Sr. Cyber Security Engineer
Dallas, IA - USA
Job Summary
Powering the agentic revolution in travel. Sabre is an AI-native technology leader backed by one of the worlds largest travel data clouds. Built on an open modular cloud-native architecture Sabre serves as the backbone for both established leaders and bold new disruptors guiding them to the next age of travel retailing through intelligent connected and personalized experiences. With AI at its core and operating at unparalleled scale Sabre transforms insights into innovation empowering airlines hoteliers agencies and other partners to retail distribute and fulfill travel worldwide.
- Conduct rapid host-level triage on enterprise endpoints and servers following alert detection evaluating events through an adversarys perspective.
- Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains validate threats and differentiate legitimate administrative behavior from active exploitation.
- Identify adversary tradecraft host persistence mechanisms credential theft attempts and local privilege escalation vectors across Windows Linux and macOS platforms.
- Analyze Windows and Linux host telemetry file system architecture administrative structures and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging.
- Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams.
- Minimum 4 years of hands-on security operations center (SOC) or threat response experience.
- Operational proficiency with Palo Alto Cortex XSIAM for log correlation threat hunting and incident triage.
- Firm understanding of Windows OS internals file system architecture and host telemetry to evaluate security alerts and trace execution paths.
- Solid grasp of Linux file system hierarchies administrative structures and native logging mechanisms to investigate server anomalies and host-level misconfigurations.
- Practical understanding of offensive methodologies including local host enumeration credential harvesting techniques and privilege escalation pathways.
- 6 years of experience in a dedicated SOC Threat Management Incident Response or Penetration Testing role.
- Practical experience conducting penetration tests security assessments or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins).
- Practical familiarity with macOS file system layout native configuration file formats and common host persistence vectors.
- Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks.
- Professional industry certifications such as OSCP PNPT GPEN GCIH GCFA GCFE CySA or equivalent offensive/defensive credentials.
- Competitive pay and performance-based bonuses
- Flexible work options
- Comprehensive healthcare coverage
- Generous PTO and holidays
- Strong retirement planning support
- Family-friendly benefits
- Professional development opportunities
Reasonable Accommodation
Sabre is committed to working with and providing reasonable accommodation to applicants with disabilities. Applicants applying for a Sabre position with a disability who require a reasonable accommodation for any part of the application or hiring process may contact Sabre at .
Determinationson requests for reasonable accommodation will be made on a case-by-case basis.
Equal Employment Opportunity
Sabre is an equal employment opportunity employer and is committed to providing employment opportunities to minorities females veterans and disabled individuals. EEO IS THE LAW
#LI-Hybrid#LI-BG1
Required Experience:
Senior IC
About Company
Sabre Corporation is a travel technology company based in Southlake, Texas. It is the largest Global Distribution Systems provider for air bookings in North America. American Airlines founded the company in 1960, and it was spun off in 2000.