À propos du poste
Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us. THE ROLE Everpure is seeking a hands-on Senior Security Engineer to drive security operations from our Prague, Czech Republic location. In this role, you will contribute to operational excellence across incident response, threat hunting, threat intelligence integration, detection engineering, and security automation, bringing real-time visibility and rapid response to our 24/7 global security operations environment. This is a technical delivery and execution role, not a traditional monitoring position. You will work closely with detection engineers, threat intelligence analysts, incident response leadership, and our global Security Operations teams to build and refine detections, improve signal quality, execute threat hunts, automate workflows, and respond to complex security incidents with speed and precision. Success in this role is measured not by alert volume, but by signal quality, real threat detection, incident containment speed, automation maturity, and the effectiveness of response workflows. WHAT YOU'LL DO - Detection Engineering: Design, implement, and maintain detections in Splunk and related security platforms. Develop detection-as-code content using formats such as YAML/JSON, incorporate unit and regression testing, map coverage to MITRE ATT&CK, and contribute to Sigma/YARA-L coverage expansion. - Incident Response & Triage: Investigate suspicious activity and participate in incident triage, scoping, containment, eradication, recovery, and post-incident reviews. Use lessons from investigations to continuously improve detection and response processes. - Threat Hunting: Execute hypothesis-driven threat hunts using MITRE ATT&CK, the Diamond Model, kill chains, threat intelligence, behavioral baselines, and anomaly detection. Correlate signals across endpoint, cloud, identity, SaaS, network, and other security telemetry to identify real threats and operational blind spots. - Detection Quality: Continuously tune detections to improve true-positive rates and reduce alert fatigue. Identify which signals provide meaningful security value and refine detection logic based on investigation outcomes and changes in the threat landscape. - Threat Intelligence Integration: Operationalize cyber threat intelligence (CTI) by mapping adversary tools, techniques, TTPs, and indicators to the Everpure environment and translating relevant intelligence into detection and hunting strategies. - Automation & Orchestration: Build Python scripts, API integrations, enrichment workflows, and SOAR automation using platforms such as Tines, XSOAR, or equivalent. Develop workflows that reduce manual effort and accelerate investigation and containment while maintaining appropriate guardrails and logging. - Cloud & Container Security Monitoring: Monitor and investigate security signals across AWS, GCP, and Azure, including CloudTrail, GuardDuty, and cloud audit logs. Identify container and Kubernetes runtime anomalies and contribute to monitoring cloud-native attack surfaces. - Agentic & AI-Assisted Workflows: Evaluate and implement AI-assisted security workflows, including LLM-based investigation and autonomous triage capabilities. Assess AI-generated detection logic while maintaining appropriate human oversight and guardrails. - Playbooks & Documentation: Develop and refine detection playbooks, investigation procedures, automated security playbooks, and operational runbooks to improve consistency, investigation rigor, and response effectiveness. - Security Operations Development: Help build detection content addressing threats such as credential abuse, privilege escalation, lateral movement, cloud misuse, insider risk, sensitive data movement, and unauthorized access. - Detection-as-Code & Automation Infrastructure: Contribute to Git-backed detection repositories, CI/CD processes, testing frameworks, enrichment pipelines, remediation workflows, and response automation designed to reduce analyst toil and improve response times. - Global Collaboration: Partner with global Security Operations teams and contribute to a SOC culture focused on operational excellence, collaboration, knowledge sharing, and continuous improvement. - We are primarily an in-office environment and therefore, you will be expected to work from the Prague, Czech Republic office in compliance with Everpure's policies, unless you are on PTO, work travel, or other approved leave. WHAT YOU BRING - 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related security discipline. - 3+ years of hands-on experience executing threat hunts, complex incident investigations, or detection engineering within a SOC or SIEM environment. - Deep hands-on experience with Splunk, including search, dashboards, alerts, correlation searches, saved searches, deployment server, and forwarder management. - Strong understanding of the complete incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning. - Strong knowledge of networking, operating systems, cloud environments, and security architecture across identity, endpoint, network, and cloud. - Experience developing Python scripts for data processing, API integrations, security tooling, and automation. - Strong understanding of threat intelligence and attacker frameworks, including MITRE ATT&CK, the Diamond Model, kill chains, and TTPs. - Hands-on experience with threat hunting methodologies, including hypothesis-driven hunting, behavioral baselines, and anomaly detection. - Excellent written and verbal communication skills in English. - Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience. Strongly Preferred: - Detection-as-code experience, including Sigma, ECMA/JSON detection formats, Git-backed detection repositories, unit testing, MITRE ATT&CK coverage mapping, Splunk Security Content, or similar detection frameworks. - Hands-on experience with security automation and SOAR platforms such as Tines, XSOAR, Splunk SOAR, or equivalent, including API-driven enrichment and response workflows. - Cloud security operations experience across AWS, GCP, and/or Azure, including CloudTrail, GuardDuty, cloud audit logs, and cloud-native attack surfaces. - Container and Kubernetes security experience, including Falco, container runtime monitoring, image scanning, vulnerability management, or software supply chain security. - Experience evaluating or implementing agentic or AI-assisted security workflows, including LLM-assisted investigations, autonomous triage, or AI-generated detections, with an understanding of appropriate guardrails and human oversight. - Experience operationalizing threat intelligence, including PIRs, CTI-to-detection pipelines, and intelligence-driven threat hunting. - Experience with Python, Bash, Go, or similar languages and exposure to infrastructure-as-code technologies such as Terraform or CloudFormation. - Experience working within follow-the-sun security operations models and with security operations metrics such as MTTD, MTTA, and MTTC. - Experience with Attack Surface Management, including secret hygiene, identity attack surface, and Shadow AI. - Relevant certifications such as GCIH, GCIA, AWS Security Specialty, CKS, or equivalent. #LI-ONSITE WHAT YOU CAN EXPECT FROM US: - Innovation: We celebrate those who think critically, like a challenge, and aspire to be trailblazers. - Growth: We give you the space and support to grow along with us and to contribute to something meaningful. We have been named Fortune's Best Workplaces in Technology™, Fortune's Best Workplaces in the Bay Area™, and certified as a Great Place to Work®! - Team: We build each other up and set aside ego for the greater good. And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out http://benefits.everpuredata.com/ for more information. ACCOMMODATIONS AND ACCESSIBILITY: Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at TA-Ops@purestorage.com if you’re invited to an interview. OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM: We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership. Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire. Join us and bring your best. Bring your bold. Pure and simple.