Bestow logo
Bestow

Building cutting-edge technology and data solutions for life insurance and annuities.

Security Operations Engineer II

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 51-200Since 2017H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

39 days ago

Salary

$107.5K - $126.5K / year

Seniority

Senior

Job Description

Security Operations Engineer II

Bestow

• Collaborates with the CSO Team to support the development, maintenance, and implementation of security standards. • Partner with IT to support the secure implementation of access controls and identity management • Participate in and contribute to initiatives for operating system, Docker images, Kubernetes/GKE and configuration hardening in the public cloud • Support the execution of vulnerability and patch management programs, including tracking remediation efforts. • Work with engineering teams to communicate remediation steps required for vulnerabilities identified through scans or penetration tests. • Support IT, Legal, Finance, Insurance Operations, External Examiners, and business areas during compliance exams. • Assist with the day-to-day operations of security scanning and web penetration testing tools • Support the implementation of security monitoring measures to secure the production environment • Contribute to regular metrics and reporting on the state of the environment • Identify and surface opportunities to improve security tooling, processes, and best practices.

Job Requirements

  • 3+ years of Information Security Experience
  • Working experience with the Google Cloud Platform or AWS
  • Hands-on experience with automation and scripting such as Terraform and shell/Python scripts
  • Experience supporting or participating in penetration testing of web applications, network devices, and cloud configurations
  • A self-starter, comfortable working with cloud infrastructure, software development, and information security risk issues
  • Foundational knowledge of information technology and/or software development risk management frameworks and compliance practices
  • Familiarity with the NIST CyberSecurity Framework and control testing; exposure to audits and some experience with SOC2, HiTrust, or similar audits and certifications is a plus
  • Ability to apply security policies, standards, and guidelines based on best practices and industry frameworks
  • Strong interpersonal and communication skills, with the ability to clearly document and convey security findings
  • Industry security certifications (i.e. CCSP, CCSK, CCSE for cloud security) are a plus
  • You are passionate about learning and supporting a culture of security awareness and compliance across the organization.

Benefits

  • Competitive salary and equity based on role
  • Policies and managers that support work/life balance, like our flexible paid time off and parental leave programs
  • 100% paid-premium option for medical, dental, and vision insurance
  • Lifestyle stipend to support your physical, emotional, and financial wellbeing
  • Flexible work-from-home policy and open to remote
  • Remote and WFH options, as well as a beautiful, state-of-the-art office in Dallas’ Deep Ellum, for those who prefer an office setting
  • Employee-led diversity, equity, and inclusion initiatives

Related Categories

Related Job Pages

More Security Operations Jobs

SupportYourApp logo

Security Incident Response Specialist, Fluent Ukrainian

SupportYourApp

Support-as-a-Service that helps companies scale faster by taking care of their customers’ needs.

ContractRemoteTeam 1,001-5,000H1B No Sponsor

• Full cycle of investigation and coordination in response to security or workflow breaches; • Direct contact and communication with Clients and stakeholders in the event of a Data Breach; • Performing Root Cause Analysis, developing preventive measures, and preparing reports for top management; • Analyzing Client's operational workflows based on incident trends to identify potential threats to the company and developing proactive security optimization recommendations; • Evaluating the security of software, platforms, and third-party services. • Assessing new hiring locations regarding data protection standards and security tool feasibility. • Developing incident management procedures and maintaining the internal knowledge base.

Poland
Whatnot logo

Corporate Security Operations Manager

Whatnot

Whatnot is an online community marketplace where people can work to “turn their passion into a business.” In past hiring for flexible roles, the venture-backed company has post

Full TimeHybridTeam 1,200Since 2019

Title: Corporate Security Operations Manager Location: Los Angeles, CA Department: Legal Compensation $174K – $205K • Offers Equity Job Description: Join the Future of Commerce with Whatnot! Whatnot is the largest livestream shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops. As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact. Role Whatnot's Corporate Security team is looking for an experienced security operations leader to own the physical safety of our people — across offices, live events, and the field. This role lives in both the strategic and tactical worlds. Half the job is program-building: developing the frameworks, playbooks, and vendor standards that scale with a fast-growing company. The other half is being the person our teams rely on when the stakes are high — a flagship seller event in a new city, a sensitive field engagement, a crisis developing overseas. You need to be equally comfortable writing the playbook on Monday and executing it on Friday. You'll partner daily with Workplace, People, Marketing, and Category teams, and manage a network of third-party vendors across our global and growing portfolio. The role reports into Corporate Security and sits at the intersection of operational rigor and strategic program growth. - Office Security Operations - Own the security standard across all Whatnot global office locations - Manage third-party guard vendors to performance expectations you will define — not just oversight, but accountability - Partner with Workplace on emergency response programs - Be the person with the plan when something goes wrong at one of our sites - Event Security Operations - Develop repeatable security playbooks for events ranging from intimate seller meetups to large-scale live activations - Conduct advance site assessments (in-person or virtual) and implement appropriate security measures - Serve as the on-the-ground security lead at high-visibility activations, managing vendors in real time - Field Security Operations - Assess and mitigate risk for seller engagements, category activations, and community-based initiatives - Build training and incident response protocols for Category and Community team members working in non-traditional environments: retail floors, warehouses, private residences, etc - Travel Security Management - Assist in the initial design and oversight of Whatnot’s travel security framework supporting domestic and international travel - Support response coordination for travel-related incidents and crises as needed Location & Travel This role will be based in Los Angeles, CA or New York, NY. The successful candidate must live within commuting distance of one of these two locations. Expected in-office cadence: 2–3 days per week, with flexibility to be on-site more frequently during major events, activations, or security initiatives. This role includes regular domestic and international travel (~25-40%) to support events, office operations, and field engagements. You People who do well at Whatnot tend to be comfortable figuring things out as they go, biased toward action, and genuinely curious about what they're building. They care more about outcomes than credit and stay close to the product and the people using it. As our next Corporate Security Operations Manager, you should have 10+ years of physical security experience, plus: - 10+ years of experience in corporate security operations, with extensive depth in the multi-office environment pillar and solid experience in the events/field security pillar - A track record of managing external vendors to high standards and running cross-functional partnerships without friction - You must know what "good" looks like and how to build toward it in a fast-moving organization - You are at your best when the environment is fast-moving and the playbook doesn't exist yet — you spot what needs fixing, scope it, and get to work - You communicate in plain language that non-security stakeholders can act on - You are willing to work in office 2-3 days a week and travel at least 25% of your time Bonus points if you have: - Experience in high-growth tech companies, marketplaces, or live-event businesses - International office or event security experience - Hands-on experience with global travel security programs Benefits - Generous Holiday and Time off Policy - Health Insurance options including Medical, Dental, Vision - Work From Home Support - Home office setup allowance - Monthly allowance for cell phone and internet - Care benefits - Monthly allowance for wellness - Annual allowance towards Childcare - Lifetime benefit for family planning, such as adoption or fertility expenses - Retirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary) and Pension plans internationally - Monthly allowance to dogfood the app - All Whatnauts are expected to develop a deep understanding of our product. We're passionate about building the best user experience, and all employees are expected to use Whatnot as both a buyer and a seller as part of their job (our dogfooding budget makes this fun and easy!). - Parental Leave - 16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence. 1212 EOE Whatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.

California + 1 moreAll locations: California | New York
$174K - $205K / year
Full TimeRemoteTeam 10,001

The Work The Cybersecurity Incident Response Junior Analyst and Triage Analyst role will work in the CIRT team in the CISO organization. This role works on a shift under the analysis and triage team lead to relate, scope, and triage alerts and notifications from the SIEM, security sensors, ticketing system, walk-ins, and phone calls. Requires technical understanding to collaborate with the incident response and operations teams to qualify events as relevant and determine true and false positives. Knowledge in incident response lifecycles, common cyber-attacks, and federal incident reporting requirements. Primary responsibilities: - Actively monitor and respond to cybersecurity incidents related to alerted policy violations - Analyze and investigate incidents to determine their nature and scope. - Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution. - Document incidents and response activities in detail. - Stay updated with the latest cybersecurity threats and trends. - Assist in developing and refining incident response strategies and procedures. - Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives. What you need - US Citizenship required - 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience. - 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus, - Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions. - Excellent written and oral communication skills, attention to detail, and interpersonal skills. - Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages. - Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages. - Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same. - Familiarity with static and dynamic malware analysis concepts. - Experience with indicators of attack and compromise. - Familiarity with Windows / Linux architecture and endpoint analysis of the same. - Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc Bonus if you have - SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply. The pay range for the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland is: $57,200—$109,400 USD What We Believe As a company wholly dedicated to serving the US federal government, we bring together the best talent to help reinvent how federal agencies operate and deliver greater value for their mission and the American people. We have an unwavering commitment to creating a culture in which all our people are respected, feel a sense of belonging, and have equal opportunity. As a business imperative, every person at Accenture Federal Services has the responsibility to create and sustain a culture where everyone feels welcomed and included. This is grounded in our core values and our experience that hiring and developing great people who reflect different perspectives, experiences, and backgrounds is key to driving innovation and delivering the results that our clients and the country count on. Equal Employment Opportunity Statement We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. For details, view a copy of the Accenture Federal Services Equal Opportunity Policy Statement. Accenture Federal Services is an Equal Employment Opportunity employer. Additionally, as an Affirmative Action Employer for Veterans and Individuals with Disabilities, Accenture Federal Services is committed to providing veteran employment opportunities to our service men and women. Requesting An Accommodation Accenture Federal Services is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture Federal Services and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired. If you are being considered for employment opportunities with Accenture Federal Services and need an accommodation for a disability or religious observance during the interview process or for the job you are interviewing for, please speak with your recruiter. Other Employment Statements Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States. Candidates who are currently employed by a client of Accenture Federal Services or an affiliated Accenture business may not be eligible for consideration. Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process. The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information. California requires additional notifications for applicants and employees. If you are a California resident, live in or plan to work from Los Angeles County upon being hired for this position, please click here for additional important information.

United States
$57.2K - $109K / year
SitusAMC logo

Security Operations Engineer

SitusAMC

We're helping our clients identify and capture opportunities across the entire lifecycle of their real estate activity.

Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Monitor, investigate, and respond to security alerts across cloud, endpoint, network, and identity platforms • Execute mitigation and remediation actions within AWS and Azure environments • Build, tune, and maintain detections in SIEM, EDR, and cloud-native security tools • Develop, maintain, and execute security runbooks, response playbooks, and operational documentation • Implement and support automation and response workflows using scripting, APIs, and cloud-native tooling • Partner with cloud, infrastructure, and application teams to remediate findings and harden systems • Support threat hunting activities using logs and telemetry • Assist with vulnerability management and corrective action tracking • Monitor cloud environments for misconfigurations and control failures • Stay current with emerging threats and recommend strategies to evolve security defenses.

United States
$110K - $140K / year
Job Closed