Lands' End

Security Engineer (Remote)

Lands' End Dodgeville, Wisconsin, United States

Retail Apparel and Fashion · 1,001-5,000 employees

3 h ago
Remote security Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer is responsible for designing, implementing, and operating security controls across cloud, identity, endpoint, and network infrastructure. They also manage incident triage, threat investigation, and the automation of security workflows to improve detection and response capabilities.

What they look for

Microsoft Sentinel Microsoft Defender XDR CrowdStrike Falcon Palo Alto Networks Mimecast Microsoft Entra ID KQL PowerShell Incident Response Cloud Security Network Security Zero Trust Vulnerability Management Automation Threat Hunting Identity Security

Requirements

Candidates must have at least 4 years of progressive experience in security engineering or a related technical discipline. A bachelor's degree in a relevant field or equivalent practical experience is required, along with proficiency in Microsoft security technologies and incident management.

Full description

The Security Engineer is a hands-on technical role responsible for designing, implementing, operating, and continuously improving security controls across cloud, identity, endpoint, email, network, data, and hybrid infrastructure. The engineer converts security requirements and threat scenarios into dependable configurations, detections, automations, investigations, and documented operating procedures.

This role partners with Infrastructure, Network, Cloud, IAM, Microsoft 365, Application, Service Desk, Legal, Privacy, Audit, and third-party providers. Success requires disciplined ownership, sound judgment, technical curiosity, clear communication, and the ability to move work from initial intake through validation, implementation, evidence collection, and closure.

Primary Outcomes

• Improved visibility and reduced detection latency for high-impact identity, privilege, endpoint, email, cloud, and network threats.

• Secure, supportable, and well-documented configurations for enterprise security platforms and integrations.

• Timely, evidence-based incident triage, investigation, containment coordination, root-cause analysis, and follow-through.

• Consistent security review of technology changes, firewall requests, cloud deployments, identity changes, and production releases.

• Automation that reduces manual effort, improves data quality, and strengthens repeatability without compromising control or auditability.

• Clear technical ownership, current documentation, defensible change records, and measurable operational health.

Security Engineering and Architecture

• Design, implement, maintain, and improve security controls aligned with Zero Trust, least privilege, defense-in-depth, secure-by-default, and risk-based design principles.

• Provide security design review and technical consultation for cloud, network, identity, endpoint, messaging, data protection, application, and hybrid infrastructure initiatives.

• Translate business, regulatory, and architectural requirements into practical security configurations, standards, baselines, and implementation plans.

• Participate in major technology projects and changes early enough to identify security dependencies, rollback needs, logging requirements, and control gaps before production implementation.

• Evaluate emerging technologies and recommend improvements based on business value, operational supportability, threat reduction, integration fit, and total cost.

Detection Engineering, SIEM and Security Automation

• Engineer and optimize Microsoft Sentinel data connectors, analytics rules, incident creation logic, automation rules, workbooks, watchlists, and Logic Apps or SOAR playbooks.

• Develop and maintain KQL queries for alerting, threat hunting, operational monitoring, troubleshooting, evidence collection, and security reporting.

• Validate source telemetry, connector health, ingestion gaps, parsing, normalization, rule execution, alert grouping, deduplication, and escalation paths.

• Tune detections using documented threat scenarios, severity, expected detection latency, false-positive analysis, query performance, and analyst workload.

• Automate repeatable security administration and response activities with PowerShell, KQL, APIs, and approved orchestration capabilities while preserving approvals and audit trails.

Incident Response and Threat Investigation

• Triage and investigate alerts from Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Mimecast, Palo Alto Networks, identity platforms, and other enterprise sources.

• Correlate identity, endpoint, network, cloud, email, application, and threat-intelligence telemetry to determine scope, impact, chronology, and likely root cause.

• Coordinate containment, eradication, recovery, evidence preservation, and escalation with internal teams, vendors, and managed security partners.

• Document investigative steps, queries, screenshots, findings, decisions, affected assets, communications, and remediation actions in the designated incident record.

• Lead or support high-severity incidents and after-action reviews, including lessons learned, detection improvements, procedure updates, and assigned follow-up actions.

• Participate in an on-call or after-hours rotation as required for significant security events and approved production changes.

Security Platform Operations

• Administer and improve controls across Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Microsoft Entra ID, Microsoft Purview, Mimecast, Palo Alto Networks firewalls and Panorama, and related security technologies.

• Monitor platform health, integration status, licensing or capacity constraints, privileged access, configuration drift, policy exceptions, and vendor escalations.

• Review and validate firewall and connectivity requests, including source, destination, port, protocol, direction, business purpose, data sensitivity, segmentation, logging, ownership, and rollback requirements.

• Support identity security capabilities such as Conditional Access, MFA, Identity Protection, privileged access, access governance, service-account controls, and investigation of anomalous authentication activity.

• Partner with platform owners to address endpoint coverage, cloud posture findings, vulnerability exposure, unsupported systems, and telemetry gaps.

Vulnerability, Change and Risk Management

• Analyze vulnerability and exposure data, validate technical risk, coordinate remediation with system owners, and track material findings through closure or approved risk acceptance.

• Provide security subject-matter expertise for standard, normal, and emergency changes; verify testing, implementation evidence, and post-change validation.

• Support third-party security reviews and technical due diligence by identifying integration risks, required controls, logging expectations, access boundaries, and remediation needs.

• Escalate material control weaknesses, unsupported technology, recurring operational failures, and accepted risks through established governance channels.

Documentation, Audit Support and Collaboration

• Create and maintain security architecture records, standards, procedures, runbooks, playbooks, diagrams, configuration baselines, control narratives, and knowledge articles.

• Produce complete and timely ServiceNow records, change documentation, investigation notes, evidence packages, and status updates that can withstand operational and audit review.

• Support internal and external assessments involving PCI DSS, SOX, NIST, privacy obligations, and other applicable requirements by supplying accurate technical evidence and remediation updates.

• Communicate technical findings and recommendations clearly to engineers, service owners, leadership, auditors, and business stakeholders.

• Mentor developing team members, share investigative methods, and contribute to a unified operating model with clear handoffs, ownership, and follow-through.

Skills

• Hands-on experience with an enterprise SIEM and security analytics, including query development, log-source onboarding, detection tuning, alert investigation, and operational health monitoring.

• Practical experience investigating security events across two or more domains such as identity, endpoint, email, network, cloud, applications, or data.

• Working knowledge of Microsoft cloud and security technologies, including Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, or Purview.

• Working knowledge of enterprise network security concepts, including firewalls, segmentation, VPNs, DNS, TLS, routing, ports and protocols, proxy technologies, and traffic analysis.

• Ability to script or automate technical work using PowerShell, KQL, Python, APIs, JSON, or comparable tools.

• Experience with incident, request, problem, and change-management practices, including accurate ticket documentation and validation of completed work.

• Understanding of NIST security principles and experience supporting regulated or audited environments such as PCI DSS, SOX, privacy, or comparable control frameworks.

• Ability to communicate risk, investigation findings, and technical recommendations to both technical and non-technical audiences.

Qualifications

• Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto Networks firewalls or Panorama, Mimecast, Microsoft Entra ID, Microsoft Purview, and ServiceNow.

• Experience with Azure security engineering, hybrid identity, Microsoft 365 security, email security, cloud posture management, or data protection capabilities.

• Experience building SIEM or SOAR content, custom parsers, automation playbooks, threat-hunting queries, operational dashboards, or detection-as-code practices.

• Experience with vulnerability-management platforms and remediation workflows in a large or complex enterprise.

• Experience in retail, ecommerce, payment environments, customer-data protection, or high-availability digital services.

Education & Experience Requirements

• Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field, or equivalent practical experience.

• At least 4 years of progressive experience in security engineering, security operations, incident response, cloud security, network security, or a closely related technical discipline.

• Relevant certifications such as SC-200, AZ-500, SC-300, SC-400, PCNSE, Security+, GCIH, GCIA, CISSP, or comparable technical credentials.

Similar roles