Staff Security Operations Engineer
Seniority
Staff
Domain
Security Operations, Information Security, Telemetry Infrastructure
Required skills
SIEM, security data lakes, detection as code, EDR, zero trust networking, incident response and management, MITRE ATT&CK, authentication and authorization schemes (SAML, OpenID, OAuth2, SCIM), scripting/coding (Python, NodeJS, Ruby, Bash), communication, analytical acumen, self-motivation, cross-functional collaboration
Preferred skills
Panther (SIEM), Wiz, cloud native security tooling (AWS, Azure, GCP), SANS GIAC certifications, developing and maintaining detection rules (Sigma, YARA, Splunk SPL, KQL)
Responsibilities
Strengthen security posture, lead security incident management, triage, and investigations, develop innovative solutions to remediate threats, design and optimize detection logic, partner with Product Security, IT, and Legal teams, monitor security events and alerting, develop high-fidelity detection rules, conduct continuous tuning of detection logic, respond to issues, act as security incident response lead, build and manage security playbooks, conduct security assessments (vulnerability testing, threat hunts, purple team activities), perform security reviews, lead tabletop exercises, champion Cribl products in security tech stack, integrate IOCs and TTPs