Security Operations Remote Jobs in Washington (US)
This page tracks remote security operations openings that are location-eligible for Washington.
This page tracks remote security operations openings that are location-eligible for Washington.
Open jobs
239
Hiring companies this week
10
Salary sample
$70,000 - $230,000
Jobs added last hour
0
239 Jobs
184 Companies
Figma was founded in 2012 to build a collaborative, professional-grade interface design tool for the digital age. Created specifically for interface design and built entirely in th
Role Description Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full-time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: - Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement. - Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling. - Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity. - Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments. - Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps. - Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs. - Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents. - Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction. Qualifications - 7+ years of experience in security operations, incident response, or a related security engineering function. - Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms. - Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment. - Demonstrated success building, scaling, or significantly improving a detection and response program. - Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events. Requirements - While it's not required, it's an added plus if you also have: - Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements. - Applied AI risk management frameworks such as NIST AI RMF, OECD AI Principles, or ISO 42001. - Utilized AI-powered tools to automate security operations workflows and improve team efficiency. Benefits - Figma offers equity to employees, as well as a competitive package of additional benefits, including: - Health, dental & vision. - Retirement with company contribution. - Parental leave & reproductive or family planning support. - Mental health & wellness benefits. - Generous PTO. - Company recharge days. - Learning & development stipend. - Work from home stipend. - Cell phone reimbursement. - Sales incentive pay for most sales roles. - Annual bonus plan for eligible non-sales roles.
Managed endpoint protection, detection and response for the 99% who need it most.
• Triage, investigate, and respond to alerts coming in from the Huntress platform. • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine the root cause of attacks, where possible, and provide remediations needed to remove the threat. • Perform tactical malware analysis as part of investigating and triaging alerts. • Investigate suspicious Microsoft M365 activity and provide remediations. • Assist in escalations from the Product Support team for threat-related and SOC-relevant questions. • Contribute to detection engineering creation and tuning efforts. • Contribute to projects focused on driving better outcomes for our analysts and partners • Contribute to our collaboratively mentored team (we're all here to make each other better!).
Apollo is the GraphQL company. Our mission is to empower every developer with a graph.
• Partner with engineering teams to conduct threat modeling and security reviews on new features and architecture changes • Establish and evolve Apollo's application security program including SAST/DAST tooling, dependency scanning, and secure coding standards • Drive security requirements into the SDLC, embedding security gates into CI/CD pipelines • Identify and remediate vulnerabilities in Apollo's products and APIs, with a focus on reducing systemic risk rather than one-off fixes • Act as a security advisor for product teams building customer-facing features, particularly those involving authentication, authorization, and data handling • Advance Apollo’s detection and response strategy in partnership with engineering and IT leadership • Implement and maintain adherence to SOC 2 and other cloud security frameworks • Handle escalations from Sales and Customer Success • Build and tune monitoring, logging, and alerting systems to improve visibility while reducing noise • Drive automation of SecOps workflows to speed up investigation and response • Guide secure adoption of AI across Apollo - from internal use by engineers to AI-powered product features • Participate in our on-call rotation (we keep this lightweight and reasonable)
As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Role Description IMPORTANT, PLEASE READ BEFORE APPLYING - Due to Federal requirements, only US citizens, US naturalized citizens or US Permanent Residents, holding a green card, will be considered. The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact. What you get to do in this role: - Serve on the frontline of security operations, supporting both ServiceNow’s commercial customers and its federal environment. - Monitor tools and systems that defend ServiceNow’s production and corporate environments. - Define relationships between seemingly unrelated events through deductive reasoning. - Continuously find ways to do things faster, better, and more effectively while maintaining a laser focus on quality. - Work on a geographically diverse team to respond to threats against our infrastructure and track cases to closure. - Participate in an on-call rotation including weekends to ensure timely response to priority incidents. - Work weekend rotational shifts and hours (Pacific Time Zone) outside of standard business hours if necessary. Qualifications - Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. - 2+ years of related experience or equivalent combination of education and experience. - Deep understanding of Security Operations Center and Security Incident Response Team protocols and procedures. - A solid foundation in networking fundamentals, with a deep understanding of TCP/IP and other core protocols. - Experience with SIEM platforms (e.g., Splunk) for log analysis and detection tuning. - Familiarity with EDR tools for endpoint detection and response. - Exposure to SOAR platforms for workflow automation and incident orchestration. - Knowledge of cloud security concepts and experience working in cloud environments (AWS, Azure, or GCP). - The ability to analyze event and system logs, perform forensic analysis, analyze malware, and process other incident response-related data as needed. - Familiarity with intrusion detection systems. - Understanding of Windows and Linux operating systems and command-line tools. - Familiarity with scripting in any language. Requirements - Any cybersecurity or network related certifications (e.g., CCNA, CompTIA, GSEC, GCIH, CEH certifications) are a plus. - ServiceNow platform knowledge is a plus. Benefits - Base pay of $97,600 - $151,300, plus equity (when applicable), variable/incentive compensation and benefits. - Health plans, including flexible spending accounts. - 401(k) Plan with company match. - Employee Stock Purchase Plan (ESPP). - Matching donations. - Flexible time away plan and family leave programs.
Unqork is no-code computer software platform that is on a mission to reimagine the way businesses develop, launch, and manage enterprise-grade applications. As
• Security Monitoring & Alert Triage: Actively monitor SIEM, EDR/XDR, and other security tools to detect, analyze, and triage security alerts. Follow established playbooks to ensure timely and accurate initial response to potential threats. • Process Efficiency & Automation: Utilize existing Security Orchestration, Automation, and Response (SOAR) platforms to handle alerts efficiently. Identify repetitive manual tasks and implement automations. • SIEM & Detection Engineering: Integrate and set up the ingestion of log sources to a SIEM tool, including the normalization of fields and data. Create timely monitoring solutions for relevant threats based on active threat intelligence. Share responsibility for detection and log lifecycle / maintenance. • Threat Intelligence: Consume and review daily threat intelligence feeds, security advisories, and industry alerts to ensure the company is protected against known Indicators of Compromise (IoCs) and emerging threat trends. • IT Operations & Asset Security: Work closely with IT Operations to maintain accurate hardware and software asset inventories. Assist in deploying and troubleshooting endpoint security agents to ensure a secure baseline for all employee devices. • Cross-Functional Technical Partnership: Collaborate extensively with resources in Engineering, Product, IT, and other departments to embed operational security requirements, influence architectural decisions for detectability, and foster a strong security culture. Serve as the primary security technical expert for these partnerships. • Compliance & Operational Reporting: Assist in generating routine security metrics and operational reports. Help gather technical evidence to support adherence to security policies and compliance audits (e.g., SOC 2, ISO 27001).
A different breed of specialty technology distributor. #ClimbWithUs
• Lead the development, rollout, and operations of security operations tools and services such as SIEM, EDR, NDR, email, cloud; building detection rules, automated playbooks, and integrations • Serve as a technical resource for security operations analysts; conduct design reviews and provide engineering guidance on detection and response workflows • Apply a detections-as-code approach; version-controlled, peer-reviewed, and tuned against alert quality metrics • Architect and implement security engineering capabilities, including endpoint security, data loss prevention, email security, network security, SIEM enhancements, detection engineering, and security automation. • Partner with cross-functional teams to perform threat modeling and embed security requirements in the development lifecycle. • Research, evaluate, and operationalize security products and services (including AI enabled platforms), building proof-of-concept integrations, provide recommendations or deferrals on adoption, and driving adoption across the security stack.
Role Description Unit4 Global Cloud Operations Team is seeking a skilled Security Operations Engineer to join our international team. As part of this dynamic team, you will play a key role in maintaining the security and integrity of our cloud infrastructure and environments. You will monitor security systems, analyze threats, and manage security incidents from detection through resolution, ensuring a robust defense against emerging threats. Key Responsibilities - Continuous Monitoring: Continuously monitor cloud environments for potential security threats. - Threat Analysis: Analyze security alerts and logs to identify suspicious activities. - Incident Response: Lead response efforts during security incidents, including containment, eradication, and recovery. - Investigation: Investigate security breaches and identify root causes. - Post-Incident Review: Conduct post-incident analysis to suggest improvements. - Documentation: Document security incidents and maintain detailed records. - Customer Incident Handling: Act on security incidents reported by customers or identified proactively. - Policy Adherence: Follow established security policies and procedures. - System Maintenance: Monitor and maintain security systems such as firewalls, intrusion detection and prevention systems, and SIEM systems. - Preventative Measures: Implement security measures to prevent future incidents. - Staying Current: Stay up-to-date with the latest security trends and technologies. Qualifications - 3+ years of relevant experience in security monitoring, analysis, and incident response. - Knowledge and experience in hardening OS and other environments/systems. - Knowledge and experience with security-related group policies and their implementation. - Knowledge of forensic analysis and incident management tools. - Familiarity with SIEM tools and security incident management. - Strong analytical and problem-solving skills. - Excellent communication skills, both written and verbal. - Ability to work under pressure and manage multiple incidents simultaneously. - Understanding of security policies and procedures. - Experience with firewalls, intrusion detection/prevention systems, and SIEM systems. Requirements - Familiarity with Microsoft Azure & Microsoft certifications. - Experience with AWS. - Experience with scripting languages (e.g. PowerShell) for automation. - Knowledge of networking, and PKI infrastructure. - Basic Linux skills. Benefits - A culture built on trust and accountability - giving you the freedom and autonomy to be successful and make an impact. - Balance - with our Flexible Leave Paid Time Off policy, remote working opportunities, Global Wellbeing Days, and other great benefits. - Growth opportunities - we provide the tools and guidance required so that you can focus on what really matters to you and so, ultimately, you can achieve your best work. - Talented colleagues, role models and mentors - work, learn and be inspired by some of the best talent in the software industry. - A commitment to sustainability - with initiatives such as our Environmental, Social, and Governance strategy and Act4Good programme. - A safe and inclusive working environment – supported by our Employee Resource Groups, which are open to all.
Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
Role Description The NISC IV program at Leidos is seeking an Operations Security Data Release Support Specialist to provide support to the Federal Aviation Administration (FAA) System Operations Security Group. Support will require you to assist the government in addressing a broad range of NAS Data Release Board (NDRB) issues associated with protection of sensitive flight data (SFD) and operations security (OPSEC) issues associated with air traffic control, airspace restrictions, SFD identification and protection, Standard Operating Procedures Development, FAA Prohibitions, Restrictions, and Notices (PRN), Limiting Aircraft Data Displayed (LADD) program, and data release issues associated with integration of unmanned aerial systems (UAS) in the NAS. You will support the development of solutions to complex air traffic management (ATM) operations security and data release projects and programs for NAS stakeholders. - Support the OPSEC, privacy, and data release procedures and policies of the FAA as they pertain to the security of the NAS. - Maintain and publish the Limiting Aircraft Data Displayed (LADD) program database. - Support during development and writing of OPSEC and data release policy and procedures for sensitive military and law enforcement flight operations, flight data identified as Sensitive Unclassified Information (SUI) and Controlled Unclassified Information (CUI), and aircraft privacy programs through Document Change Proposals (DCPs) for FAA Orders; Notices to Airmen (NOTAMs); Memorandums of Agreement (MOAs), Letters of Agreement (LOAs), and/or other written documents as required. - Respond to security-related issues such as Sensitive Flight Data, call sign requests, LADD Program, Sensitive FAA Publications and Orders, FOIA requests, PRN site requests, and other security related issues. - Systematically gather and analyze information and manage privacy, operations security (OPSEC), and flight data protection risks and associated mitigations for Federal, State, and Local law enforcement and other government agencies. - Technical support for meetings and direct interface with government and law enforcement agencies and other NAS stakeholders regarding OPSEC, privacy, and NAS data release requirements. - Updates to Sensitive Flight Data (SFD) and/or LADD program identification and protection data for use by FAA data release programs. - Be the focal for coordinating, updating, and development of AJR-2 internal SOP’s. - Provision of other written products to the government when required. - Support for related briefings regarding OPSEC and NAS data release issues for public, local, state and federal stakeholders when required. - Support J-CAT operations and development of J-CAT procedures, work tools, and templates. Qualifications - Bachelors degree and 12 – 15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience or if no degree, additional related work experience can be substituted. - Knowledge of FAA NAS security processes and information systems. - Experience managing Sensitive Flight Data. - Excellent oral and written communication skills and ability to handle multiple tasks and deadlines. - Skill in communicating at the senior leadership level within the FAA and external entities requesting approval for release of FAA NAS data. - Experience with Microsoft Office and Adobe Acrobat Pro. - Must be familiar with J-CAT Operations and enterprise level responses to natural disasters and other significant incidents affecting the NAS. Preferred Qualifications - Familiarity with FAA NAS data systems including ADS-B and secondary surveillance radar data, and SWIM data systems. - Familiarity with FAA Prohibitions, Restrictions, and Notices (PRN). Original Posting June 2, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range Pay Range $116,350.00 - $210,325.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
MedPro Group’s mission is built on a century-old legacy of protecting those who protect others. From our roots in our hometown of Fort Wayne, Indiana, we've worked diligently to become the nation's premier healthcare liability coverage provider, currently insuring more than 300,000 customers. With that growth, we've built a significant presence in all 50 states. Our team works across the country to provide the best strategies to mitigate risk and preserve the reputations of those who have entrusted their good name to us. That passion – built on a foundation of a culture that values uncompromised integrity, obsessive client focus, great teamwork, and a long-term mindset – make MedPro a preferred employer that many call their career home. General: MedPro Group is an Equal Opportunity Employer. The annual gross base salary range is $93,040 to $130,000. This range anticipates the low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate’s qualifications, skills and competencies. Salary is one component of MedPro’s total compensation and benefits package. For a more detailed overview, visit our careers website at www.medpro.com/careers.
Role Description We are seeking a Security Operations Center Manager who will lead and mature our 24x7 cybersecurity threat detection and response processes, procedures, and strategy, manage and provide oversight for the team of analysts and associated vendors, and other various cybersecurity operations responsibilities. The role will also support the Deputy Chief Information Security Officer (Deputy CISO) in defining controls and governance for the overall corporate cybersecurity strategy with a focus on: - Incident response - Logging & analysis - Regulatory compliance - Ongoing defense & detection hardening of the various on-prem and Cloud technologies utilized by the enterprise In this role, you will… - Lead the 24x7 incident detection and response team and day-to-day efforts. - In the event of a breach, lead efforts with detection, containment, and mitigation as well as aid the corporate response team (General Counsel, HR, Marketing, etc.) as needed. - Update and maintain the Incident Response Plan's processes and procedures to keep current with industry best practices, regulatory requirements, and the threat landscape. - Lead efforts in ongoing tabletop and red/blue team exercises to continue implementing better defenses and quick incident detection and response. - Research and understand the regulatory and compliance mandates to ensure cybersecurity practices fulfill these requirements. - Lead efforts with external and internal audit control compliance and responses to due diligence inquiries. - Review industry news, intelligence reports, and emerging technologies to ensure MedPro is taking the proper action to mitigate risk and improve defenses. - Provide recommendations and assistance with developing short and long-term enterprise-wide cybersecurity goals and objectives. - Assist with security assessments and help provide recommendations on applications, vendor, and business & technical team processes and practices used by MedPro. - Work closely with and provide support to the cybersecurity technical team. - Assist with the execution and completion of cybersecurity related projects. - Perform other related duties. Qualifications - Bachelor's degree in computer science, computer engineering, information technology with a focus on cybersecurity, or relevant field. - Seven years of management and industry experience or ten years of management and relevant cybersecurity related experience. - A thorough understanding of cybersecurity defense hygiene and industry best practices (like MITRE ATT&CK tactics) and risk management frameworks (like NIST, COBIT, or OCTAVE). - Strong knowledge of financial services cybersecurity regulations and controls. - Significant experience leading security incident response activities (including detection, analysis, containment, response, and prevention procedures). - Experience with building, defining, and leading 24x7 SOC teams and efforts. - Experience with vendor contracting and management. - A thorough understanding of Cybersecurity attack and defense methodologies. - Ability to work independently, while reporting back to team leader/manager on any issues or concerns in a timely fashion. - Excellent learning, teamwork, relationship management, influence, and creativity skills. - Excellent customer service skills. - Excellent oral and written communication skills. Benefits - Medical, vision, and dental insurance options - Life and accident insurance - 401(k) - Short-term and long-term disability insurance Company Description MedPro Group’s mission is built on a century-old legacy of protecting those who protect others. From our roots in our hometown of Fort Wayne, Indiana, we've worked diligently to become the nation's premier healthcare liability coverage provider, currently insuring more than 300,000 customers. With that growth, we've built a significant presence in all 50 states. Our team works across the country to provide the best strategies to mitigate risk and preserve the reputations of those who have entrusted their good name to us. That passion – built on a foundation of a culture that values uncompromised integrity, obsessive client focus, great teamwork, and a long-term mindset – makes MedPro a preferred employer that many call their career home.
We are a global education technology company equipping learners with the skills and competencies needed to be job ready.
Role Description As the Director of Security Operations at Cengage, you will play a pivotal role in our ambitious Information Security department. You will lead an extraordinary team to successfully implement innovative security measures, focusing on security operations from an engineering, cloud development, AI security, and vulnerability management perspective. In this role, you will: - Develop and coordinate security protocols to ensure detailed operations. - Collaborate with the Incident Response team to identify, bring up and mitigate security threats. - Implement sophisticated security solutions powered by artificial intelligence. - Manage vulnerability assessments and remediation processes. - Lead a team of skilled engineers to drive outstanding security outcomes. - Coordinate with Cloud Operations and Development Operations to highlight security improvement areas and lead initiatives to improve cyber hygiene in these areas. - Coordinate standard processes for Artificial intelligence security and application across the business. - Perform proactive threat modeling and testing to highlight areas of security improvement across all functions based on Threat Actor TTPs and Mitre Attack Framework kill chains. Qualifications - Significant background in security operations and managing vulnerabilities. - Deep knowledge of cloud development and AI security technologies. - Strong leadership and team management capabilities. - Ability to develop and enforce strict security protocols. - Outstanding problem-solving and analytical skills. Benefits - Comprehensive and rewarding Total Rewards package designed to support and empower employees. - Eligibility to participate in the company’s discretionary incentive bonus program. - Bonus target amount of 25% Annual: Individual Target. - Base pay range: $138,200.00 - $179,650.00 USD. Company Description Cengage, a global education technology company serving millions of learners, provides affordable, quality digital products and services that equip students with the skills and competencies needed to be job ready. For more than 100 years, we have enabled the power and joy of learning with trusted, engaging content, and now, integrated digital platforms. We serve the higher education, workforce skills, secondary education, English language teaching, and research markets worldwide. Through our scalable technology, including MindTap and Cengage Unlimited, we support all learners who seek to improve their lives and achieve their dreams through education.
229more opportunities are still waiting for you.Log in now and take your next shot before someone else does.
Cloud, Linux, MacOS, Apollo, SDLC, AWS