Security Engineer - SecOps
Atlanta, GA - Remote
JumpCloud
JumpCloud's revolutionary directory unifies device and identity on Windows, Mac, and Linux with cloud based SSO, MDM, MFA, PAM, and more.Primary Responsibilities/Duties:
- Execute, develop, and document incident management runbooks and processes
- Prepare incident reports of analysis methodology and results.
- Prioritizes events using existing tools to correlate data for the purpose of reducing false positives and detecting threats
- Analyze and tune security alerts and interpret events, as well as create new signals based on signatures and behavioral activities
- Respond to security incidents, lead investigations, and perform forensics on IT systems as necessary.
- Assist with implementation of counter-measures or mitigating controls
- Recognize potential, successful, and unsuccessful intrusion attempts and potential compromises through thorough reviews and analyses of relevant event detail and summary information
- Partner with key stakeholders and communicate effectively to continuously improve the feedback loop of preparation, identification, analysis, containment, and post mortem activities.
- Prepare executive summaries and conduct briefings on significant investigations.
Additional Responsibilities/Opportunities for growth:
- Depending on your skillset and interest level, the following responsibilities are available to all members of the security team.
- Contribute to our Threat Modeling and Threat Assessment efforts
- Partner with engineering teams to promote secure coding practices
- Pentesting and Red Team Operations
Qualifications And Skills
- Expertise in building and operating security information/event management systems (SIEM), centralized logging, and enrichment solutions (Endpoint protection/detection, Network telemetry data, ELK, DataDog, Snowflake, AWS services, HR systems, codebase infrastructure, build infrastructure).
- Expertise with Linux, Windows, and MacOS security and best practices
- Practical experience working with AWS and knowledge of AWS security best practices
- Ability to automate workflows via scripting languages: Python, Go, & Shell
- Superb communication skills and capacity; ability to partner effectively with diverse company stakeholders.
- Active and current knowledge of campaign behavior, trending threats, IoCs, TTPs, and mitigation techniques as blue team operations
- Competency in integrating Threat data, enrichments, for higher-value outcomes and behavioral situational awareness.
- Industry certifications such as GCIH, GCIA, CFCE, GFCA and/or GCFE a plus
Personal Characteristics
- Views security as an enabler, not an inhibitor to innovation
- Results oriented
- High Level of Integrity
- Ownership and Accountability
- High Level of Autonomy
- Clear Communication
- Creative Problem Solver
- Passionate about Security
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Blue team CFCE Cloud CrowdStrike DevOps ELK Forensics GCFE GCIA GCIH Incident response Linux MacOS Pentesting Python Red team SaaS Scripting SecOps SIEM TTPs Windows
Perks/benefits: Career development Startup environment Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open SOC Analyst jobs
- Open Senior Cybersecurity Engineer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open IT Security Analyst jobs
- Open Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cyber Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Security Operations Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Senior SOC Analyst jobs
- Open Product Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Staff Information Security Engineer jobs
- Open o365 Security Architect jobs
- Open Infosec Risk Manager jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Fortinet Firewall Engineer jobs
- Open Cyber Security Architect jobs
- Open Ingénieur DevSecops H/F jobs
- Open Application security-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open SaaS-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open Java-related jobs
- Open Analytics-related jobs
- Open ISO 27001-related jobs
- Open Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISM-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open APIs-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open Malware-related jobs
- Open Splunk-related jobs
- Open Kubernetes-related jobs
- Open CISA-related jobs
- Open DevSecOps-related jobs
- Open Terraform-related jobs
- Open IDS-related jobs
- Open GDPR-related jobs