Назад
Company hidden
3 часа назад

Security Operations Engineer

91 200 - 118 600$
Формат работы
remote (только USA)
Тип работы
fulltime
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Engineer (Cybersecurity): Monitoring, investigating, and responding to threats across endpoint, identity, network, cloud, SaaS, and application environments with an accent on incident response, detection engineering, and SecOps automation. Focus on building detection logic and response tooling, conducting MITRE ATT&CK-aligned threat hunting, and validating AI-assisted security workflows.

Location: Remote USA

Salary: US base salary of $91,200–$118,600 per year, with potential eligibility for a bonus plan, sales commission or bonus, and equity grants.

Company

Customer-focused organization committed to excellence, integrity, speed, agility, bold innovation, and transparent communication.

What you will do

  • Monitor, triage, investigate, and respond to security alerts across endpoint, identity, network, cloud, SaaS, and application environments.
  • Lead incident response from detection through containment, eradication, recovery, root-cause analysis, and corrective action tracking.
  • Build and tune detection logic across SIEM, EDR, cloud, and network platforms, and conduct MITRE ATT&CK-aligned threat hunting.
  • Develop SecOps scripts, API integrations, tooling, and workflow automations to accelerate investigations and response execution.
  • Apply AI responsibly in security workflows by explaining, validating, testing, and maintaining AI-assisted outputs.
  • Collaborate across functions to close telemetry gaps, improve detection coverage, and implement lasting security improvements.

Requirements

  • Hands-on experience in security operations, incident response, detection engineering, or threat hunting, including leading significant investigations.
  • Strong knowledge of attacker tactics across endpoint, identity, network, cloud, and email environments, including MITRE ATT&CK mapping and IOC analysis.
  • Experience with SIEM platforms and detection queries using KQL, SPL, Sigma, YARA, or equivalent.
  • Experience with EDR/XDR platforms, including alert triage, investigation, and containment.
  • Scripting or automation experience with Python, PowerShell, or Bash, plus experience with at least one cloud platform such as AWS, Azure, GCP, or OCI.
  • Strong understanding of identity security, analytical investigation, evidence-driven work, attention to detail, and communication with technical and non-technical audiences.

Nice to have

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field, or equivalent education and experience.
  • Experience with threat intelligence, malware triage, digital forensics, reverse engineering, vulnerability management, or compliance-driven SecOps.
  • Familiarity with detection-as-code, Git workflows, CI/CD pipelines, and code review practices.
  • Relevant GIAC, OffSec, AWS, Google Cloud, Microsoft, or CompTIA certifications.

Culture & Benefits

  • Rotating schedule providing continuous 24/7/365 security analysis and incident response coverage.
  • Availability for nights, weekends, holidays, and extended hours based on assigned coverage and operational needs.
  • Values-driven environment focused on teamwork, customer outcomes, integrity, speed, agility, innovation, and transparent communication.
  • Potential eligibility for a bonus plan, role-specific commission or bonus, and equity grants.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →