Job Closed

This listing is no longer active.

InstantServe LLC logo
InstantServe LLC

Changing People, Processes & Perceptions.

Security Operations Next-Gen SIEM Analyst

Security OperationsSecurity OperationsFull TimeRemoteMid LevelTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

9 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

Security Operations Next-Gen SIEM Analyst

InstantServe LLC

Role Description This project will optimize the agency's CrowdStrike SIEM and related CrowdStrike services to improve threat detection, monitoring, and response capabilities. The contractor will expand and tune telemetry, integrate additional high-value log sources, enhance security dashboards, and support the rollout of additional CrowdStrike services. The effort will increase visibility into endpoint and security risk, improve signal quality and correlation, and provide security leadership with clear insight into security operations effectiveness and overall risk posture. Expected Outcomes - Expanded and optimized CrowdStrike SIEM telemetry coverage - Integration of additional high-value log sources - Improved dashboards for operational and executive visibility - Enhanced detection fidelity and monitoring effectiveness - Clearer insight for leadership into endpoint risk and security operations performance Duties to Be Performed - Assess current CrowdStrike SIEM configuration, telemetry coverage, and log ingestion - Enable and tune additional CrowdStrike telemetry to improve visibility and signal quality - Identify and integrate new high-value log sources into CrowdStrike SIEM - Develop and refine security dashboards aligned to SOC and executive use cases - Assist with technical enablement and rollout of additional CrowdStrike services - Validate data quality, parsing, and correlation within the SIEM - Coordinate with Security Operations, IT Operations, and system owners - Identify gaps, risks, and improvement opportunities in monitoring and detection - Provide weekly status updates and monthly executive-level progress summaries - Deliver supporting documentation and recommendations to sustain improvements Deliverables - Summary of work performed and capabilities delivered - Documentation supporting all telemetry enablement, log integrations, and dashboard implementations - Measurable improvements in monitoring, detection, or visibility - Recommendations for future enhancements or next-phase efforts Qualifications - Demonstrated skill with documentation, reporting, and knowledge transfer - Experience with Stakeholder Engagement and Executive Communication - Experience in SIEM Detection Engineering and Alert Optimization - Experience in Log Source Integration and Data Normalization - Hands-On Experience with CrowdStrike SIEM and Dashboard Development - Hands-On Experience with SIEM and Dashboard Development

Related Categories

Related Job Pages

More Security Operations Jobs

DEUNA logo

Security Operations Lead

DEUNA

Libera el poder de tu e-commerce

Full TimeRemoteTeam 51-200H1B No Sponsor

• Strengthen DEUNA's security posture as we continue scaling our global payments platform. • Build and operate modern cloud security capabilities that protect millions of payment transactions. • Partner closely with Infrastructure, Engineering, Compliance, and Product teams to improve security maturity. • Own security monitoring, threat detection, and incident response processes. • Build and continuously improve SIEM, detection rules, alerting, and security automation. • Lead vulnerability management, remediation tracking, and risk prioritization. • Drive cloud security initiatives across AWS, Kubernetes, containers, IAM, networking, and secrets management. • Manage endpoint security, identity security, privileged access management, and access reviews. • Coordinate external penetration tests, red team exercises, and security assessments. • Develop security metrics, dashboards, and executive reporting.

Colombia
Palo Alto Networks logo

SecOps Transformation Advisor

Palo Alto Networks

Palo Alto Networks is committed to protecting our digital way of life through innovation and impact. We value disruption, collaboration, execution, integrity, and inclusion, and we empower our employees to push boundaries and evolve together.

Full TimeRemoteTeam 10,001+H1B Sponsor

• Contribute to sales strategy and consultative discovery • Drive XSIAM revenue across all segments • Initiate executive relationships with prospective customers • Demonstrate the business value of XSIAM • Craft customer-specific proposals and business cases • Collaborate across sales teams to achieve synergies

Arizona + 4 moreAll locations: Arizona | Colorado | Nevada | Utah | Washington
$264K - $363K / year
Job Closed
Twilio logo

Senior Security Engineer, Incident Response

Twilio

Build the future of communications.

Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications. • Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams. • Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity. • Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents. • Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment. • Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents. • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work. • Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

California + 5 moreAll locations: California | Connecticut | New Jersey | New York | Pennsylvania | Washington
$141.5K - $176.9K / year
Full TimeRemoteTeam 1-10H1B No Sponsor

Security Operations Engineer Reserv Technologies, LLC Remote (Atlanta, GA) About Reserv Reserv is an InsurTech company creating and incubating cutting-edge AI and automation technology to bring efficiency and simplicity to claims. We’re stripping away the "mundane" to set a new global standard for the insurance industry! Founded by industry veterans, with deep experience in SaaS and digital claims, Reserv is venture-backed by Bain Capital and Altai Ventures and began operations in May 2022. We’re focused on automating highly manual tasks to tackle long-standing problems in claims while setting the new standard for TPAs, insurance technology providers and adjusters alike. As our Cybersecurity Analyst you won't just be watching a dashboard; you’ll be helping to build the shield that protects our digital assets and our customers. You’ll be responsible for executing tactical daily tasks and participating in broader planning efforts. If you thrive on novel problem-solving and adapt quickly to new technologies, you’ll fit right in! This is a hands-on technical role focused on protecting the organization’s digital assets from cyber threats by monitoring networks, identifying vulnerabilities, implementing security measures, threat hunting, responding to breaches and developing security policies & procedures. No day will be the same and you will continuously learn & grow! Successful candidates will bring experience utilizing and configuring various security tools such as IDP, EDR/XDR, SIEM, SOAR, IDS/IPS and secure email gateways. What to expect - Continuously monitor security telemetry to identify potential threats, malicious activity, or unauthorized access. Sniff out threats before they become a headline! - Investigate, analyze, classify, prioritize and contain security breaches in real-time, providing detailed reporting and post-incident analysis. Build a secure plan, not a work around, so it never happens again! - Conduct vulnerability assessments to identify system weaknesses before they are exploited - Coordinate and assist with penetration testing activities - Install, configure and maintain security software and systems such as endpoint security, intrusion detection, prevention systems and logging platforms - Install and fine-tune our arsenal—from EDR/XDR and SIEM to SOAR and IDS/IPS. - Research, analyze and stay up to date on the latest security trends, hacking techniques, emerging cyber threats - Educate employees and stakeholders on security protocols, phishing threats and data protection - Develop SOPs, playbooks/runbooks to consistently respond to common incidents that allow our security posture to scale as fast as our business - Hunt for unknown threats in the environment by analyzing logs based on current and emerging threat intelligence. Be the hero who identifies potential threats before they happen! Does this sound like you? - Minimum of 3 years of experience in the trenches of a dedicated cybersecurity role - Working understanding of NIST Cybersecurity Framework - Technical proficiency with MacOS, Windows, Unix/Linux - Experience securing and monitoring mobile devices - Knowledge of current threat actors, TTPs, and MITRE ATT&CK framework - Fluent in SIEM, EDR/XDR, and Vulnerability Scanners - Experience with cloud-based productivity platforms such as Google Workspace and/or Microsoft 365 - Demonstrated experience working with SIEM tools, vulnerability scanners, endpoint protection, email security and threat intelligence platforms - Experience with penetration testing - Experience performing risk assessments, drafting/maintaining cybersecurity policies and procedures, and constructing after-action reports with precise details - Familiarity with SSO and identity and access management systems - Security+, CySA+ or similar industry-standard security certifications - Strong written and verbal communication skills - You possess a relentless technological curiosity where "sniffing out" anomalies is becoming second nature - Experience working in a cloud-first or startup environment Icing on the cake - Bachelors degree in Cybersecurity, IT, or related field - Automation experience with various scripting languages (e.g. Bash, Python, PowerShell) - AWS and/or GCP certifications or demonstrated experience - Deep understanding of at least two major operating systems - Familiarity with the concepts of secure software development (SSDLC) What we offer - Generous health-insurance package with nationwide coverage, vision, & dental - 401(k) retirement plan with employer matching - Competitive PTO policy – we want our employees fresh, healthy, happy and energized - Generous family leave policy - Work from almost anywhere to facilitate your work life balance - Cool, functional swag - Apple laptop, large second monitor, and other quality-of-life equipment you may want Technology is something that should make your life easier, not harder! At Reserv, we value diversity and believe that a variety of perspectives leads to innovation and success. We are actively seeking candidates who will bring unique perspectives and experiences to our team. We welcome applicants from all backgrounds and encourage those from underrepresented groups to apply. If you believe you are a good fit for this role, we would love to hear from you!

Georgia