Job Closed

This listing is no longer active.

GuidePoint Security logo
GuidePoint Security

Founded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security

SecOps Observability Engineer

Location

United States

Posted

112 days ago

Salary

0

Seniority

Senior

Bachelor Degree4 yrs expEnglishSplunkTableau

Job Description

SecOps Observability Engineer

GuidePoint Security

• Provide trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. • Evaluate security posture and ecosystems. • Optimize resources and integrate best-fit solutions that mitigate risk.

Job Requirements

  • Hands-on experience with observability products such as SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation, and Response), and data stream management tools like Cribl.
  • In-depth knowledge of log management, monitoring, and alerting techniques.
  • Experience with setting up, modifying, and tuning alerts within the SIEM to ensure critical threats are identified properly.
  • Understanding data ingestion, transformation, and enrichment workflows for integrating various log sources, network telemetry, and security event data into observability platforms.
  • Ability to work with and understand log parsing, aggregation, and normalization.
  • Proven track record working in a Security Operations Center (SOC), with direct involvement in threat detection, incident response, and security event monitoring. Strong understanding of SOC workflows and processes.
  • Ability to communicate strongly and efficiently within the SOC. Must be able to collaborate with internal stakeholders and external vendors.
  • Comfortable producing clear, concise reports and documentation related to security incidents and system performance.
  • Experience with one or more products: Observo, Tableau, CrowdStrike NG-SIEM, Splunk, Google SecOps, Palo Alto XSIAM, Elastic, etc...
  • Bachelor’s degree in a relevant discipline or equivalent experience
  • Minimum 4 years in an enterprise-level security consultative role building and assessing Information Security architectures and programs
  • Prior experience in a corporate operational or technical leadership role.

Benefits

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

Related Categories

Related Job Pages

More Security Operations Jobs

athenahealth logo

Cyber Security Operations Center (CSOC) Analyst – Tier 3

athenahealth

We provide network-enabled services, mobile apps, and data-driven insights to hospitals and medical organizations.

OtherRemoteTeam 5,001-10,000Since 1997H1B Sponsor

• Understand that as the Tier 3 (highest level) engineer, you’re expected to handle potential incidents and act as the as a subject matter expert for all security-related tickets that come into the team's various queues (including triage, containment, and remediation when necessary). • Receive incident escalations from Tier 1 and 2 analysts, assisting with real-time advanced analysis, response, and reporting. • Mentor and assist in training Tier 1 and 2 analysts to aid in their skills development and analytical capabilities. • Proactively hunt for threats and enacting identification, containment, and eradication measures while supporting recovery efforts. • Serve as a point person for coordination with appropriate parties during a security incident – client, management, legal, security, operations, etc. • Create thorough reports and documentation of all incidents and procedures, presenting findings to team and leadership on a routine basis. • Incident Response: remote remediation when possible and working with onsite teams when necessary. • Detailed documentation of events and remediation steps taken. • Root Cause Analysis: initiation and follow-through to ensure quality forensic materials are captured, writing reports with details and timelines of events with recommendations to avoid future occurrences. • Assist in the general maintenance and improvement of procedures, processes and playbooks. • Conduct research regarding the latest methods, tools, and trends in digital forensics analysis. • Conduct analysis using logs, previous alerts, etc. to identify trends to identify and prevent potential incidents. • Follow standard operating procedures (SOPs) to ensure tickets are triaged appropriately and in a timely manner, according to SLAs. • Excel at documentation and detailed notetaking, including SOP writing, incident reporting, e-mail and instant messaging etiquette, and most importantly, documenting incident actions in tickets. • This role is responsible for completing incident reports and forensic reports, when appropriate, so competent writing skills are necessary. • Ability to know when to appropriately escalate a potential issue to peers and/or leadership. • Desire to learn new concepts and technologies to grow and take on more responsibility over time. • Ability to communicate risk, prioritize incident response actions, and keep a cool head under pressure. • Advanced experience with security tools like Splunk, CrowdStrike EDR, Carbon Black EDR, Proofpoint tools, Microsoft Defender components, Cyberhaven DLP, Axiom Cyber and open-source forensic tools, Cylance Protect, Office 365 tools, PowerShell, and various network tools, etc. • Understanding the various stages of incident response, the importance and critical factors of an investigation, and how to contain as soon as possible. • Have experience with the incident response lifecycle, the Lockheed Martin Cyber Kill Chain, the MITRE framework, and the forensic workflows as outlined by NIST. • Work with development teams to ensure they're using best practices and company processes in their daily activities. • Drive self-organization; help determine how the team functions in collaboration with your peers. • Build strong relationships with cross-functional team members between the three tiers of the CSOC. • Participate in off-hours on-call incident handler rotation, which is a requirement for this role, as incidents may be escalated outside of normal business hours by our 24/7/365 Tier 2 team. Tier 3 teammates rotate on-call responsibilities which requires each teammate to be formally on-call roughly one week a month.

Massachusetts
$121K - $207K / year
Job Closed
ContractRemoteTeam 1-10Since 2015

• Oversee all active executive protection deployments • Coordinate agent scheduling and assignment logistics • Develop operational plans for residential and travel protection • Lead pre-mission briefings and post-mission reviews • Ensure proper documentation for every assignment • Recruit, vet, and onboard contractors • Maintain a strong national roster of vetted agents • Evaluate performance and enforce standards • Ensure all deployments comply with state licensing requirements • Maintain clean operational records • Act as the operational point of contact once clients are onboarded

Arizona
$125K - $180K / year
Job Closed
SWK Technologies, Inc. logo

Security Operations Engineer II

SWK Technologies, Inc.

Fulfill your vision of a smarter and easier way to run your business

OtherRemoteTeam 201-500Since 1987H1B No Sponsor

• Monitor, detect, analyze, and respond to security threats in real time. • Lead incident response efforts—from containment to recovery. • Hunt for threats, analyze logs, and fine‑tune detection rules. • Perform forensic investigations and reconstruct attack paths. • Harden servers, workstations, and network infrastructure using CIS, STIGs, and best practices. • Manage and optimize firewalls (Palo Alto, Fortinet, SonicWall), IDS/IPS, SIEM, and EDR tools. • Drive vulnerability management and partner with teams to remediate risks. • Create clear documentation, playbooks, and security reports.

United States
Job Closed
SWK Technologies, Inc. logo

Security Operations Engineer II

SWK Technologies, Inc.

Fulfill your vision of a smarter and easier way to run your business

OtherRemoteTeam 201-500Since 1987H1B No Sponsor

Ready to take your cybersecurity career to the next level? We’re looking for a Security Operations Engineer II who thrives on solving complex security challenges and protecting critical infrastructure from real-world threats. If you love threat hunting, incident response, and hardening systems to perfection, this role is for you. What You’ll Do - Monitor, detect, analyze, and respond to security threats in real time. - Lead incident response efforts—from containment to recovery. - Hunt for threats, analyze logs, and fine‑tune detection rules. - Perform forensic investigations and reconstruct attack paths. - Harden servers, workstations, and network infrastructure using CIS, STIGs, and best practices. - Manage and optimize firewalls (Palo Alto, Fortinet, SonicWall), IDS/IPS, SIEM, and EDR tools. - Drive vulnerability management and partner with teams to remediate risks. - Create clear documentation, playbooks, and security reports. What You Bring - 5+ years Windows/Linux admin experience + 3+ years in security operations/IR/forensics. - Deep knowledge of OS internals, firewalls, network security, and security frameworks. - Hands-on experience with SIEM, EDR, IDS/IPS, and vulnerability scanners. - Strong analytical, communication, and documentation skills. - Ability to stay calm and effective during high-severity incidents. - Passion for continuous learning and staying ahead of emerging threats. - Experience with MSP/MSSP environments a plus; SonicWall experience preferred. Additional certifications (preferred) Security+, PenTest+, (ISC)² Associate, SSCP Other Details Rotational on-call and occasional off-hours support required.

United States
Job Closed