Security Operations Engineer, Cloud & Endpoint Defense
Core
Operate, tune, and improve security tools across endpoint, cloud, and edge security to reduce alert noise and strengthen detection coverage.
Role type
Security Operations Engineer (Cloud & Endpoint Defense)
Builds
Security operations function, incident response capabilities, and improved security visibility for the organization
Domain
Cybersecurity, Cloud Security, Endpoint Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Endpoint security tool operation (CrowdStrike Falcon/EDR/XDR), AWS security services (GuardDuty, CloudTrail, IAM, VPC, CloudWatch), WAF/CDN/edge security controls, incident response fundamentals (triage, investigation, containment, remediation), log analysis (endpoint, cloud, web, network, application), DevOps collaboration, technical curiosity, process improvement, documentation
Preferred skills
SIEM/SOAR/detection engineering experience, scripting/APIs/Terraform/infrastructure as code, AWS Security Hub/Config/IAM Access Analyzer/CloudTrail Lake, SaaS/cloud-native/DevOps environment experience, relevant security certifications
Technologies
CrowdStrike Falcon, AWS GuardDuty, Cloudflare WAF/rules, AWS CloudTrail, AWS IAM, AWS VPC, AWS CloudWatch, AWS Security Hub, AWS Config, Terraform
Responsibilities
Operate and maintain security platforms (CrowdStrike, AWS GuardDuty, Cloudflare WAF), configure rules/alerts/policies, review security findings and validate severity, support incident response activities, investigate suspicious activity across cloud/endpoint/network, collaborate with DevOps teams, identify gaps in logging/visibility/processes, maintain security runbooks and documentation, monitor tool health and coverage
Seniority
Mid-level (3-5 years experience), hands-on IC