- Company Name
- Gridware
- Job Title
- Security Operations Engineer
- Job Description
-
Job Title: Security Operations Engineer
Role Summary:
Leverage hands‑on expertise in cloud‑first environments to detect, triage, and remediate security incidents. Build resilient, automated defenses and embed security best practices across engineering, IT, and infrastructure teams.
Expectations:
Deliver rapid, accurate incident response; continuously refine threat detection logic; automate routine security tasks; maintain stringent identity and access controls.
Key Responsibilities:
- Lead incident response: triage, containment, post‑incident review.
- Analyze alerts from EDR, SIEM, network telemetry; differentiate false positives.
- Manage and tune EDR platforms; ensure comprehensive coverage and actionable alerts.
- Configure and optimize SIEM tools; improve log visibility, rule accuracy, and correlation.
- Develop detection rules, hunting queries (KQL, SPL, SQL‑like), and response playbooks aligned to emerging TTPs.
- Implement identity & access controls (conditional access, least‑privilege).
- Automate repetitive tasks via scripting/automation across monitoring, alerting, and response tools.
- Identify, assess, and coordinate remediation of vulnerabilities.
- Drive policy and compliance initiatives; align operations with NIST, CIS, ISO 27001.
- Document and publish playbooks; maintain operational efficiency.
Required Skills:
- 3–5 years in SOC, incident response, or security operations.
- Deep understanding of threat detection, analysis, and response workflows in cloud/enterprise settings.
- Hands‑on experience with EDR and SIEM platforms; tuning, rule creation, and alerting.
- Proficient in log/search languages (KQL, SPL, SQL‑like).
- Strong knowledge of IAM concepts: conditional access, RBAC, least‑privilege.
- Working knowledge of AWS, Azure, or equivalent cloud environments.
- Programming/automation skills (Python, PowerShell, or similar).
- Familiarity with vulnerability management lifecycle.
- Awareness of NIST, CIS, ISO 27001 and operational security frameworks.
- Analytical mindset; ability to discern real threats amid noise.
- Proactive, detail‑oriented problem‑solver.
Bonus Skills (desirable, not mandatory):
- Experience with SOAR, cloud security posture management, threat intelligence enrichment.
- Mapping detections to MITRE ATT&CK.
Required Education & Certifications:
- Relevant bachelor’s degree (Computer Science, Cybersecurity, Information Technology) **or** equivalent professional experience.
- Preferred certifications: CISSP, CEH, or analogous security credentials.
San francisco, United states
On site
12-11-2025