Security Engineer III ( developing and tuning SIEM detections, writing threat hunting queries, and participating in incident response)
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.
What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.
Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.
Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.
Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!
What you’ll be doing:
As a Senior Security Engineer in the Security Operations team, you will design, build, and enhance our technical capabilities for detecting, investigating, and responding to threats. You will bridge engineering and operations, transforming security challenges into scalable, automated solutions. Your key responsibilities include:
- SIEM Engineering: Lead the engineering of our SIEM platform, onboard and normalize log sources, build and maintain parsers, and ensure high-fidelity data pipelines for detection and investigation. Continuously improve log coverage, data quality, and platform performance.
- Detection Engineering: Create and maintain a library of high-quality detections using a Detection as Code approach, managing detection content through version control, peer review, and automated testing. Map detections to the MITRE ATT&CK framework and enhance coverage, precision, and resilience against evasion.
- SOAR & Automation: Develop and maintain automated workflows and playbooks using SOAR platforms to streamline alert triage, enrichment, and response. Identify and automate manual processes to enable scalable operations.
- AI-Augmented Security Operations: Explore and implement AI and machine learning to enhance security operations, including alert triage, incident response, threat intelligence analysis, threat hunting, and detection content enrichment. Evaluate and responsibly integrate emerging AI tools into workflows.
- Threat Intelligence Integration: Operationalize threat intelligence from various sources, integrating indicators and adversary context into detection logic, SOAR playbooks, and hunting activities. Ensure actionable intelligence is timely and structured for security operations.
- Threat Hunting: Conduct proactive, hypothesis-driven threat hunts to identify attacker activity that evades existing detections. Document findings and use them to improve detection engineering and tooling.
- Incident Response Support: Provide engineering-level support during security incidents, aiding in investigation, containment, and recovery. Contribute to post-incident reviews and apply lessons learned to enhance detections, playbooks, and tooling.
What you’ll bring to the role:
We seek a technically adept security professional with hands-on experience in building and operating security capabilities in complex environments. The ideal candidate will have:
- Technical Security Experience: Extensive experience in security engineering, DevSecOps, or a similar role, with a solid background in securing cloud-native environments and modern application stacks.
- Detection & Response Skills: Practical experience in developing and tuning SIEM detections, writing threat hunting queries, and participating in incident response.
- SecOps Tooling: Proficiency in administering and operating core security operations tools, including SIEM platforms (e.g., Splunk, Microsoft Sentinel), EDR/XDR solutions, vulnerability scanners, and ticketing systems. Experience integrating these tools for detection, investigation, and response workflows.
- Threat Intelligence & Threat Hunting: Experience with threat intelligence platforms and feeds (e.g., MISP, Recorded Future, VirusTotal), and integrating intelligence into security tooling and operational processes. Familiarity with threat hunting methodologies and the ability to identify indicators of compromise or attacker behavior is highly desirable.
- Scripting & Automation: Proficiency in scripting or programming languages (e.g., Python, Go, Bash) to build security tools, automate workflows, and integrate security capabilities.
- Application Security Knowledge: Understanding of secure development practices, OWASP top risks, and the ability to perform code reviews or collaborate with developers to address security findings.
- Security Frameworks & Standards: Familiarity with relevant security frameworks (e.g., NIST CSF, CIS Benchmarks, MITRE ATT&CK) and compliance standards like SOC 2 or ISO 27001.
Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)
We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day!
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.
Fraud Recruitment Disclaimer
It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.
Anaplan does not:
- Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.
- Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.
All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to people@anaplan.com before taking any further action in relation to the correspondence.
Candidate data processed during our recruitment activities is handled in accordance with our Candidate Privacy Notice. This may include the use of artificial intelligence or automated tools to assist our team in evaluating qualifications.