Senior Security Operations Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Operations Engineer (Cybersecurity): Strengthening security posture through robust security operations and advanced threat detection with an accent on incident management, triage, and detection logic optimization. Focus on designing high-fidelity detection rules, mapping TTPs to the MITRE ATT&CK framework, and conducting security assessments of corporate assets.
Location: Remote - United States
Salary: $128,000 - $200,000
Company
is a data engine for IT and Security, providing solutions to solve the most pressing data needs for some of the most demanding industries.
What you will do
- Lead security incident management, triage, and investigations to remediate threats and prevent future attacks.
- Design, implement, and optimize high-fidelity detection rules and alerts within SIEM and other security platforms.
- Conduct continuous tuning of detection logic to reduce false positives and improve detection efficacy.
- Perform security assessments, vulnerability testing, threat hunts, and purple team activities.
- Build and manage security playbooks incorporating detection engineering best practices.
- Collaborate with threat intelligence teams to integrate new IOCs and TTPs into detection strategies.
Requirements
- Must be based in the United States.
- Experience with modern security principles such as security data lakes, detections as code, EDR, and zero trust networking.
- Strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and mapping detections to TTPs.
- Proficiency in at least one scripting language: Python, NodeJS, Ruby, or Bash.
- Understanding of authentication and authorization schemes (SAML, OpenID, OAuth2, SCIM).
- Proven experience developing and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL).
Nice to have
- Experience with SIEM platforms like Panther and its detection capabilities.
- Familiarity with Wiz and cloud-native security tooling for AWS, Azure, or GCP.
- Relevant certifications in cloud security or incident response (e.g., SANS GIAC).
Culture & Benefits
- Remote-first company culture empowering employees to work from anywhere.
- Comprehensive benefits package including health, dental, vision, short-term disability, and life insurance.
- Financial perks including 401(k), equity, and eligibility for a discretionary company-wide bonus.
- Paid holidays, paid time off, and a fertility treatment benefit.
- A collaborative environment that values diversity, innovation, and a customer-first mindset.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →