Lead Security Engineer | US Remote
United States
Applications have closed
Coalfire
Coalfire is the cybersecurity advisor that combines extensive cloud expertise, technology, and innovative approaches to help clients develop scalable programs that improve their security posture and fuel their continued success.What You'll Do
- Be a point of escalation for our 24x7x365 security monitoring for multiple clients while working closely with DevOps and product teams
- Work across a myriad of technology stacks in leading cloud providers like AWS, Azure, and GCP
- Automate/Oversee the process to analyze security events using logs and open-source knowledge to determine legitimate or false positive nature
- Maintain a record of security monitoring activities via case management and ticketing technologies
- Develop processes & best practices/procedures for intrusion detection, file integrity, endpoint protection, log management and SIEM solutions
- Develop overall architecture and standards for security tools using a wide variety of data sources that use various protocols
- Set standards for environment-specific rules, alerts, and dashboards in SIEM tooling via custom queries
- Consult with clients to customize and configure SIEM tools in order to meet security and compliance requirements.
- Support incident response process to address security anomalies in the environment.
- Apply technical writing skills to create formal documentation such as analytical reports and briefings
- Develop and maintain standard operating procedures and training materials
- Participate in on-call rotations as needed to support client operational needs that may lay outside of business hours
- Conduct testing and data reviews to evaluate the effectiveness of current security and operational measures
- Lead the administration and maintenance of SIEM, Log Management, and Data Analytical Platform
- Conduct System Health Checks on managed technologies and provide recommendations on performance improvements.
- Schedule and run regular technical changes such as version updates, security patches, major software releases following best practices for change management policies and procedures
- Lead the resolution for customer-initiated requests such as Log Source configuration, App installation, Data Parsing, Use Case Development, and Troubleshoot complex issues for managed technologies.
- Develop technical solutions to automate repeatable tasks
- Provide overall guidance, instruction, and leadership to the Security Analysts
- Areas of responsibility will include onboarding new data sources, developing alerting, developing run books, conducting security investigations, responding to incidents, and deploying security solutions in a rapidly growing environment
What You'll Bring
- BS or above in related Information Technology field or equivalent combination of education and experience
- 5-7 years experience in 24x7x365 production security operations
- 5-7 years experience administering and operating security tooling such as SIEM, IDS, and endpoint protection
- 4+ years of hands-on technical experience supporting cloud operations and automation in Azure, AWS, and/or GCP
- Must have ELK stack experience
- Experience with ITSM solutions such as Jira and ServiceNow
- Certifications such as Splunk Enterprise Certified Admin/Splunk Power User or ELK Certification.
- Proven experience configuring, implementing, and supporting Splunk Enterprise components deployed in the Cloud
- Knowledge of scripting languages such as Python
- Understanding of regular expression and query languages
- Practical experience in administration of Linux infrastructure.
- Experience in Information Security with a focus on incident response and security engineering
- Experience analyzing events or incidents to triage the issue, find the root cause through log and forensic analysis, and determine security vulnerabilities, attacker exploit techniques, and methods for their remediation.
- Experience developing playbooks, run books, troubleshoot technical issues, and recognize and identify patterns
- Experience with AWS and vendor SaaS Integrations
- Experience with automation, building security, and/or deploying tools
- Proficiency with infrastructure as code, such as Terraform
- Excellent communication, organizational, and problem-solving skills in a dynamic environment
- Effective documentation skills, to include technical diagrams and written descriptions
- Ability to work independently and as part of a team with professional attitude and demeanor
Bonus Points
- ELK Certification
- EC-Council Certified Security Analyst (ECSA) or Certified SOC Analyst (CSA), CompTIA Cybersecurity Analyst (CySA+), GIAC certifications
- Splunk Certified Enterprise Security Admin certification
- Splunk Core Certified Advanced Power User certification
- Previous experience supporting a 24x7x365 security operations for a SaaS vendor
- Experience contributing to security incident handling and investigation, and/or system scenario recreation
- Experience in malware analysis, threat intelligence, forensics, or penetration testing
- Familiarity with Kali Linux, Wireshark, Metaspolit, IDA Pro, or open-source debuggers
- Familiarity with frameworks such as FedRAMP, FISMA, SOC, ISO, HIPAA, HITRUST, PCI, etc.
- Experience with vulnerability management tools and data to ensure secure, patched system resources
Tags: Automation AWS Azure Cloud Compliance CompTIA CySA+ DevOps ECSA ELK Exploit FedRAMP FISMA Forensics GCP GIAC HIPAA HITRUST IDS Incident response Intrusion detection Jira Kali Linux Malware Monitoring Pentesting Python SaaS Scripting SIEM SOC Splunk Terraform Threat intelligence Vulnerabilities Vulnerability management
Perks/benefits: Career development Competitive pay Equity Flex hours Flex vacation Health care Home office stipend Salary bonus Startup environment Team events
More jobs like this
Explore more InfoSec/Cybersecurity career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.
- Open Information Security Specialist jobs
- Open Security Architect jobs
- Open Senior Cybersecurity Engineer jobs
- Open Security Operations Analyst jobs
- Open Senior SOC Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Security Operations Engineer jobs
- Open IT Security Engineer jobs
- Open Information System Security Officer (ISSO) jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Head of Information Security jobs
- Open IT Security Analyst jobs
- Open Cyber Hunt SME jobs
- Open Security Consultant jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Security Specialist jobs
- Open Staff Application Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Manager Pentest H/F jobs
- Open Lead Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Senior Security Analyst jobs
- Open Senior Penetration Tester jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open Risk assessment-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Clearance-related jobs
- Open Kubernetes-related jobs
- Open DevOps-related jobs
- Open Vulnerability management-related jobs
- Open DevSecOps-related jobs
- Open IAM-related jobs
- Open Java-related jobs
- Open SaaS-related jobs
- Open CISM-related jobs
- Open APIs-related jobs
- Open Forensics-related jobs
- Open Analytics-related jobs
- Open CI/CD-related jobs
- Open Malware-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Terraform-related jobs
- Open IDS-related jobs
- Open OWASP-related jobs