Sr. Cyber Security Engineer
Sabre Corporation Dallas, Texas, United States
Technology, Information and Internet · 5,001-10,000 employees
About the role
The Sr. Cyber Security Engineer will conduct rapid host-level triage and threat validation across multi-platform environments to identify and neutralize active threats. They will reconstruct attack chains using telemetry and provide actionable intelligence to support incident response teams.
What they look for
Requirements
Candidates must have at least 4 years of experience in a SOC or threat response role with operational proficiency in Palo Alto Cortex XSIAM. A strong understanding of Windows and Linux OS internals, file system architecture, and offensive methodologies is required.
Benefits
Full description
Powering the agentic revolution in travel. Sabre is an AI-native technology leader, backed by one of the world’s largest travel data clouds. Built on an open, modular, cloud-native architecture, Sabre serves as the backbone for both established leaders and bold, new disruptors, guiding them to the next age of travel retailing through intelligent, connected, and personalized experiences. With AI at its core and operating at unparalleled scale, Sabre transforms insights into innovation, empowering airlines, hoteliers, agencies and other partners to retail, distribute and fulfill travel worldwide.
Sr. Cyber Security Engineer
We are seeking a Sr. Cyber Security Engineer to join our global Cybersecurity team, where innovation knows no borders. This team protects Sabre’s critical architecture, cloud environments, and travel technology platforms from emerging threats while enabling secure business innovation. With an inclusive culture and flexible work environment, we work together with boldness, curiosity and commitment so we can all win together.
As a Sr. Cyber Security Engineer, you will focus on the rapid triage, correlation, and validation of security alerts across multi-platform environments to accelerate threat detection and containment. You will evaluate telemetry through both defensive monitoring and an attacker’s perspective to trace execution paths and identify host-level weak points. This role requires strong host analysis capabilities, operational proficiency in log correlation tools, and the technical confidence to isolate and neutralize active threats across enterprise systems.
What you'll do
• Conduct rapid host-level triage on enterprise endpoints and servers following alert detection, evaluating events through an adversary's perspective.
- Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains, validate threats, and differentiate legitimate administrative behavior from active exploitation.
- Identify adversary tradecraft, host persistence mechanisms, credential theft attempts, and local privilege escalation vectors across Windows, Linux, and macOS platforms.
- Analyze Windows and Linux host telemetry, file system architecture, administrative structures, and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging.
- Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams.
What you'll bring
Required qualifications
• Minimum 4 years of hands-on security operations center (SOC) or threat response experience.
- Operational proficiency with Palo Alto Cortex XSIAM for log correlation, threat hunting, and incident triage.
- Firm understanding of Windows OS internals, file system architecture, and host telemetry to evaluate security alerts and trace execution paths.
- Solid grasp of Linux file system hierarchies, administrative structures, and native logging mechanisms to investigate server anomalies and host-level misconfigurations.
- Practical understanding of offensive methodologies, including local host enumeration, credential harvesting techniques, and privilege escalation pathways.
Preferred qualifications
• 6+ years of experience in a dedicated SOC, Threat Management, Incident Response, or Penetration Testing role.
- Practical experience conducting penetration tests, security assessments, or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins).
- Practical familiarity with macOS file system layout, native configuration file formats, and common host persistence vectors.
- Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks.
- Professional industry certifications such as OSCP, PNPT, GPEN, GCIH, GCFA, GCFE, CySA+, or equivalent offensive/defensive credentials.
Benefits that support you
We know support looks different for everyone. That is why Sabre offers benefits beyond medical and financial coverage, with programs designed to support your well-being, growth and life outside work:
• Competitive pay and performance-based bonuses
- Flexible work options
- Comprehensive healthcare coverage
- Generous PTO and holidays
- Strong retirement planning support
- Family-friendly benefits
- Professional development opportunities
Reasonable Accommodation
Sabre is committed to working with and providing reasonable accommodation to applicants with disabilities. Applicants applying for a Sabre position with a disability who require a reasonable accommodation for any part of the application or hiring process may contact Sabre at recruiting@careers.sabre.com.
Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
Equal Employment Opportunity Sabre is an equal employment opportunity employer and is committed to providing employment opportunities to minorities, females, veterans and disabled individuals. EEO IS THE LAW
#LI-Hybrid#LI-BG1
Similar roles
-
Security Engineer, Offensive Security
Anthropic San Francisco, California, United States · $300K–$320K/yr
-
Senior Application Security Engineer (Blue Team)
Altruist Los Angeles, California, United States · $170K–$225K/yr
-
Senior Application Security Engineer (Red Team)
Altruist Los Angeles, California, United States · $170K–$225K/yr
-
Principal Security Engineer
Altruist Los Angeles, California, United States · $203K–$285K/yr
-
Senior Cloud Security Engineer
Altruist Los Angeles, California, United States · $170K–$225K/yr
-
Cybersecurity Supply Chain Risk Management Analyst - Top Secret Clearance
Maania Consultancy Services Washington, District of Columbia, United States