Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.
About the Role
Veeam VDC Security Engineering builds and operates the security platform for a multi-cloud (Azure and AWS) SaaS serving regulated industries. This role sits in Security Engineering and helps drive security as a discipline. You will design and operate detection systems that identify threats across our infrastructure, lead response efforts to investigate and remediate security incidents at scale, and drive the vulnerability management program to reduce risk systematically.
Responsibilities
Design and deploy detection rules and analytics across VDC's cloud infrastructure, leveraging SIEM platforms, log aggregation, and behavioral analysis to identify suspicious activity in real-time
Build and operationalize incident response runbooks that automate triage, containment, and remediation workflows while maintaining audit trails for compliance
Develop correlation and detection logic that surfaces real security threats with a low false-positive rate, enabling fast investigation and response without alert fatigue
Own and evolve VDC's vulnerability management program, including scanner integration, severity classification, SLA enforcement, and remediation tracking across infrastructure and applications
Partner with engineering teams to integrate security telemetry, detection hooks, and vulnerability scanning into applications and infrastructure, creating visibility into attack surfaces and threat indicators
Partner with Compliance to ensure detection systems, incident response procedures, and vulnerability tracking generate auditor-facing evidence that holds up under regulatory review (SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST)
Lead threat hunting initiatives to proactively identify compromises, lateral movement, and persistence mechanisms within VDC's environment
Establish and evolve incident response procedures, playbooks, and vulnerability remediation processes across VDC teams, including containment strategies, communication protocols, and post-incident reviews
Technologies You’ll Work With
Microsoft Sentinel and Log Analytics for SIEM, detection rule development, and incident investigation
Azure security services (Azure Defender, Microsoft Defender for Cloud) and AWS security tools (GuardDuty, Security Hub, CloudTrail)
Vulnerability scanning and management tools (Qualys, Tenable, Wiz, or equivalent) for asset inventory and risk quantification
Endpoint detection and response (EDR) platforms and host-based threat monitoring
Cloud audit logs, VPC Flow Logs, and DNS query logs for network-layer threat detection
Python and PowerShell for automation, data processing, and custom detection logic
GitHub Actions and Azure DevOps for CI/CD security integration, automated response actions, and remediation workflows
Incident tracking and ticketing systems for case management and post-incident reporting
What You’ll Bring
8+ years in security operations, threat detection, incident response, or vulnerability management, with recent hands-on experience investigating and responding to security incidents
Proven ability to build detection rules and analytics that effectively identify real threats while maintaining acceptable false-positive rates
Experience designing and implementing incident response workflows, including triage criteria, escalation procedures, and containment strategies
Track record of building and operationalizing vulnerability management programs, including scanner tuning, prioritization frameworks, and remediation SLA enforcement
Strong cloud security fundamentals across Azure and AWS: understanding of attack paths, misconfiguration risks, data exfiltration vectors, and network segmentation
Track record of operationalizing security tools—turning ad-hoc threat hunting and vulnerability remediation into repeatable mechanisms (detection-as-code, automated playbooks, approval gates)
Hands-on experience with SIEM platforms (Sentinel, Splunk, or equivalent) for log analysis, correlation, and alerting
Hands-on experience with vulnerability scanners and asset management platforms for tracking and prioritizing risk
Comfort building automation and response tooling in Python and PowerShell
Familiarity with regulated-industry security requirements and how detection/response/vulnerability procedures generate compliant evidence
Understanding of common attack techniques (lateral movement, privilege escalation, data exfiltration, persistence) and how to detect and prevent them
Demonstrable track record of shipping production code or security automation (code portfolio, open-source contributions, or internal build history). This is a hands-on building role, not an advisory one
Bonus Skills
Experience with threat intelligence integration and using indicators of compromise (IoCs) to drive detections
Background in traditional incident response or forensics that translates to cloud-native environments
Prior work with Azure Sentinel enterprise deployments and advanced analytics
Experience tuning detection and vulnerability management systems in high-volume environments without creating merge-blocking bottlenecks or alert fatigue
Familiarity with attack frameworks (MITRE ATT&CK) and their application to threat modeling, detection strategy, and vulnerability prioritization
LI-SO2
What you'll get
Unlimited paid time off, 12 paid holidays including 4 global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares
Paid parental leave: 8 weeks for all parents, 16 weeks for birthing parents
Medical, dental, and vision coverage starting on your first day
Mental health support, therapy sessions, and digital wellness tools via our Employee Assistance Program
401(k) retirement plan with company matching contributions
Fertility, adoption, and surrogacy support through Maven, plus paid volunteer time
AirVet: 24/7 virtual veterinary care at no cost
Legal services, identity protection, and supplemental health insurance options
Tax-advantaged spending accounts for healthcare, dependent care, and commuting
Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops, and learning events like our annual Global Day of Learning
Conditions
Veeam is committed to pay transparency and equitable compensation. For this role, the compensation range below reflects the expected total target compensation (TTC), inclusive of base pay and a competitive performance-based bonus. For roles with a commission plan, the compensation range represents On Target Earnings (OTE), which includes base salary plus variable commission. When determining compensation, Veeam takes into consideration factors such as experience, education, skills, and geographic zone. Offers are typically made below the midpoint of the range.
In addition to compensation, Veeam provides a comprehensive benefits package, including health coverage, retirement plans, and unlimited time off.
$289,320 - $537,360 USD
Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.
By submitting your application, you confirm that the information provided, including any supporting documents, is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification may result in disqualification from consideration or, if discovered after employment begins, termination of employment.