Senior Cybersecurity Engineer, CSOC

Security OperationsSecurity OperationsFull TimeRemoteTeam 10,001+H1B SponsorCompany SiteLinkedIn

Location

Washington

Posted

4 days ago

Salary

$112.4K - $211.8K / year

Bachelor Degree5 yrs expEnglishCloudCyber SecurityJavaLinuxMac OSPythonRubyRustGo

Job Description

• Detect, assess and respond to alerts and incidents • Perform rapid triage to determine severity, validity, and urgency of alerts • Follow SOC playbooks and SOPs to ensure consistent triage and decision-making • Creates custom detections aligned to the MITRE ATT&CK Framework • Review and audit available logging to determine potential gaps in detection capabilities • Reviews threat intel reports and feeds, makes recommendations for profile or toolset changes based on reviews • Hunts for new threats and perform data analytics to surface activity not seen within the environment • Performs in-depth investigations on Windows, Linux, and MacOS hosts • Write stories for engineers to improve our SOAR environment • Support the improvement of SOC processes through feedback and operation observations • Acts as a mentor and escalation point for SOC engineers • Tune security tool configuration to minimize false positives • Collaborate with security leadership, engineering, and compliance to execute security strategies • Assess our current cloud security and propose improvements or solutions • Serve as a subject matter expert for security tools, applications, and processes

Job Requirements

  • 5+ years of experience working in an information technology discipline
  • 4+ years of security operations experience
  • Deep technical understanding of modern Cybersecurity threats
  • Ability to quickly learn new cybersecurity concepts
  • Understanding of the MITRE ATT&CK framework and the ability to create detections based on analysis of attacker tools & techniques using this framework
  • Proficient in programming with at least one modern language such as Python, Powershell, C#, Ruby, Java, Rust, Go
  • Experience with the following technologies: SIEMs, WAFs, IDS/IPS, EPP, EDR, FIM, DLP, Cloud Security, Container Security
  • Basic understanding of compliance and regulatory requirements such as SOX and PCI.
  • Ability to balance multiple priorities and meet deadlines
  • Excellent problem-solving abilities
  • Passionate about cybersecurity and self-driven to become an expert
  • Preferred Qualifications: Proficiency in two or more of the following technologies: SIEMs, WAFs, IDS/IPS, EPP, EDR, FIM, DLP, Cloud Security, Container Security
  • Proficiency in two or more of the following pillars: Phishing, DLP, Compliance, Networking, Forensics, Big Data, Threat Intel, Operating Systems, Reverse Engineering
  • Contributes back to the cybersecurity community through teaching or through code
  • Certifications such as CISSP, SSCP, GCIH or others focused on cybersecurity

Benefits

  • medical, dental, vision, basic and supplemental life insurance
  • short-term and long-term disability
  • paid parental leave
  • family expansion reimbursement
  • paid vacation from date of hire*
  • sick time (accrued at 1 hour for every 25 hours worked)
  • eight paid holidays
  • two personal days per year
  • 401(k) retirement plan with employer match
  • discounted company stock program (S.I.P.)
  • Starbucks equity program (Bean Stock)
  • incentivized emergency savings
  • financial well-being tools
  • 100% upfront tuition coverage for a first-time bachelor’s degree through Arizona State University’s online program via the Starbucks College Achievement Plan
  • student loan management resources
  • access to other educational opportunities
  • backup care
  • DACA reimbursement
  • compliance with state and local laws regarding employee leave benefits

Related Categories

Related Job Pages

More Security Operations Jobs

Security Operations4 days ago
Full TimeRemoteTeam 10,001+Since 2020H1B No Sponsor

Business Operations Leader (BOL) supports the Business Unit CISO and is a direct report to the Director of ES Cyber Business Operations. This role serves as the strategy and operations lead for the Executive Level 4 (L4) organization and is the primary Strategy & Transformation l...

United States

System Administrator - Crowdstrike

Gunnison Consulting Group

Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation. Quality is our top priority. Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer. There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow. We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding. We hire for careers at Gunnison, not to fill a position. Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time. In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Security Operations4 days ago
Full TimeRemoteTeam 201-500

We are seeking a skilled Cybersecurity System Administrator to support critical enterprise security operations. This individual will support cyber attack surface management and network defense with a strong emphasis on Crowdstrike. This is not a user-level position; hands-on syst...

CrowdstrikeCybersecurityNetwork DefenseSystem AdministrationArmisCorelightNISTZero TrustRMF
United States
$103K - $113K / year

Director, Physical Security Programs, Policy, and Assurance (Hyperscale)

Oracle

Only Oracle brings together the data, infrastructure, applications, and expertise to power everything from industry innovations to life-saving care. And with AI embedded across our products and services, we help customers turn that promise into a better future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of lives. True innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing a workforce that promotes opportunities for all. We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@oracle.com or by calling 1-888-404-2494 in the United States. Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Security Operations4 days ago
Full TimeRemoteTeam 10,001

This senior leadership role is responsible for driving Global Physical Security (GPS) programs, policy, and assurance across the organization's hyperscale environment. The position will coordinate various cross-functional stakeholders and oversee governance and documentation to ensure reliable and scalable security operations.

United States
$139K - $291K / year
Full TimeRemoteTeam 35,000

The investigator protects the company and members from fraudulent claims by investigating suspect activity in compliance with fraud laws and regulations. This involves applying knowledge of fraud schemes, collecting evidence through interviews and database searches, and preparing detailed investigative reports.

United States
$77.1K - $147K / year