Addi logo
Addi

Somos una empresa de tecnología que busca impulsar y habilitar el comercio digital en Latinoamérica.

SecOps Engineer

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

Colombia

Posted

33 days ago

Salary

0

Seniority

Senior

Bachelor Degree3 yrs expEnglishAWSCloud

Job Description

SecOps Engineer

Addi

• Own the implementation and day-to-day operation of security controls across endpoints, infrastructure, secure connectivity, and data protection • Execute the migration to the selected XDR platform across endpoints and infrastructure • Implement and operate DLP and SASE controls to secure user access, SaaS usage, and data flows • Deploy and operate a centralized MDM solution to manage and secure corporate endpoints • Implement and maintain endpoint security policies including encryption, OS hardening, patching, and access controls • Operate and continuously improve SIEM detections and SOAR playbooks for security events across critical platforms • Support brand protection operations by monitoring phishing, impersonation, and brand abuse activity

Job Requirements

  • Proven Experience in Security Operations & Control Implementation
  • Hands-on experience implementing and operating security controls across endpoints, infrastructure, secure connectivity, and data protection in cloud-first environments.
  • At least 3 years of experience working with XDR platforms (e.g., CrowdStrike, Cortex, Sentinel) and MDM solutions (e.g., Google Workspace, JumpCloud, or similar).
  • Demonstrated ability to deploy and operate SASE / Zero Trust, VPN, and DLP solutions, including troubleshooting production control failures.
  • Experienced in operating security detections, alerts, and response workflows within SIEM and XDR platforms, including integrations with AWS, Google Workspace, and endpoint tools.
  • Executes incident response actions using defined playbooks and escalates effectively based on severity and impact.
  • Familiar with SOAR concepts and automation of repetitive security operations tasks to improve response efficiency.
  • Proven experience deploying and managing MDM solutions to enforce endpoint security baselines at scale.
  • Strong knowledge of device hardening, encryption, patching, application control, web filtering, and secure access controls.
  • Ability to monitor device compliance and remediate non-compliant endpoints in a timely and efficient manner.
  • Demonstrates strong operational discipline, including documentation, monitoring, alert follow-up, and incident tracking.
  • Effectively manages multiple operational priorities while maintaining stability and reliability of security controls.
  • Proactively identifies operational gaps and contributes to continuous improvement of security operations.
  • Works effectively with IT, engineering, and infrastructure teams to deploy, operate, and improve security controls.
  • Communicates incidents, operational issues, and risks clearly and concisely to both technical and non-technical stakeholders.
  • Follows established processes while providing constructive feedback to improve tooling, workflows, and controls.

Benefits

  • Competitive compensation & meaningful ownership
  • Health insurance
  • 401(k) matching
  • Flexible work hours
  • Paid time off
  • Professional development opportunities

Related Categories

Related Job Pages

More Security Operations Jobs

Security Operations - Incident Response Coordinator

Converge Technology Solutions

Converge Technology Solutions provides specialized IT services tailored to meet customers' individual needs. The company offers a wide range of services, including advanced analyti

Role Description We are seeking a highly skilled and motivated Incident Response Coordinator to join our Security Operations team. This role involves planning, coordinating, and managing responses to security incidents, ensuring accurate execution of processes and timely completion of documentation and communications. The ideal candidate for the Incident Response Coordinator role is an experienced professional with the soft skills that enable effective performance in high-stakes environments: - Active listener with strong analytical and problem-solving abilities - Ability to confidently communicate clear, concise updates to diverse stakeholders - Exhibits adaptability, attention to detail, and a commitment to ethical practices Personnel performing this role may unofficially or alternatively be called: - Incident Handler - Incident Responder - Incident Response Analyst - Incident Response Engineer - Intrusion Analyst - Computer Network Defense Incident Responder - Computer Security Incident Response Team Engineer Qualifications - Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field or equivalent work experience of 5 years or more - Minimum of 2 years of experience in cybersecurity incident response or a related role Requirements - Coordinate the investigation, containment, recovery, and remediation of cybersecurity incidents - Serve as the primary contact during incidents, providing status updates - Monitor and analyze network traffic, security logs, and alerts - Document after action incident details, actions taken, timelines, and lessons learned - Conduct periodic incident response exercises, deliver training, and raise awareness - Collect intrusion artifacts and use discovered data to enable mitigation - Continuously review and improve the incident response plan - Perform initial triage and analysis of security incidents - Guide cross-functional teams to contain threats and restore normal operations - Coordinate with Corporate Leadership, Security Operations Center (SOC), and external parties - Lead after-action reviews, publish findings, and recommend mitigation measures - Stay current with evolving threats, vulnerabilities, and best practices Benefits - Equal employment opportunities to all employees and applicants - Prohibits discrimination and harassment of any type Preferred Qualifications - Outstanding English language communication skills, both written and verbal - Professional certifications such as CISSP, ECIH, GCFE, GCIH - Experience with digital forensics and malware analysis - Knowledge of network protocols and security architecture - Familiarity with malware types and attack methods - Experience with scripting and automation tools Physical Requirements - Prolonged periods of sitting at a desk and working on a computer

India
Job Closed
Versant Health logo

Cybersecurity Operations Analyst

Versant Health

Versant Health is one of the nation’s leading administrators of managed vision care, serving millions of our clients’ members nationwide. We are driven by our mission to help members enjoy the wonders of sight through healthy eyes and vision. As a Versant Health associate, you can enjoy a comprehensive Total Rewards package, which includes health and dental insurance, tuition reimbursement, 401(k) with company match, pet insurance, no-cost-to-you vision insurance for you and your qualified dependents. We are also invested in your success. There are many opportunities for advancement and development throughout all stages of your career with us.

Full TimeRemoteTeam 1,001-5,000

Role Description The Cybersecurity Operations Analyst supports and advances the organization’s Information Security program by protecting the enterprise against evolving cyber threats. This role is responsible for participating in incident response activities, investigating and analyzing security events, optimizing security controls, and collaborating cross-functionally to strengthen the organization’s overall security posture. The Cybersecurity Operations Analyst provides hands-on technical leadership through proactive threat hunting and the continuous enhancement of detection and response capabilities. This position contributes to the ongoing evolution of Versant Health’s cybersecurity operations by leveraging leading security technologies, partnering with internal stakeholders, and staying current on emerging threats and attack methodologies. Where you will have an impact - Security Hygiene & Control Validation - Routinely audit and validate security control coverage (e.g., XDR, ZTNA, DLP) to ensure tools are operating effectively and protect 100% of intended assets. - Partner with the SOC to ensure log integrity across security and non-security systems; validate alert scope, fidelity, and thresholds. - Monitor the health and performance of security tools, performing root cause analysis when agents fail or policies are not properly applied. - Incident Response, Event Monitoring, & Threat Hunting - Serve as the Tier 2 escalation point for the SOC and lead the full incident response lifecycle, from containment through recovery. - Conduct proactive threat hunting using threat intelligence, SOC findings, and behavioral analysis to identify threats that bypass automated controls. - Analyze threat intelligence to inform defensive strategies and continuously improve detection capabilities. - Collaborate with the SOC to develop, refine, and maintain incident response playbooks aligned to business context. - Monitor and analyze security alerts from SIEM, EDR, and other tools to identify and respond to potential threats. - Implement and enforce security controls, policies, and procedures to protect organizational assets. - Blue, Red, and Purple Team Activities - Engage in the development and execution of recurring security wargames, including scenario design and cross functional participation. - Actively participate in blue team activities focused on defensive security, detection, and incident response. - Collaborate in purple team exercises to validate detection and response effectiveness against real world attack scenarios. - Participate in internal red team exercises, penetration tests, and simulated attacks to identify security gaps and control weaknesses. - Perform adversary emulation by modeling tactics, techniques, and procedures (TTPs) of known threat actors. - Share insights, lessons learned, and intelligence across teams to continuously improve security posture. - Use findings from offensive testing to optimize SIEM rules, EDR/CASB/SWG policies, firewall configurations, and other security controls. - Security Tool Management - Configure, maintain, and optimize a broad portfolio of security technologies, including: - Security Information and Event Management (SIEM): Log aggregation, correlation, tuning, and alerting. - Endpoint Detection and Response (EDR): Threat detection and response across endpoint environments. - Attack Surface & Exposure Management (ASM/AEM): Continuous discovery and prioritization of vulnerabilities and exposures. - Cloud Access Security Broker (CASB): Enforcement of security controls for cloud applications and services. - Secure Web Gateway (SWG): Inspection of web traffic and protection against web-based threats. - Data Loss Prevention (DLP): Design, implementation, and management of policies to prevent unauthorized data exfiltration across endpoints, networks, and cloud environments. - Security Operations & Support - Respond to and resolve security related tickets and user inquiries. - Provide guidance and best practice recommendations to end users and IT partners. - Troubleshoot security tool issues and perform root cause analysis. - Documentation, Reporting, & Communication - Create and maintain detailed documentation for incident response procedures, security tool configurations, and security advisories. - Generate and present reports on security incidents, trends, and overall security posture to management. - Communicate clearly and effectively with stakeholders during and after security incidents. Qualifications - 3+ years of experience in cybersecurity, with a focus on security operations and incident response. - Bachelor’s degree from an accredited college or university or equivalent professional experience. - Hands-on experience administering and maintaining SIEM, EDR, and related security tools. - Understanding of networking concepts, TCP/IP, Active Directory, DNS, DHCP, and network defense technologies. - Proficiency with Windows, Linux, and macOS operating systems. - Experience with cloud security platforms (e.g., AWS, Azure). - Knowledge of secure engineering principles and technical security testing methodologies. Requirements - All Associates must comply with the Health Insurance Portability Accountability Act of 1996 (HIPAA) as it pertains to disclosures of protected health information (PHI). - Associates may have access to covered information, cardholder data or other confidential customer information which must be protected at all times. - Associates must explicitly adhere to all data security guidelines established within the Company’s Privacy & Security Training Program. Benefits - Comprehensive and competitive total rewards package designed to support your health, financial well-being, and work-life balance. - Medical, dental, and paid vision coverage. - Paid time off and company holidays. - Retirement savings with employer contribution. - Employee wellness resources. - Professional development opportunities. - Flexible work arrangements. - Employee assistance programs.

United States
Lincoln Financial logo

IT Security Operations Center Specialist

Lincoln Financial

We help people confidently plan for their version of a successful financial future.

Full TimeRemoteTeam 10,001+Since 1905H1B No Sponsor

• Monitor and defend network perimeter interfaces against malicious traffic. • Analyze inbound and outbound network traffic for anomalies and threats. • Perform real-time security event analysis using SIEM and other advanced security tools. • Correlate and triage security alerts and indicators generated by monitoring systems. • Investigate and respond to suspected phishing emails and related incidents. • Manage and resolve cybersecurity-related requests received via phone, email, or internal ticketing systems promptly and accurately. • Execute routine assignments and projects while applying deep knowledge of security operations. • Identify and recommend process improvements to enhance efficiency and quality within the SOC. • Ensure availability and proper functioning of security technologies, including IDS/IPS, Web Application Firewalls, DLP, syslog servers, and vulnerability scanners. • Stay current on emerging cybersecurity trends and technologies; assess their impact and collaborate with leadership to integrate improvements into security operations. • Support organizational and departmental initiatives by promoting best practices and contributing to change management efforts.

North Carolina + 1 moreAll locations: North Carolina | Pennsylvania
$86.3K - $120K / year
Sunshine Enterprise USA logo

SOC Analyst – Contract

Sunshine Enterprise USA

Our commitment to creating American jobs

ContractRemoteTeam 51-200Since 2001H1B No Sponsor

• Monitor, analyze, and correlate security events across SIEM platforms, EDR/XDR solutions, IDS/IPS systems, Threat intelligence feeds • Investigate and validate security incidents, determine root cause • Perform deep-dive analysis of suspicious activity • Conduct incident response activities including containment, eradication, and recovery support • Develop detailed incident reports, timelines, post-incident summaries • Recommend improvements to SOC playbooks, detection rules • Perform proactive threat hunting using MITRE ATT&CK framework • Collaborate with engineering teams to tune and optimize security tools • Support dashboard creation, reporting, and SOC performance metrics • Serve as a subject matter expert (SME) interacting with stakeholders • Document SOC processes, runbooks, incident handling procedures • Coordinate with SOC teams, engineering teams, and agency stakeholders

South Carolina
Job Closed