Job Closed

This listing is no longer active.

CivicPlus logo
CivicPlus

Powering and Empowering Government

Security Operations Engineer

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 501-1,000Since 2001H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

56 days ago

Salary

$61.7K - $87.6K / year

Seniority

Senior

Bachelor Degree3 yrs expExperience acceptedEnglishCloudCyber Security

Job Description

Security Operations Engineer

CivicPlus

• Configure, administer, and continuously tune security technologies to support prevention, detection, response, and recovery capabilities, including SIEM, EDR, IDS/IPS, WAF, vulnerability scanning tools, and cloud security platforms. • Monitor security logs, alerts, and telemetry across on-premises and cloud environments; analyze anomalous activity and escalate or respond in accordance with established procedures. • Investigate and respond to security alerts and incidents in production environments, performing threat hunting, root cause analysis, containment, eradication, and recovery activities. • Maintain, update, and test incident response playbooks and procedures aligned with modern cybersecurity frameworks (including NIST 800-61); document lessons learned and implement improvements. • Define, track, and report operational security metrics, including alert trends, incident volumes, response times, and control effectiveness. • Support internal and external security audits and compliance assessments by providing operational evidence, incident documentation, and control validation artifacts. • Support backup, recovery, and system resilience capabilities as part of information system contingency and business continuity planning. • Collaborate cross-functionally with Engineering, IT, Cloud Operations, and Compliance teams to remediate vulnerabilities, strengthen security controls, and improve detection coverage. • Develop and maintain clear, accurate documentation of security configurations, processes, investigations, and system changes to support knowledge sharing and operational continuity.

Job Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred).
  • Certifications Security+, Network+, or equivalent (required).
  • CySA+, GCIA, GCED, or equivalent (preferred).
  • 3–7 years of experience in security operations, incident response, defensive security, or a related field.
  • Experience coordinating and responding to security incidents in production environments.
  • Experience working with SaaS or cloud-native security technologies and platforms.
  • Strong understanding of security operations, incident response methodologies, and defensive security controls.
  • Demonstrated ability to analyze security threats and respond effectively under time-sensitive and high-pressure conditions.
  • Hands-on experience administering and supporting security technologies (SIEM, EDR, IDS/IPS, WAF, and related platforms).
  • Strong analytical, problem-solving, and documentation skills.
  • Ability to communicate technical findings clearly to technical and non-technical stakeholders.

Benefits

  • Comprehensive health insurance
  • Dental insurance
  • Vision insurance
  • Flexible Time Off
  • 401(k) plan

Related Categories

Related Job Pages

More Security Operations Jobs

Apollo.io logo

Senior Security Operations Engineer

Apollo.io

Helping sales teams find their ideal buyers and convert them into customers.

Full TimeRemoteTeam 51-200Since 2015H1B No Sponsor

• Monitor, triage, and investigate security alerts and events across cloud infrastructure, SaaS applications, and corporate systems. • Conduct end-to-end security investigations, including scoping, containment, eradication, recovery, and documentation. • Own investigations independently while collaborating effectively during high-severity incidents. • Configure and maintain SIEM detections in Panther, including use cases, correlation rules, alert logic, and tuning. • Onboard, validate, and maintain log sources to ensure visibility, accuracy, and reliability. • Design and improve investigation and response workflows to streamline triage, escalation, and resolution. • Perform proactive threat-hunting activities to identify malicious or anomalous behavior not surfaced by existing detections. • Investigate abuse, fraud, account compromise, and automation misuse scenarios in close collaboration with Fraud teams. • Identify detection gaps and propose, implement, and validate improvements. • Build scripts, automations, and tools to reduce manual work and improve response speed and consistency. • Produce clear, high-quality documentation for incidents, investigations, and post-incident reviews. • Share knowledge, review peer work, and mentor other engineers.

Poland
Job Closed

Global IT&SecOps Director

HiBob

HiBob is a modern HR technology company focused on transforming the way organizations operate in today’s dynamic workplace. Its platform streamlines core HR processes, enhances e

Full TimeRemoteTeam 1,350Since 2015

Job Description About UsHiBob helps modern, mid-size businesses transform the way they manage people, giving HR and managers all they need to connect, engage, develop, and retain top talent. Since 2015, we've achieved consecutive triple-digit year-over-year growth, all backed by our amazing team of Bobbers from across the globe, making us the choice HRIS of over ~5500 midsize and multinational companies and over 1 Milion users. Our HR platform is intuitive, data-driven, and built for the way people work today: globally, remotely, and collaboratively. About the Role We are looking for an experienced and forward-thinking IT Director to lead our IT, IT-Security Operations, and Cloud Operations domains. This role is critical in shaping how technology enables the company to scale efficiently, securely, and intelligently in an AI-driven environment. The IT Director will be responsible not only for operational excellence, but also for evolving our operating model - driving automation, augmentation, improving resilience, and ensuring our systems, data, and security posture support rapid growth. Job Requirements Who You Are - 8+ years of experience in IT / Infrastructure / Security leadership roles - Proven experience managing multiple domains (IT, Security, Cloud/Infra) - Strong understanding of modern cloud architectures and SaaS environments - Experience with security operations, risk management, and compliance frameworks - Track record of leading organizational and operational transformation - Strong leadership and people management skills - Ability to operate both strategically and hands-on when needed - High communication skills What Sets You Apart - Experience scaling systems and teams in high-growth SaaS environments - Deep understanding of how AI and automation reshape operations - Ability to simplify complex environments and drive standardization - Strong cross-functional mindset and ability to influence senior stakeholders Job Responsibilities What You'll Own 1. IT & Enterprise Systems - Lead the strategy and execution of corporate IT . - Manage our global sites infrastructure and establishment of new sites. - Ensure high availability, performance, and scalability of cross services. - Drive simplification and standardization of tools and processes - Own employee experience across IT services (onboarding, support, productivity tools) - Lead the AI IT transformation 2. Security Operations - Own the company's IT security operations execution - Lead IT security operation projects and deployment - Partner with Security, Legal, Compliance teams on risk management ,policies and execution Key Responsibilities - Define and execute a unified strategy across IT, Security, and Cloud Operations - Build and lead Global high-performing teams across multiple domains - Reduce complexity by consolidating systems, improving architecture, and eliminating redundancy - Drive automation and AI adoption across operations to increase efficiency, improve employee experience and reduce manual work - Establish clear SLAs, KPIs, and operational metrics - Ensure strong governance, compliance, and risk management practices - Implement a unified role based permission metric across the organization What Success Looks Like - Highly reliable, scalable, and secure systems that support business growth - Reduced operational complexity and improved efficiency - Faster incident detection and resolution - Improved employee experience with IT services - Clear ownership and accountability across domains - Increased automation and reduced manual workload - Making IT organizational changes with cross teams collaboration Why This Role Matters This role sits at the core of how we scale. As the company grows, the ability to operate securely, reliably, and efficiently becomes a competitive advantage. The IT Director will play a key role in building that advantage by shaping the systems, processes, and teams that power the organization. Benefits Join our village HiBob is a village filled with amazing people and we're especially proud of that. It's a place where Bobbers can be themselves. We're about fun, dreams, hopes and ambition, just as much as we are about precision, growth, and top performance. Becoming a Bobber means you'll receive competitive compensation, benefits, and pre-IPO equity alongside all of this: - Company share options plan - We have a flexible hybrid working model - Work from home allowance- to get your home office set up! - Payment for sick leave from the first day - 2 Social Impact days per year for volunteering - Annual Headspace subscription and wellness benefits - Awesome employee referral program- $2,500 for each successful referral with an additional ambassador programme - Monthly Wolt Allowance - Transportation allowance - Dog-friendly - Temporary remote work from anywhere in the world for up to 2 months (after 6 months of employment) - Fun company and team social events (locally and virtually with our global teams) - Bob balance days - 4 additional days within a calendar year - Enjoy a company-wide long weekend at the beginning of each quarter If this sounds like something you've been looking for, we'd love to have you. Come on, join our village!

Israel
KBR, Inc. logo

Information System Security Officer (ISSO)

KBR, Inc.

We deliver science, technology and engineering solutions to governments and companies around the world.

Full TimeRemoteTeam 10,001+Since 1901H1B No Sponsor

Title: Information System Security Officer (ISSO) Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country’s most critical role – protecting our national security. Why Join Us? - Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. - Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace. - Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense Job Summary The successful candidate will provide support to the Test Resource Management Center’s (TRMC) All Domain Test Range (ADTR) and INDOPACOM Pacific-Rim Multi-Domain Training and Experimentation Capability Team, Joint Mission Environment Test Capability (JMETC) Secret Network (JSN) Node, JMETC Multiple Independent Levels of Security Network (JMN) Node, Secret Defense Research and Engineering Network (SDREN), Defense Research and Engineering Network (DREN). In this role, you will be a critical part of our team responsible for evaluating customer requirements pertaining to complex technical challenges. The successful candidate will assist with providing solutions to complex problems in a manner which meets both functional and security requirements. You will be responsible for keeping the team’s computing environment operational and in compliance with all TRMC directives and applicable RMF requirements. To do this, you will frequently collaborate with other distributed team members to discuss current system status and plan desired future enhancements. The ideal candidate will have a blended skill set with a strong background in both systems administration and cybersecurity. This individual will possess experience in Windows and Linux server management, Active Directory, Security Technical Implementation Guides (STIGs), and virtualization technologies. This role is critical in ensuring the integrity, confidentiality, and availability of our information systems within a Department of Defense (DoD) environment. Key Responsibilities: - Security Management: - Develop, implement, and maintain security policies, procedures, and standards to safeguard organizational information systems. - Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate potential threats. - Monitor security alerts and logs to respond to incidents in a timely manner, ensuring compliance with DoD regulations. - Manage Privileged Access Management (PAM) solutions to ensure secure access control for sensitive systems and data. - Filter and generate reports from Security Information and Event Management (SIEM) tools to provide insights into security incidents and trends. - Respond to JFHQ-DODIN issued orders, such as Cyber Task Orders (CTO). - Participate in DoD mandated Zero Trust efforts (initiatives, planning, testing, and implementation). - Risk Management Framework (RMF) Compliance - Apply RMF principles to assess and manage risk associated with information systems, including categorization, selection of security controls, implementation, assessment, authorization, and continuous monitoring. - Collaborate with stakeholders to ensure all systems are RMF-compliant and maintain relevant documentation. - Training and Awareness - Develop and conduct security training programs for staff to enhance awareness of information security best practices and organizational policies. - Function as a security advisor to other departments, providing guidance on secure system design and implementation. - Documentation and Reporting - Maintain comprehensive documentation of security processes, incidents, and remediation efforts. - Prepare and present reports on security posture, vulnerabilities, and incident response efforts to senior management and other stakeholders. - Additional Tools and Technologies - Experience with McAfee ePolicy Orchestrator (ePO) for centralized security management. - Familiarity with Assured Compliance Assessment Solution (ACAS) for vulnerability scanning and compliance monitoring. - Jira and Confluence - ServiceNow - Helpdesk and CCB solutions input, monitoring status, approval workflows Work Environment: - Location: Remote - Travel Requirements: Minimal up to 20% - Working Hours: Standard Qualifications: Required: - Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field - Certifications: CISSP, CISM, CASP, Security+ - Security Clearance: Active TS/SCI - Experience: Minimum 10 years of system administration or cybersecurity-related experience, specifically within DoD environment. - Technical Skills: - Proficient in Windows server and Linux server management, including installation, security policies, configuration, and troubleshooting. Desired: - Education: Master’s degree in computer science, Information Technology, Cybersecurity, or related field. Advanced degrees or certifications (CISSP, CISM, CASP, Security+) - Virtual Desktop Infrastructure: Horizon, UAG, Provision and Maintain VM pools - Client Support: Solid understanding and experience supporting zero/thin clients - Risk Management System Support: Experience supporting systems within a DoD Risk Management Framework (RMF) accredited environment. - SIEM Solutions: Splunk, SolarWinds, etc. - Skills: Coordination, Communication and Presentation skills - Functionality: Layer 2/3 Networking experience - Firewall experience - DoD 8570 certifications: Security+, CISSP, Computing Environment - DoD Network experience: Experience working with DoD Wide Area Networks and familiarity with various network architectures and common protocols to include: - Experience working with Defense Research and Engineering Network (DREN) - Experience working with the Secret Defense Research and Engineering Network (SDREN) - EPO (Trelix) experience – policy, agent updates, compliance dashboards, ACAS experience – scanning, reporting, compliance dashboards Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

United States
Job Closed
Fresenius Medical Care logo

Principal Analyst Cyber Security Operations - SOAR

Fresenius Medical Care

Fresenius Medical Care provides dialysis treatments, products, and services for individuals living with chronic kidney diseases (CKD). Founded as a result of the 1996 merger of Fre

Role Description Fresenius Medical Care’s CSOC seeks a Principal Analyst to lead engineering and development of advanced enterprise-wide detection and threat analytics capabilities. The role drives security engineering strategy, AI enhanced detection logic, threat modeling, and continuous tuning across diverse platforms. It also leads SOAR engineering—building automations, integrating security tools, and creating workflows that reduce manual work and speed up response—while partnering closely with Security and Global IT teams. This is a U.S.-based remote position supporting Fresenius Medical Care’s Global Cyber Security Operations Center. Principal Duties and Responsibilities - Lead architecture, development, and maintenance of SOAR playbooks and automation pipelines. - Automate repetitive security operations and security engineering workflows (EDR, VM scanning, SIEM enrichment, IR actions). - Integrate security tools and platforms using APIs, scripting, and microservices. - Improve MTTR and reduce operational overhead through intelligent automation by closely partnering with Security Engineering, IT Operations, and Cloud Teams. - Develop KPIs to measure automation impact and report operational improvements. - Lead POCs for new automation platforms and evaluate opportunities for AI-based operations. - Provide mentorship and code reviews for automation engineers and analysts. - Partner with security engineering on telemetry strategy, logging requirements, and architectural standards for monitoring visibility. - Integrate AI/ML driven detection capabilities into existing pipelines, validating model performance and reducing false positives. - Maintain ingestion pipelines, parsing logic, normalization rules, and event taxonomies across critical log sources: identity, endpoint, cloud, network, application, and medical systems. - Lead the design, implementation, and optimization of enterprise-wide detection content, including correlation rules, behavioral analytics, machine learning assisted detections, and anomaly models. - Develop detection playbooks and logic focused on lateral movement, credential abuse, insider threats, privilege escalation, cloud compromise, and advanced persistent threats. - Tune, optimize, and enrich detection pipelines with contextual data (identity, asset, threat intelligence, vulnerability data). - Mentor analysts and engineers globally on detection logic development, data analytics, and platform best practices. - Serve as a senior escalation point for complex security incidents and investigations. Physical Demands and Working Conditions The physical demands and work environment characteristics represent those typically encountered while performing essential duties. Reasonable accommodation may be made as needed. This is a remote role with availability expected during core hours and during escalations as required. Supervision Provides technical leadership and mentorship to threat engineers, automation engineers, and security operations analysts globally. Does not directly manage staff. Education - Minimum Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent professional experience). Experience and Required Skills - 5+ years in automation engineering, SOAR engineering, or DevSecOps. - Strong scripting/programming experience (Python required; PowerShell, Go, or NodeJS a plus). - Hands-on experience with: - SOAR platforms (Cortex XSOAR, Splunk SOAR, Microsoft Sentinel automation) - API integrations and REST/JSON workflows - CI/CD tools (GitHub, GitLab, Azure DevOps) - Deep understanding of SOC processes, alerting workflows, and incident response. - Experience integrating EDR, VM, identity, and cloud security tools. Preferred - Experience with AI-driven automation or LLM-assisted workflow design. - Certifications: GCSA, GCFA, GCIH, scripting/DevOps certs. - Experience in hybrid or multi-cloud environments. Compensation The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies. Annual Rate: $117,700.00 - $196,200.00 for Waltham, MA location. Benefits - Comprehensive benefits package including medical, dental, and vision insurance. - 401(k) with company match. - Paid time off. - Parental leave. - Potential for performance-based bonuses depending on company and individual performance. Equal Opportunity Employer Fresenius Medical Care maintains a drug-free workplace in accordance with applicable federal and state laws. Fresenius Medical Care is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sexual orientation, gender identity, parental status, national origin, age, disability, military service, or other non-merit-based factors.

United States
$117.7K - $196.2K / year