times across Relativity’s technical ecosystem.\nJob Description and Requirements\nLayered Defense/Defense in Depth\nAs applicable, design, deploy and optimize security controls that span perimeter, network, host, application, identity and data layers, ensuring and maintaining effectiveness of controls at each layer.\nCollaborate cross-functionally to ensure controls are aligned to industry recognized frameworks.\nValidate that telemetry from each layer feeds the central analytics platforms and supports 360-degree visibility and appropriate attack surface coverage.\nContinuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly.\nProactively partner with IT, Engineering and other stakeholders to embed security controls natively.\nPeriodically provide recommendations on technical design of security controls aligned to vulnerabilities, risks, issues and/or events.\nSupport purple-team exercises and control-efficacy testing to verify depth and resilience under attack conditions.\nEnsure redundant, complementary security capabilities to prevent bypasses and ensure failure redundancy through all security layers.\n\nEndpoint Security & Hardening\nDeploy, integrate, optimize and manage EDR/XDR platforms and periodically define custom detections and automated response actions across security tooling.\nEstablish and enforce endpoint and image hardening baselines, configuration standards, and application control baselines.\nIntegrate endpoint telemetry into the central analytics platform (or SIEM) to support security context and cross-domain correlation; ensure SIEM coverage is adequate and effective.\nCollaborate cross-functionally to ensure security events, exposures, vulnerabilities and alerts are remediated within appropriate SLA’s.\nInvestigate endpoint-based alerts and incidents through to root cause: perform triage, forensic artifact collection (memory, disk, logs), timeline reconstruction, and containment/eradication actions.\n\nThreat Hunting\nCollaborate cross-functionally to support purple team exercises and analyze security telemetry to surface anomalous and malicious behavior to the relevant stakeholders.\nDevelop, execute and document structured hunts mapped to MITRE ATT&CK and ATLAS techniques and current threat intelligence.\nPerform exposure analysis on identified vulnerabilities, zero-day, alert telemetry, threat intelligence feeds and notifications from partners and customers and conclude on exploitability risk and/or exposure.\nMaintain awareness of the evolving threat landscape, adversary TTP’s, and emerging vulnerabilities and their relevance to Relativity’s technical ecosystem and organizational trajectory.\nStandardize and document hunt methodology, hypotheses, and outcomes and collaborate with security stakeholders to mature threat hunting program over time.\nConvert successful hunts, exposure analysis, purple team findings and alerts into durable, automated detections and containment logic and improved coverage.\n\nAI-Enabled Security Operations\nBuild and maintain SOAR workflows that automate enrichment, triage, containment, and routine response actions.\nMeasure and continuously improve the impact of automation on time-based detection, containment and response to reduce threat actor dwell time.\nIdentify, evaluate and operationalize AI/ML capabilities for semantic anomaly detection, behavioral analytics, alert triage, and prioritization.\n\nData Security\nImplement data classification, discovery, and data security posture management across cloud and on-premises stores.\nDeploy and tune data loss prevention controls across endpoints, network, email, cloud and SaaS surfaces.\nInvestigate data key risk indicators associated with data access, exfiltration, and integrating data telemetry into central analytics (SIEM).\n\nMinimum Qualifications:\nBachelor's in Computer Science, Information Security, or equivalent experience.\n5+ years of hands-on experience in enterprise security engineering, with a focus on network and/or endpoint security domains (or) Master’s Degree in Cybersecurity or relevant field.\nHands-on experience with common security tools such as EDR, XDR, SIEM, CNAPP, CSPM, CWP, etc. and intermediate knowledge of applicable security technologies at all layers of the OSI model.\nThreat hunting, digital forensics, and/or detection engineering experience and writing automation scripts and rules for security enforcement and/or observability.\nBasic knowledge of industry standard common security benchmarks and frameworks (e.g., MITRE, NIST, etc.)\nProficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI based commands, and/or security specific use cases.\nAbility to communicate technical findings clearly to both engineering peers and non-technical stakeholders.\n\nPreferred Qualifications:\nFamiliarity with AI-enabled SecOps (e.g., detection: UEBA, ML-based alert prioritization, or AI-assisted threat hunting workflows)\nBasic knowledge of common cloud environments such as AWS, Azure or GCP.\nWorking knowledge of software development lifecycle, software engineering practices or infrastructure as code environments: contributing endpoint or network security controls to CI/CD pipelines.\nExperience supporting compliance and audit requirements (SOC 2, ISO 27001, HIPAA) from a technical control perspective.\nRelevant certifications such as SEC+, CISSP, CISA, GCIH, GCFA, GCIA, GPEN, OSCP, CySA+, or equivalent.\nRelativity is committed to competitive, fair, and equitable compensation practices.\nThis position is eligible for total compensation which includes a competitive base salary, an annual performance bonus, and long-term incentives.\nThe expected salary range for this role is between following values:\n$104,000 and $156,000\nThe final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position.\nRequired Skills:\nEndpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation, Security Information, Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability Management","company":"Relativity","rawCompany":"relativity","city":"Round Lake","state":"IL","isRemote":false,"isActive":false,"createdAt":"2026-08-17T13:35:13.533Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Advanced Security Engineer, Enterprise Security","description":"Posting Type\nRemote/Hybrid\nJob Overview\nThe Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design, deployment, implementation and optimization of AI-enabled security technologies at all layers. With the goal of enabling automated orchestration of security operations into day-to-day detection and response capabilities, hardening rigor, and rapid response. This role works closely with the Senior Manager of Enterprise Security and cross-functional engineering teams to reduce the organization’s attack surface, enable threat landscape adaptability, and improve detection and response times across Relativity’s technical ecosystem.\nJob Description and Requirements\nLayered Defense/Defense in Depth\nAs applicable, design, deploy and optimize security controls that span perimeter, network, host, application, identity and data layers, ensuring and maintaining effectiveness of controls at each layer.\nCollaborate cross-functionally to ensure controls are aligned to industry recognized frameworks.\nValidate that telemetry from each layer feeds the central analytics platforms and supports 360-degree visibility and appropriate attack surface coverage.\nContinuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly.\nProactively partner with IT, Engineering and other stakeholders to embed security controls natively.\nPeriodically provide recommendations on technical design of security controls aligned to vulnerabilities, risks, issues and/or events.\nSupport purple-team exercises and control-efficacy testing to verify depth and resilience under attack conditions.\nEnsure redundant, complementary security capabilities to prevent bypasses and ensure failure redundancy through all security layers.\n\nEndpoint Security & Hardening\nDeploy, integrate, optimize and manage EDR/XDR platforms and periodically define custom detections and automated response actions across security tooling.\nEstablish and enforce endpoint and image hardening baselines, configuration standards, and application control baselines.\nIntegrate endpoint telemetry into the central analytics platform (or SIEM) to support security context and cross-domain correlation; ensure SIEM coverage is adequate and effective.\nCollaborate cross-functionally to ensure security events, exposures, vulnerabilities and alerts are remediated within appropriate SLA’s.\nInvestigate endpoint-based alerts and incidents through to root cause: perform triage, forensic artifact collection (memory, disk, logs), timeline reconstruction, and containment/eradication actions.\n\nThreat Hunting\nCollaborate cross-functionally to support purple team exercises and analyze security telemetry to surface anomalous and malicious behavior to the relevant stakeholders.\nDevelop, execute and document structured hunts mapped to MITRE ATT&CK and ATLAS techniques and current threat intelligence.\nPerform exposure analysis on identified vulnerabilities, zero-day, alert telemetry, threat intelligence feeds and notifications from partners and customers and conclude on exploitability risk and/or exposure.\nMaintain awareness of the evolving threat landscape, adversary TTP’s, and emerging vulnerabilities and their relevance to Relativity’s technical ecosystem and organizational trajectory.\nStandardize and document hunt methodology, hypotheses, and outcomes and collaborate with security stakeholders to mature threat hunting program over time.\nConvert successful hunts, exposure analysis, purple team findings and alerts into durable, automated detections and containment logic and improved coverage.\n\nAI-Enabled Security Operations\nBuild and maintain SOAR workflows that automate enrichment, triage, containment, and routine response actions.\nMeasure and continuously improve the impact of automation on time-based detection, containment and response to reduce threat actor dwell time.\nIdentify, evaluate and operationalize AI/ML capabilities for semantic anomaly detection, behavioral analytics, alert triage, and prioritization.\n\nData Security\nImplement data classification, discovery, and data security posture management across cloud and on-premises stores.\nDeploy and tune data loss prevention controls across endpoints, network, email, cloud and SaaS surfaces.\nInvestigate data key risk indicators associated with data access, exfiltration, and integrating data telemetry into central analytics (SIEM).\n\nMinimum Qualifications:\nBachelor's in Computer Science, Information Security, or equivalent experience.\n5+ years of hands-on experience in enterprise security engineering, with a focus on network and/or endpoint security domains (or) Master’s Degree in Cybersecurity or relevant field.\nHands-on experience with common security tools such as EDR, XDR, SIEM, CNAPP, CSPM, CWP, etc. and intermediate knowledge of applicable security technologies at all layers of the OSI model.\nThreat hunting, digital forensics, and/or detection engineering experience and writing automation scripts and rules for security enforcement and/or observability.\nBasic knowledge of industry standard common security benchmarks and frameworks (e.g., MITRE, NIST, etc.)\nProficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI based commands, and/or security specific use cases.\nAbility to communicate technical findings clearly to both engineering peers and non-technical stakeholders.\n\nPreferred Qualifications:\nFamiliarity with AI-enabled SecOps (e.g., detection: UEBA, ML-based alert prioritization, or AI-assisted threat hunting workflows)\nBasic knowledge of common cloud environments such as AWS, Azure or GCP.\nWorking knowledge of software development lifecycle, software engineering practices or infrastructure as code environments: contributing endpoint or network security controls to CI/CD pipelines.\nExperience supporting compliance and audit requirements (SOC 2, ISO 27001, HIPAA) from a technical control perspective.\nRelevant certifications such as SEC+, CISSP, CISA, GCIH, GCFA, GCIA, GPEN, OSCP, CySA+, or equivalent.\nRelativity is committed to competitive, fair, and equitable compensation practices.\nThis position is eligible for total compensation which includes a competitive base salary, an annual performance bonus, and long-term incentives.\nThe expected salary range for this role is between following values:\n$104,000 and $156,000\nThe final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position.\nRequired Skills:\nEndpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation, Security Information, Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability Management","datePosted":"2026-08-17T13:35:13.533Z","dateModified":"2026-08-17T13:35:13.533Z","hiringOrganization":{"@type":"Organization","name":"Relativity","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Round Lake","addressRegion":"IL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1564d5eb4c8e5ddb3f7b35bb"},"url":"https://jobsearcher.com/jobs/1564d5eb4c8e5ddb3f7b35bb"}}