Pleasanton, CA

Salary
—
Posted
Jul 30, 2026
Location
Pleasanton, CA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A senior-level security engineering role at an enterprise organization, focused on designing, implementing, and optimizing endpoint, mobile, and infrastructure security technologies. Day-to-day work spans EDR/XDR platforms, SIEM monitoring, vulnerability management, and incident response, with a cross-functional mandate to embed security into infrastructure, cloud, and application initiatives. Suits an experienced security engineer comfortable owning technical roadmaps and providing Tier III support.

Senior level · 7+ years

Must have (7)
EDR/XDRantivirus/anti-malwareSIEMvulnerability managementWindowsLinuxincident response
Nice to have (8)
CrowdStrikeMicrosoft DefenderTaniumSentinelOneSplunk, Microsoft Sentinel or QradarTenable, Qualys or Rapid7file integrity monitoringmobile device security

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%incident response62%SIEM55%vulnerability management55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 2, 2026. It is a model, not a headcount.

Why we read it this way (7)

No work location is specified in the posting; CBSA and state fields are left blank. The role may be on-site, hybrid, or remote — candidates should confirm directly.

The degree requirement is listed as 'preferred' and explicitly states that relevant certifications may substitute, so no hard degree gate is set.

The title carries no seniority level word, so advertised seniority is Unspecified; however, the 7+ years requirement and Tier III / architecture scope support a Senior classification.

The alt SOC (15-1244) reflects that a portion of the role involves operating and administering endpoint and infrastructure platforms, though the primary framing is security analysis and threat response.

Specific tool names (CrowdStrike, Tanium, SentinelOne, Splunk, Sentinel, QRadar, Tenable, Qualys, Rapid7) appear only under the 'Preferred Technical Skills' section and are therefore marked preferred. The broader capability categories they represent (EDR/XDR, SIEM, vulnerability management) are required per the Required Qualifications section.

The posting names 'incident response' as a concrete required capability; it is retained as a skill because it maps to a specific, recognized security discipline with associated tooling, not merely a generic responsibility.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): security automation.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗