Job Closed

This listing is no longer active.

AHEAD, Inc. logo
AHEAD, Inc.

AHEAD, Inc. is an IT services and consulting company that is on a mission to “accelerate the impact of technology on business.” As an employer, the company

Senior Technical Consultant-Network Security Operations

Location

United States

Posted

102 days ago

Salary

0

No structured requirement data.

Job Description

Senior Technical Consultant-Network Security Operations

AHEAD, Inc.

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Technical Consultant, Network Security Operations, is a cybersecurity professional with knowledge around the Palo Alto XSIAM Platform, Cortex XDR, Cortex XSOAR and working knowledge around additional technologies. Responsible for the technical execution of XSIAM, XDR and XSOAR deployments with complex configurations. As a Technical Consultant, you will be a key player in implementing Security Operation tools for a diverse client base, helping them detect, respond and automate effectively. - Hands-on role in the end-to-end delivery of Palo Alto XSIAM, XSOAR, and XDR solutions to include deployment, configuration and customization to meet client requirements. - Develop and implement custom XSIAM, XSOAR and XDR content such as Correlations rules, data models, Automation Playbooks that streamline client SOC workflows. - Integrate a variety of data sources that ensure visibility across endpoint, network, cloud and identity. - Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform. - Act as a technical resource for troubleshooting and resolving complex XSIAM-related issues during and post-implementation. - Contribute to detection and Playbook strategies to enhance client security posture. - Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations. - Mentor junior AHEAD consultants, sharing your XSIAM knowledge and fostering their technical development. Qualifications - 3-5 years of dedicated experience in cybersecurity, with a strong practical background in SIEM, SOAR, EDR/XDR, or SOC operations. - 2-4 years of demonstrated threat intelligence and/or Incident response experience. - Minimum of 2 years of direct experience implementing and configuring XSIAM or similar advanced SecOps Platforms. - Demonstrated expertise in SIEM and Soar development to include creating playbooks, log collection, parsing and normalization. - Demonstrated expertise in EDR/XDR deployment and management with CrowdStrike, Cortex and Cisco. - Proficient with XQL for data analysis and rule creation. - Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows. - Strong analytical and troubleshooting capabilities. - Effective communication skills with the ability to engage with clients and Team members. - Palo Alto Network Certifications (PCNSE) or relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus. Requirements - $130,000 - $200,000 a year Benefits - Medical, Dental, and Vision Insurance - 401(k) - Paid company holidays - Paid time off - Paid parental and caregiver leave - Plus more! See benefits here for additional details.

Job Requirements

  • 3-5 years of dedicated experience in cybersecurity, with a strong practical background in SIEM, SOAR, EDR/XDR, or SOC operations.
  • 2-4 years of demonstrated threat intelligence and/or Incident response experience.
  • Minimum of 2 years of direct experience implementing and configuring XSIAM or similar advanced SecOps Platforms.
  • Demonstrated expertise in SIEM and Soar development to include creating playbooks, log collection, parsing and normalization.
  • Demonstrated expertise in EDR/XDR deployment and management with CrowdStrike, Cortex and Cisco.
  • Proficient with XQL for data analysis and rule creation.
  • Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows.
  • Strong analytical and troubleshooting capabilities.
  • Effective communication skills with the ability to engage with clients and Team members.
  • Palo Alto Network Certifications (PCNSE) or relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus.
  • $130,000 - $200,000 a year

Benefits

  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits here for additional details.

Related Categories

Related Job Pages

More Security Operations Jobs

Cyber Operations Intern

American Systems

Headquartered in Chantilly, Virginia, American Systems is a government contractor that provides professional, technical, and Information Technology services. Established in 1975, A

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for an entry level IT Security Analyst summer intern to perform the day-to-day operations of the security solutions and use these solutions to identify, investigate and resolve security incidents on the network. This is a great opportunity for someone who likes to dig in and understand the intricacies of cyber defense, has a technical hands-on mindset, and exhibits good work ethic and a positive attitude to learning the ins and outs of information security operations for an enterprise environment. - Co-Op / Interns typically represent college students trying to gain related work experience while pursuing an undergraduate degree. - Under direct supervision, performs various tasks and assignments for the organization's professional staff in such disciplines as Engineering, Software Development, Database Management, Security Threat Analysis. - Maintain in-place security tools and processes. - Evaluate, test and implement new security tools & technologies. - Respond to computer security incidents. - Research system and network logs and alerts as they relate to incidents. - Identify gaps in cyber operations capabilities and assist in developing those capabilities. - Develop technical summary information for presentation to management. Qualifications - High School diploma and 1-2 years of college or related work experience. - Understanding of incident response process in an enterprise operations environment. - Understanding of cyber threats and defenses against those threats. - Knowledge of Windows, Linux, and networking. - Knowledge of enterprise security technologies such as web filtering, endpoint protection and forensics, sandbox, threat intel integration, firewalls, SIEM, patch and vulnerability management etc. - Familiarity with using scripting languages for security automation. - Ability to juggle multiple tasks and projects with varying priorities. - Ability to document findings for audiences with various levels of technical expertise. - MUST BE A US CITIZEN. - Cyber Defense Club membership a plus! Benefits AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $43,200.00/Yr. - USD $72,100.00/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO Statement EEO Race/Sex/Disability Status/Veteran Status

United States
$55K - $65K / year
Job Closed
Anchorage Digital logo

Member of the Technical Staff, Security Operations

Anchorage Digital

Trusted institutional partner in crypto and first federally chartered crypto bank

OtherRemoteTeam 201-500Since 2017H1B Sponsor

Founded in 2017, Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. With the first federally chartered crypto bank in the US, Anchorage Digital offers institutions an unparalleled combination of secure custody, regulatory compliance, product breadth, and client service. We’re looking to diversify our team with people who are humble, creative, and eager to learn. We are a remote friendly, global team, but provide the option of working in-office in New York City, Sioux Falls, Porto, Lisbon, and Singapore. For our colleagues not located near our beautiful offices, we encourage and sponsor quarterly in-person collaboration days to work together and further deepen our Village The Security Operations team develops hardware and software solutions designed to establish and test security guardrails across the code, cloud resources, and hardware infrastructure of the Anchorage platform. By managing vulnerabilities in both in-house and third-party components, the team partners with service owners to secure networking and infrastructure while continuously monitoring for anomalies or unexpected configuration changes. To enhance efficiency, they strategically automate investigation tasks, threat isolation, inventory management, and assurance provision for regulated entities, all while conducting rigorous static and dynamic testing of application interfaces throughout the organization. We have created the Factors of Growth & Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Security Operations position. Technical Skills: - Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems. - Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance. - Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings. - Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform. Complexity and Impact of Work: - Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts. - Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings. - Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion. - Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations. - Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts. - Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact. Organizational Knowledge: - Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives. - Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture. - Consider security holistically across the product ecosystem—applications, infrastructure, and third-party integrations—while fostering a security-first culture. - Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes. Communication and Influence - Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure. - Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance. - Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes. - Demonstrate empathy by understanding others' context, priorities, and constraints—adapting communication style to maximize effectiveness with both technical and non-technical audiences. You may be a fit for this role if you have: - Security Operations or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations. - Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages. - Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies. - Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems. - Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging. - Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts. - You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures. - You genuinely care about code quality and operational excellence. - You prioritize security outcomes, end-user experience, and business value over "cool tech." - You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious. Although not a requirement, bonus points if: - You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.). - You have worked in a regulated financial services, fintech, or crypto environment. - You have exposure to blockchain security, smart contract auditing, or Web3 technologies. - You have built or contributed to open-source security tools. - You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.). - You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations. - You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :) We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

United States
Job Closed
AMERICAN SYSTEMS logo

Cyber Operations Intern

AMERICAN SYSTEMS

Supporting national priority programs since 1975. We know what's at stake.®

OtherRemoteTeam 1,001-5,000Since 1975H1B No Sponsor

• Perform day-to-day operations of security solutions • Identify, investigate and resolve security incidents on the network • Maintain in-place security tools and processes • Evaluate, test and implement new security tools & technologies • Respond to computer security incidents • Research system and network logs and alerts as they relate to incidents • Identify gaps in cyber operations capabilities and assist in developing those capabilities • Develop technical summary information for presentation to management

Virginia
$43.2K - $72.1K / year
Job Closed

Senior Technical Consultant – Network Security Operations

Thinkahead Consultant Psychologist Pty Ltd

We get to the heart of the matter.....real people......real solutions

OtherRemoteTeam 1-10H1B No Sponsor

• Hands-on role in the end-to-end delivery of Palo Alto XSIAM, XSOAR, and XDR solutions to include deployment, configuration and customization to meet client requirements. • Develop and implement custom XSIAM, XSOAR and XDR content such as Correlations rules, data models, Automation Playbooks that streamline client SOC workflows. • Integrate a variety of data sources that ensure visibility across endpoint, network, cloud and identity. • Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform. • Act as a technical resource for troubleshooting and resolving complex XSIAM-related issues during and post-implementation. • Contribute to detection and Playbook strategies to enhance client security posture. • Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations. • Mentor junior AHEAD consultants, sharing your XSIAM knowledge and fostering their technical development.

United States
$130K - $200K / year
Job Closed