Job Closed

This listing is no longer active.

Coalfire logo
Coalfire

Cyber solutions that move you forward, faster.

Senior Technical Manager, Security Operations

Security OperationsSecurity OperationsOtherRemoteSeniorTeam 1,001-5,000Since 2001H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

129 days ago

Salary

$94K - $163K / year

Seniority

Senior

Bachelor Degree7 yrs expEnglishAWSAzureGCPSplunk

Job Description

Senior Technical Manager, Security Operations

Coalfire

• Act as the primary technical escalation point for complex operational issues across SIEM and continuous monitoring programs, ensuring quick and effective resolutions. • Maintain and optimize critical security systems, including SIEM platforms (e.g., Splunk, ELK, SumoLogic, Sentinel), vulnerability management and scanning tools (e.g., Nessus, Qualys, Tenable), and Anti-Virus/EDR solutions (Trend Micro Deep Security Manager, Microsoft Defender, Crowdstrike). • Oversee continuous monitoring activities for FedRAMP and other compliance programs, including vulnerability scanning, configuration management, security control validation, and compliance artifact generation. • Monitor and improve the team's use of automation and monitoring tools to drive operational efficiency across both SIEM and vulnerability management workflows. • Analyze and resolve system performance issues, ensuring compliance with FedRAMP, SOC, HIPAA, and other security/operational standards. • Participate in incident response, threat hunting, and post-mortem analysis to identify root causes and prevent recurrence. • Manage a team of engineers across SIEM operations and continuous monitoring (vulnerability management) functions, fostering a high-performing and engaged team culture. • Mentor and support the professional growth of engineers through training, feedback, and career development planning. • Assist with hiring, onboarding, and retention to ensure team stability and growth. • Oversee day-to-day delivery of security services, ensuring operational consistency and high-quality outcomes for both SIEM and continuous monitoring programs. • Track and optimize key metrics such as incident response times, vulnerability remediation rates, false positive reduction, operational efficiency, and compliance posture. • Develop and refine processes for incident response, vulnerability remediation, continuous monitoring reporting, and compliance documentation. • Work with cross-functional teams, including consulting teams, SREs, and professional services teams, to improve service delivery and client satisfaction.

Job Requirements

  • 7+ years of hands-on experience in technical roles, such as engineering or operations.
  • Proven ability to manage operational processes and handle escalations.
  • Experience balancing individual contributor work with team oversight.
  • Strong technical expertise with SIEM platforms (e.g., Splunk, ELK, SumoLogic, Sentinel) and vulnerability management tools (e.g., Nessus, Qualys, Tenable).
  • Deep understanding of continuous monitoring requirements for FedRAMP, including OSCAL, POA&M management, and automated security control validation.
  • Proven ability to troubleshoot and resolve complex technical issues in high-pressure environments across both threat detection and vulnerability management domains.
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP) and their associated security practices, including cloud-native vulnerability scanning and CSPM tools.
  • Solid understanding of security compliance frameworks (e.g., FedRAMP, SOC, HIPAA, NIST 800-53).
  • Ability to mentor and guide team members while contributing to technical solutions.
  • Strong written and verbal communication skills, particularly in documenting technical insights and creating compliance artifacts.
  • Bachelor’s degree (four-year college or university) *or* a equivalent work experience.

Benefits

  • paid parental leave
  • flexible time off
  • certification and training reimbursement
  • digital mental health and wellbeing support membership
  • comprehensive insurance options

Related Categories

Related Job Pages

More Security Operations Jobs

American Technology Services logo

Incident Response Eng

American Technology Services

Innovative Solutions for Today's IT Challenges

OtherRemoteTeam 501-1,000Since 1994H1B Sponsor

About American Technology Services LLC American Technology Services (ATS) started in 1994 with the same mission as today, providing high-quality managed IT services, network support, and cybersecurity services to firms where quality matters most – the organizations that rely heavily on information technology and high levels of services. Over the years, ATS has built client trust that has lasted for years and years. As time goes forward, our consultative approach resonates well, and our “corporate knowledge” about our clients’ IT operations helps our clients perform at a higher level. About the role At ATS, you’ll join a dedicated team focused on Incident Detection & Response, working to protect the people, processes, and technology of our organization. We are seeking an experienced and adaptable Security Operations Engineer to join our Cybersecurity team. This role reports to the Cybersecurity Manager and will play a critical part in responding to cybersecurity incidents across the enterprise. What you'll do Serve as a primary responder to security incidents, including the monitoring, triaging, and investigation of security alerts in a timely manner. Collaborate with cross‑functional teams to document, enhance, and coordinate Incident Response processes. Maintain and organize Cybersecurity documentation, including the creation and upkeep of incident response playbooks. Participate in and/or lead incident post‑mortems, distilling lessons learned into actionable recommendations and comprehensive written reports. Analyze logs and EDR telemetry across a variety of systems, including medical devices, cloud applications, workstations, and data exchange platforms. Conduct investigations across Windows, Linux, iOS, and cloud platforms using SIEM tools and manual log analysis. Participate in a global on‑call rotation. Identify opportunities for automation and for improving detection capabilities. Perform proactive threat hunting to identify emerging tactics, techniques, and procedures (TTPs). Assess and respond to new and evolving threats using threat intelligence to evaluate likelihood and organizational impact. Assist in forensic acquisition, malware analysis, and network analysis. Qualifications Proven ability to translate abstract requirements into clear, actionable steps. Excellent written and verbal communication skills, including the ability to convey technical concepts to non‑technical audiences. Strong work ethic with exceptional attention to detail and organizational skills. Ability to prioritize and multitask effectively in a fast‑paced environment. Capable of working both independently and collaboratively within a team. Conceptual understanding of software development methodologies. Experience with application security, SaaS, or cloud security is a plus. Experience with programming or scripting languages is a plus. Familiarity with cloud environments (e.g., AWS, Azure) and automation frameworks.

Georgia
Alpaca logo

Security Operations Engineer

Alpaca

Developer APIs for stocks and crypto trading, investing apps, and embedded fintech.

OtherRemoteTeam 201-500H1B No Sponsor

• Own the relationship with our managed SOC, including alert quality, escalation workflows, SLAs, runbooks, and continuous improvement of detection coverage and response effectiveness. Assist with triage, investigations, and respond to security alerts across endpoints, identity, cloud, network, and application logs. • Operate and maintain our SIEM, including log onboarding, parsing, normalization, correlation rules, alert tuning, and lifecycle management to reduce noise and increase signal. • Ensure critical systems generate the right security telemetry, filling gaps across endpoints, identity providers, network devices, SaaS tools, and cloud platforms. • Continuously refine detection logic based on threat intelligence, SOC feedback, incident learnings, and emerging attack techniques. • Assist with security incidents, working with IT, Engineering, and external partners to contain, eradicate, and recover from incidents. • Develop, maintain, and continuously improve incident response playbooks, escalation paths, and communication procedures. • Track and report on key security operations metrics such as alert volumes, false positive rates, mean time to detect (MTTD), mean time to respond (MTTR), and SOC performance. • Act as the security liaison to the IT Helpdesk, ensuring security-related tickets are properly triaged, prioritized, and resolved without slowing down business operations. • Provide guidance and context to IT teams on security alerts, risks, and required actions, helping raise the overall security maturity of frontline support teams.

United States
Job Closed
Fluent, Inc logo

Security Operations Specialist

Fluent, Inc

Simplify the way you find customers with Fluent. Enabling advertisers to identify, win, and build their customer base.

OtherRemoteTeam 201-500H1B No Sponsor

• Monitor, investigate, and respond to security incidents and alerts in real-time • Manage and optimize security tools including Crowdstrike and Wiz • Conduct threat hunting and proactive security analysis to identify potential vulnerabilities • Develop and maintain security incident response playbooks and documentation • Perform log analysis and correlation to identify security events and anomalies • Support SOC2 audit preparation and maintain ongoing compliance requirements • Assist with other security and compliance certification standards and frameworks • Implement and enforce security policies, procedures, and controls • Conduct security assessments and risk evaluations • Maintain evidence collection and documentation for audit purposes • Serve as a security resource and advisor to end users, providing guidance on security best practices • Partner with development teams to integrate security into the software development lifecycle • Communicate security incidents and risks to both technical and non-technical stakeholders • Provide security awareness training and guidance across the organization • Balance security requirements with business needs while maintaining a customer service-oriented approach

New York
$100K - $130K / year
Job Closed
OtherRemoteTeam 201-500Since 2018H1B Sponsor

• Own Tier 2 escalations across endpoints, identity & access, collaboration tools, and core services—balancing fast resolution with long-term quality. • Investigate root causes of recurring issues and design durable fixes that prevent repeat incidents (vs. one-off workarounds). • Develop secure configuration standards and baselines spanning endpoints, GenAI, orchestration, and SaaS/cloud infrastructure, and iterate on them to support scale and reliability. • Shape incident/problem/change practices by proposing safe changes with clear rollback plans and improving how the team learns from incidents. • Create operational documentation (knowledge base articles, runbooks, reusable patterns) that reduces escalations and uplevels the service desk. • Triage and investigate security alerts in EDR/SIEM/SOAR, escalate effectively, and coordinate containment to recovery using playbooks with clear timelines. • Build and improve automations + analytics (GenAI/ML workflows, scripts/APIs, dashboards) to streamline tasks like alert enrichment, ticket routing, lifecycle changes, remediation flows, and ongoing operational reporting. • Partner on vulnerability and patch management by prioritizing issues, tracking remediation to SLAs, and verifying closure in measurable ways.

Texas
$80K - $85K / year
Job Closed