About this role
Powering the agentic revolution in travel. Sabre is an AI-native technology leader, backed by one of the world’s largest travel data clouds. Built on an open, modular, cloud-native architecture, Sabre serves as the backbone for both established leaders and bold, new disruptors, guiding them to the next age of travel retailing through intelligent, connected, and personalized experiences. With AI at its core and operating at unparalleled scale, Sabre transforms insights into innovation, empowering airlines, hoteliers, agencies and other partners to retail, distribute and fulfill travel worldwide.
Sr. Cyber Security Engineer
We are seeking a Sr. Cyber Security Engineer to join our global Cybersecurity team, where innovation knows no borders. This team protects Sabre’s critical architecture, cloud environments, and travel technology platforms from emerging threats while enabling secure business innovation. With an inclusive culture and flexible work environment, we work together with boldness, curiosity and commitment so we can all win together. As a Sr. Cyber Security Engineer, you will focus on the rapid triage, correlation, and validation of security alerts across multi-platform environments to accelerate threat detection and containment. You will evaluate telemetry through both defensive monitoring and an attacker’s perspective to trace execution paths and identify host-level weak points. This role requires strong host analysis capabilities, operational proficiency in log correlation tools, and the technical confidence to isolate and neutralize active threats across enterprise systems. What you'll do • Conduct rapid host-level triage on enterprise endpoints and servers following alert detection, evaluating events through an adversary's perspective.
• Pivot across Palo Alto Cortex XSIAM telemetry to reconstruct attack chains, validate threats, and differentiate legitimate administrative behavior from active exploitation.
• Identify adversary tradecraft, host persistence mechanisms, credential theft attempts, and local privilege escalation vectors across Windows, Linux, and macOS platforms.
• Analyze Windows and Linux host telemetry, file system architecture, administrative structures, and native logging to trace execution paths and investigate server-side anomalies without requiring full forensic disk imaging.
• Package actionable intelligence and concise event summaries to drive immediate containment or seamless hand-off to Digital Forensics and Incident Response (DFIR) teams.
What you'll bring Required qualifications • Minimum 4 years of hands-on security operations center (SOC) or threat response experience.
• Operational proficiency with Palo Alto Cortex XSIAM for log correlation, threat hunting, and incident triage.
• Firm understanding of Windows OS internals, file system architecture, and host telemetry to evaluate security alerts and trace execution paths.
• Solid grasp of Linux file system hierarchies, administrative structures, and native logging mechanisms to investigate server anomalies and host-level misconfigurations.
• Practical understanding of offensive methodologies, including local host enumeration, credential harvesting techniques, and privilege escalation pathways.
Preferred qualifications • 6+ years of experience in a dedicated SOC, Threat Management, Incident Response, or Penetration Testing role.
• Practical experience conducting penetration tests, security assessments, or privilege escalation research with focus on Living-off-the-Land tactics (LOLBins / GTFOBins).
• Practical familiarity with macOS file system layout, native configuration file formats, and common host persistence vectors.
• Experience building custom queries via Cortex Query Language (XQL) and working with automated orchestration playbooks.
• Professional industry certifications such as OSCP, PNPT, GPEN, GCIH, GCFA, GCFE, CySA+, or equivalent offensive/defensive credentials.
Benefits that support you We know support looks different for everyone. That is why Sabre offers benefits beyond medical and financial coverage, with programs designed to support your well-being, growth and life outside work: • Competitive pay and performance-based bonuses
• Flexible work options
• Comprehensive healthcare coverage
• Generous PTO and holidays
• Strong retirement planning support
• Family-friendly benefits
• Professional development opportunities
Reasonable Accommodation Sabre is committed to working with and providing reasonable accommodation to applicants with disabilities. Applicants applying for a Sabre position with a disability who require a reasonable accommodation for any part of the application or hiring process may contact Sabre at recruiting@careers.sabre.com.
Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
Equal Employment Opportunity Sabre is an equal employment opportunity employer and is committed to providing employment opportunities to minorities, females, veterans and disabled individuals. EEO IS THE LAW
#LI-Hybrid#LI-BG1