Senior Security Engineer - Security Operations

Elsevier — United States · Posted ~9 hours ago

Senior Full-time Visa History ✓

Skills

Cloud security engineering Security tooling Security platform engineering Architecture Code review Design review Incident response collaboration Threat engineering collaboration Governance, risk and compliance Technical leadership Terraform GitHub Actions AWS Cloud security Security platforms

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineering role focused on designing, building, and operating security platforms across a cloud environment. The position combines hands-on engineering with architecture ownership, technical mentoring, and collaboration with incident response, threat, compliance, and engineering teams.

Highlights

Design, build, and operate security tooling at scale, own architecture decisions, mentor junior and mid-level engineers, and collaborate closely with incident response, threat engineering, and risk teams.

Description

About our Team You’ll be joining the Security Engineering team within Elsevier’s Information Security & Data Protection department. Our team designs, builds, and operates the security tooling and platforms used across Elsevier Technology, spanning both vendor platforms and team-built services. The team works closely with Incident Response, Threat Engineering, and Governance, Risk & Compliance (GRC), and partners with business and engineering teams to ensure security tooling is effectively adopted across our cloud estate. About the Role As a Senior Security Engineer, you help lead in designing, building, and operating security tooling at scale, while raising the technical bar for the wider team. You will own architecture decisions for one or more platforms, guide junior and mid-level engineers through code and design review, and act as a trusted technical voice with Incident Response, Threat Engineering, and GRC. This role suits someone with deep, hands-on cloud security engineering experience who is ready to take ownership beyond individual delivery, shaping how the team builds and operates security tooling Responsibilities Leading the design, architecture, and delivery of security platforms and services.Owning and evolve Infrastructure as Code standards (Terraform) and CI/CD practices (GitHub Actions) across the team, ensuring reliable, secure, and repeatable deployments.Providing technical leadership and mentorship to junior and mid-level engineers, including design review, code review, and guidance on secure engineering practices.Driving integration, tuning, and lifecycle management of core security tooling.Partnering with Incident Response, Threat Engineering, and GRC to translate emerging threats, incidents, and compliance requirements into engineering solutions and roadmap priorities.Championing adoption of AI-assisted engineering practices (e.g. Claude Code, GitHub Copilot) to improve team velocity, code quality, and test coverage.Leading troubleshooting and root-cause analysis for security tooling incidents, and drive resilience improvements through capacity planning, disaster recovery planning, and runbook development.Representing SENG in architecture reviews and cross-functional technical forums, advocating for secure-by-design and secure-by-default practices.Delivering production-ready systems on time and within budget, and hold the team accountable to engineering and security standards. Requirements We recognize that no one will meet every requirement. If you are excited about this role and have relevant experience, we encourage you to apply. Significant hands-on experience in security engineering or a related field, including designing and operating cloud-native security platforms at production scale.Demonstrated ownership of security architecture in AWS (or OCI/Aliyun), including multi-account environments and cross-region/CN considerations.Advanced proficiency with Terraform and Infrastructure as Code practices, with experience setting standards and patterns for a team.Experience designing and maintaining CI/CD pipelines (e.g. GitHub Actions) for reliability and security.Broad, hands-on experience across security tool categories: SIEM, EDR, DLP, PAM, WAF, SOAR, and vulnerability management,Proven track record mentoring engineers and leading technical design decisions within a team.Advanced scripting and software development skills (e.g. Python), including experience building and operating production services (APIs, cronjobs) on Kubernetes/EKS.Practical experience with AI-assisted engineering tools (e.g. GitHub Copilot, Claude Code, Spec-driven development) and sound judgment on where they add the most value.Experience with Agile and/or DevOps frameworks, including driving improvements to team process and delivery practices.