Job Closed
This listing is no longer active.
Senior Security Operations Engineer
Location
United States
Posted
133 days ago
Salary
$111K - $178K / year
Seniority
Senior
Job Description
Senior Security Operations Engineer
Workiva
• Lead and coordinate responses to security incidents, including ransomware, host compromise, credential and account compromise, phishing, insider threats, third-party risks, and data spillage while collaborating closely with information security leadership, business stakeholders, and the rest of the incident response team • Produce clear, accurate incident documentation and post‑incident analysis focused on root cause and measurable improvement • Participate in incident response tabletop exercises to identify gaps, enhance skills, and engage stakeholders; review technical reports from vulnerability and penetration testing assessments to identify potential exposure to future incidents • Improve Security Operations practices by contributing to the development, refinement, and maintenance of SOC procedures, playbooks, policies, and guidelines • Assess the effectiveness of security controls and technical risks across hosting environments, and communicate findings clearly to both technical and non-technical stakeholders • Own and act as a subject matter expert for one or more core security tools or platforms, ensuring data quality, reliable operation, and effective use.
Job Requirements
- Undergraduate degree or 3 years equivalent combination of experience of education and experience in a related field
- Experience investigating security alerts or incidents involving infrastructure, identity, endpoints, or applications
- In-depth knowledge of cloud environments such as AWS, Azure, and/or GCP, with curiosity to deepen cloud security expertise
- Experience working in security operations, incident response, or a related defensive security role (preferred)
- Familiarity with SIEM platforms (Splunk preferred) and interest in using SOAR tooling such as Tines or other automation functions to improve response workflows (preferred)
- Comfort analyzing logs and telemetry data to understand suspicious or unusual behavior (preferred)
- Ability to assess technical and business risk and communicate findings clearly (preferred)
- Strong written and verbal communication skills, with the ability to explain complex topics to a range of audiences (preferred)
Benefits
- A discretionary bonus typically paid annually
- Restricted Stock Units granted at time of hire
- 401(k) match and comprehensive employee benefits package
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Monitor and analyze log data, network traffic, and/or alerts generated by a variety of security technologies in real-time. • Respond, triage, and escalate security incidents using a SIEM platform following documented procedures. • Support the execution of vulnerability scans and assist in analyzing results for remediation recommendations. • Draft security incident reports detailing the threat, its characteristics, and required remediation activities for review by a senior analyst. • Research new threats and ensure appropriate detection capabilities are in place. • Review security incidents and other deliverables for adherence to established procedures and provide documentation updates as necessary. • Contribute to the quality and timeliness of the security incident detection and classification service. • Ensure standards and procedures are adhered to within defined SLA’s. • Articulate security issues to customers, both verbally and written. • Referring difficult or complex issues to more experienced staff. • Developing an understanding of current vulnerabilities, attacks, and countermeasures. • Identify opportunities for process improvement and suggest them to stakeholders. • Manage and track customer issues and requests within a ticketing system. • Work within a 24x7x365 team to further support the timely delivery of monitoring services. • This position may be assigned to a rotating shift schedule. • Support other teams as needed.
SOC Analyst Intern
ATPCOATPCO is committed to providing the best flight shopping experiences through reliable pricing data and innovative retail technology. Positioning itself as "the foundation of modern
• Monitor security alerts and events using SIEM and other monitoring tools. • Analyze and respond to security incidents, including malware infections, phishing attempts, and unauthorized access. • Triage and prioritize alerts based on severity and potential impact. • Conduct initial investigations and document findings in incident tracking systems. • Collaborate with internal teams to contain and remediate security threats. • Perform root cause analysis and recommend improvements to prevent recurrence. • Create and maintain standard operating procedures (SOPs) and incident response playbooks. • Assist in threat intelligence gathering and correlation with internal events. • Participate in security audits, vulnerability assessments, and compliance efforts. • Stay up-to-date with the latest cybersecurity trends, vulnerabilities, and threat actor tactics.
Analista de Segurança da Informação – Google SecOps
It4us Cyber SecurityGarantindo a Cyber Segurança de nossos amigos e clientes !
• Atuar na operação e evolução do Google SecOps (SIEM / SOAR) • Monitorar, investigar e responder a incidentes de segurança • Criar e ajustar regras, alertas e playbooks de automação • Analisar logs, eventos e indicadores de segurança • Apoiar melhorias contínuas nos processos de SecOps • Trabalhar em parceria com times técnicos e clientes
• Improve AWS security configurations (IAM, GuardDuty, CloudTrail, Amazon Inspector, etc.). • Manage and maintain security tools: EDR, MDM, DLP, compliance agents, etc. • Coordinate with IT to ensure all laptops and endpoints follow security baselines. • Review and respond to SOC provider alerts, investigate incidents, and manage the final remediation phase. • Perform vulnerability management and coordinate patching with IT and DevOps. • Improve and maintain WAF rules, anti-bot protections, and other application-layer defenses. • Support access reviews, PCI-DSS reviews, and quarterly/monthly security tasks. • Document and implement security configurations for cloud and SaaS tools. • Contribute to Backup, DRP, and BCP testing in collaboration with Infra/IT teams. • Provide input to security roadmap planning with practical improvements from operations.



