Sr. Cyber Security Engineer
Sign up free to see how well your resume matches this role.
What you'll do
- Conduct rapid host-level triage on enterprise endpoints and servers following alert detection, evaluating events through an adversary's perspective .
- Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains, validate threats, and differentiate legitimate administrative behavior from active exploitation .
- Identify adversary tradecraft, host persistence mechanisms, credential theft attempts, and local privilege escalation vectors across Windows, Linux, and macOS platforms .
- Analyze Windows and Linux host telemetry, file system architecture, administrative structures, and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging .
- Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams .
What they're looking for
- Minimum 4 years of hands-on security operations center (SOC) or threat response experience .
- Operational proficiency with Palo Alto Cortex XSIAM for log correlation, threat hunting, and incident triage .
- Firm understanding of Windows OS internals, file system architecture, and host telemetry to evaluate security alerts and trace execution paths .
- Solid grasp of Linux file system hierarchies, administrative structures, and native logging mechanisms to investigate server anomalies and host-level misconfigurations .
- Practical understanding of offensive methodologies, including local host enumeration, credential harvesting techniques, and privilege escalation pathways .
Nice to have
- 6+ years of experience in a dedicated SOC, Threat Management, Incident Response, or Penetration Testing role .
- Practical experience conducting penetration tests, security assessments, or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins) .
- Practical familiarity with macOS file system layout, native configuration file formats, and common host persistence vectors .
- Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks .
- Professional industry certifications such as OSCP, PNPT, GPEN, GCIH, GCFA, GCFE, CySA+, or equivalent offensive/defensive credentials .
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
Powering the agentic revolution in travel. Sabre is an AI-native technology leader, backed by one of the world’s largest travel data clouds. Built on an open, modular, cloud-native architecture, Sabre serves as the backbone for both established leaders and bold, new disruptors, guiding them to the next age of travel retailing through intelligent, connected, and personalized experiences. With AI at its core and operating at unparalleled scale, Sabre transforms insights into innovation, empowering airlines, hoteliers, agencies and other partners to retail, distribute and fulfill travel worldwide.
Sr. Cyber Security Engineer
- Conduct rapid host-level triage on enterprise endpoints and servers following alert detection, evaluating events through an adversary's perspective.
- Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains, validate threats, and differentiate legitimate administrative behavior from active exploitation.
- Identify adversary tradecraft, host persistence mechanisms, credential theft attempts, and local privilege escalation vectors across Windows, Linux, and macOS platforms.
- Analyze Windows and Linux host telemetry, file system architecture, administrative structures, and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging.
- Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams.
- Minimum 4 years of hands-on security operations center (SOC) or threat response experience.
- Operational proficiency with Palo Alto Cortex XSIAM for log correlation, threat hunting, and incident triage.
- Firm understanding of Windows OS internals, file system architecture, and host telemetry to evaluate security alerts and trace execution paths.
- Solid grasp of Linux file system hierarchies, administrative structures, and native logging mechanisms to investigate server anomalies and host-level misconfigurations.
- Practical understanding of offensive methodologies, including local host enumeration, credential harvesting techniques, and privilege escalation pathways.
- 6+ years of experience in a dedicated SOC, Threat Management, Incident Response, or Penetration Testing role.
- Practical experience conducting penetration tests, security assessments, or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins).
- Practical familiarity with macOS file system layout, native configuration file formats, and common host persistence vectors.
- Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks.
- Professional industry certifications such as OSCP, PNPT, GPEN, GCIH, GCFA, GCFE, CySA+, or equivalent offensive/defensive credentials.
- Competitive pay and performance-based bonuses
- Flexible work options
- Comprehensive healthcare coverage
- Generous PTO and holidays
- Strong retirement planning support
- Family-friendly benefits
- Professional development opportunities
Reasonable Accommodation
Sabre is committed to working with and providing reasonable accommodation to applicants with disabilities. Applicants applying for a Sabre position with a disability who require a reasonable accommodation for any part of the application or hiring process may contact Sabre at recruiting@careers.sabre.com.
Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
Equal Employment Opportunity
Sabre is an equal employment opportunity employer and is committed to providing employment opportunities to minorities, females, veterans and disabled individuals. EEO IS THE LAW
#LI-Hybrid#LI-BG1
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.