Claroty is a company dedicated to securing mission-critical systems and protecting national infrastructure. They are looking for a detail-oriented Security Operations Engineer (FedRAMP) to support adherence to FedRAMP requirements and manage security monitoring within a FedRAMP-authorized environment.
Responsibilities:
- Ownership of our Splunk and Trend Micro environments
- Maintain standards across all daily SecOps and JIRA ticketing
- Assist with Entra ID related tasks (user access, SSO integrations, etc)
- Architect high-fidelity logging by managing Splunk data models and CIM mapping to ensure deep root-cause analysis
- Leverage scripting to automate routine tasks, allowing the team to pivot quickly from audits to active investigations
- Bridge the gap between technical complexity and business needs by explaining critical issues to non-technical stakeholders
- Support the expansion of our Public Sector practice by securing mission-critical systems and protecting national infrastructure
Requirements:
- Minimum of 2+ years of Spunk Administration experience: comfortable managing data models and CIM mapping
- Hands-on experience with Trend Micro Deep Security or Cloud One Workload Security, specifically in auto-scaling cloud environments
- Strong proficiency in AWS (GuardDuty, CloudTrail, Config)
- Ability to automate tasks using Python, Bash, or PowerShell to reduce manual toil in the SOC recommended
- Hands on experience with IDP (Entra ID) and managing user access and group policies. SAML/SSO federation and implementation experience
- U.S. Citizenship (required for working in GovCloud environments)
- Experience in a FedRAMP Moderate or High environment
- Splunk Power User or Admin certification