Role Overview
- Monitor and triage security alerts from SIEM, EDR, and other tools; escalate and respond as needed.
- Investigate security incidents, determine root cause, document findings, and develop IOCs to prevent recurrence.
- Support escalations from internal employees or customers with security-related concerns.
- Assist with security reviews related to infrastructure and system changes.
- Build, enhance, and maintain internal security tooling and scripting repositories.
- Contribute to the development of detection content, alert tuning, and automation pipelines.
- Drive annual security team goals and cross-functional initiatives.
- Author and maintain clear, actionable documentation and knowledge bases.
- Mentor junior team members and share expertise across the organization.
- Participate in a rotating on-call schedule for security operations support.
Requirements
- 5+ years of experience in a security engineering or operations role.
- Bachelor or Master’s degree in Computer Science, Electrical Engineering, Computer Engineering, or equivalent related work experience
- Deep expertise in Windows and Linux operating systems.
- Proficiency in one or more scripting languages: Python, PowerShell, JavaScript, Bash.
- Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, etc.).
- Hands-on experience with cloud platforms (AWS, Azure, or GCP) — cloud security knowledge preferred.
- Familiarity with virtualization technologies and associated security controls.
- Demonstrated experience in at least one of the following:
- Penetration Testing: Offensive security and exploitation techniques.
- Digital Forensics: Host, network, or memory-based investigation.
- Threat Hunting: Detection engineering and hypothesis-driven threat investigation.
- Knowledge of modern security tooling (SIEM, EDR, vulnerability management, SOAR).
- Strong documentation and communication skills; fluent in written and spoken English.
Tech Stack
- AWS
- Azure
- Cloud
- DNS
- Google Cloud Platform
- JavaScript
- Linux
- Python
- TCP/IP
Benefits
We hire, promote, and compensate employees based on their ability to perform their job responsibilities, without regard to race, color, creed, religion, sex, gender, marital status, national origin, ancestry, age, citizenship, physical or mental disability, sexual orientation, or any other basis protected by applicable law (collectively referred to in our Code of Conduct as “Protected Classes”). We do not tolerate employment discrimination in the workplace, and we are committed to making reasonable accommodations for identified disabilities or other limitations as required by all applicable laws. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status