Job Closed

This listing is no longer active.

DICK'S Sporting Goods logo
DICK'S Sporting Goods

Headquartered in Coraopolis, Pennsylvania, DICK’S Sporting Goods offers sports fans and enthusiasts a “big store” selection of name-brand sports equipment

Lead Cybersecurity Operations Analyst

Location

United States

Posted

127 days ago

Salary

$83K - $138.2K / year

Seniority

Senior

Bachelor Degree7 yrs expEnglishFirewallsLinux

Job Description

Lead Cybersecurity Operations Analyst

DICK'S Sporting Goods

• Lead security incident investigations and ensure timely containment, root cause analysis, and cross-team collaboration. • Provide expert guidance on SIEM strategy, detection logic, and associated security technologies (EDR, email/web gateways, cloud controls). • Standardize and refine monitoring workflows to improve signal quality, reduce false positives, and expand visibility across the environment. • Leverage data from diverse sources (logs, telemetry, threat intel, case history) to identify patterns, emerging issues, and potential business impacts. • Develop, drive, and execute recommendations—technical or professional—that shape both short-term defensive actions and longer-term operational strategy. • Boost SOC effectiveness by implementing new tools, automation, AI-powered processes, and optimized playbooks supported by clear performance metrics. • Anticipate what’s next by actively monitoring emerging threats and regulatory changes that affect the company. • Mentor and elevate teammates by sharing expertise, modeling strong communication under pressure, and supporting a culture of learning within the SOC. • Collaborate closely with Technology teams, Legal/Privacy, Risk & Compliance, vendors, and third-party service providers. • Act as a subject matter expert for technology, policy, and regulatory topics in your area. • Maintain relevant professional certifications and stay current through conferences and ongoing professional development. • Advise peers and leadership on emerging risks, best practices, and operational implications.

Job Requirements

  • Bachelor’s Degree in Computer science , management information systems, cybersecurity, or equivalent experience
  • 7-10 years experience Security Operations, incident response, Windows, Linux, cloud, SIEM, EDR, firewalls, email gateways
  • Security & Incident Event Management (SIEM)
  • Endpoint Detection & Response (EDR)
  • Secure email gateways
  • Query-building
  • Detection Engineering
  • Threat Hunting
  • Experience with MITRE ATT&CK mapping and detection engineering workflows
  • Cloud and identity investigation experience (e.g. identity compromise and bypass techniques)
  • Exposure to SOAR automation, playbook development, or case management platforms
  • Data pipeline and storage expertise (e.g. event and log data parsing)
  • Security+ (preferred not required)
  • CISSP (preferred not required)
  • GIAC (preferred not required)
  • Vendor certifications (preferred not required)

Benefits

  • incentive
  • equity
  • benefits

Related Categories

Related Job Pages

More Security Operations Jobs

Keyrock logo

SOC Analyst, Level 1

Keyrock

Digital asset market makers building scalable, self-adaptive technologies to support efficient markets.

OtherRemoteTeam 51-200Since 2017H1B No Sponsor

• 24/7 monitoring and alert triage across SIEM/EDR/cloud security tooling; identify false positives vs. credible threats and set appropriate severity. • Initial investigation and enrichment: gather relevant logs/telemetry, add context, and document findings clearly in the case/ticketing system. • Escalation and coordination: escalate confirmed/suspected incidents quickly and cleanly to L2/IR with a complete handoff (timeline, scope, IOCs, actions taken). • Runbook execution: follow SOPs for common events (phishing, suspicious logins, endpoint detections, cloud key/token risk, malware alerts, data exfiltration signals), including containment actions you’re authorized to perform. • Threat-aware analysis: map alerts to adversary behaviors (e.g., MITRE ATT&CK techniques) to improve understanding and escalation quality. • Operational hygiene: maintain accurate shift handovers, update watchlists and investigation notes, and identify recurring alert patterns for tuning recommendations.

California + 4 moreAll locations: California | Florida | Illinois | New Jersey | New York
Job Closed
Keyrock logo

SOC Analyst, Level 2

Keyrock

Digital asset market makers building scalable, self-adaptive technologies to support efficient markets.

OtherRemoteTeam 51-200Since 2017H1B No Sponsor

• Take escalations from L1 and independently investigate complex, multi-signal alerts (identity compromise, cloud control-plane abuse, endpoint persistence, lateral movement, suspicious automation, data exfiltration). • Perform deep log/telemetry analysis across SIEM, EDR, cloud logs, IAM signals, network telemetry, email security, and SaaS audit trails. • Build and validate hypotheses, pivot across data sources, and produce clear incident timelines and scope assessments. • Serve as technical incident lead for defined incident types/severities (or co-lead with IR), driving containment and eradication steps within authorized bounds. • Execute and improve response playbooks for key scenarios (phishing/BEC, credential theft, token/key compromise, suspicious API activity, ransomware indicators, insider risk signals).

California + 4 moreAll locations: California | Florida | Illinois | New Jersey | New York
Job Closed
Sentinel Blue logo

SOC Analyst I

Sentinel Blue

Enterprise cybersecurity for small and medium businesses | Specialize in defense and federal | Ask us about CMMC/DFARS

OtherRemoteTeam 11-50H1B No Sponsor

• Continuously monitor the Security Information and Event Management (SIEM) dashboard and leverage security tools to detect potential security incidents and anomalies in real-time. • Analyze incoming alerts to determine their relevance and urgency; effectively distinguish between false and true positives to prioritize response efforts. • Conduct investigations by gathering context and other relevant logs to understand scope of alert. • Strictly adhere to established Service Level Agreements (SLAs), Incident Response (IR) playbooks and Standard Operating Procedures (SOPs) to ensure consistent and compliant handling of security events. • Create, update, and manage tickets in our case management system, ensuring all investigative steps, communications, and findings are thoroughly documented. • Identify and escalate complex or high-severity incidents to Tier II or Incident Response Team, providing clear details and a comprehensive summary of initial findings. • Perform basic remediation actions, such as blocking indicators and isolating compromised hosts, when authorized by SOPs or directed by senior personnel. • Demonstrate excellent verbal and written communication skills, when communicating with team members, clients, and/or stakeholders. • Contribute to the team’s knowledge base, creating or updating articles, SOPs, and/or playbooks when new trends or resolution methods are identified.

United States
$50K - $60K / year
Job Closed
Calendly logo

Security Operations Engineer

Calendly

The scheduling automation platform for eliminating the back-and-forth emails to find the perfect time — and so much more

OtherRemoteTeam 501-1,000Since 2013H1B No Sponsor

• Collaborating with Security Operations Center (SOC) team members to monitor, detect, and respond to cybersecurity threats in a timely manner. • Responding to cybersecurity incidents from identification through resolution. • Developing and maintaining up-to-date knowledge of the threat landscape, as well as advancements in cybersecurity technologies and methodologies. • Identifying, configuring and onboarding security telemetry sources/logs in support of threat detection and incident response • Collaborating with Engineering and SRE to identify and mitigate logging deficiencies • Developing new detection scenarios and queries to broaden and deepen the team’s detection coverage • Tuning and continuously improving existing detection queries to increase signal-to-noise ratio, and ensure our detections remain relevant and functional • Executing and improving incident response protocols and procedures to swiftly and effectively manage security incidents. • Identifying, developing and maintaining automation solutions to increase the efficiency and effectiveness of the team • Integrating various security and IT tools to enhance threat detection, incident response, and operational efficiency. • Conducting regular security assessments, threat hunts, and continuous monitoring to identify vulnerabilities, opportunities for posture enhancements and better incident preparedness. • Collaborating with Engineering, IT and other departments to support the implementation and evangelization of established cybersecurity best practices across the organization. • Leveraging JIRA for creating and managing dashboards, reports, and metrics that support cybersecurity operations and decision-making.

United States
$155.8K - $219.9K / year
Job Closed