Associate Security Operations Engineer
Conference of State Bank SupervisorsAbout the role
Job Summary
The Associate Security Operations Engineer supports CSBS’s security operations by monitoring security tools, triaging alerts, and assisting with incident response and cyber threat hunting activities. This role works under the guidance of senior security staff to help detect, analyze, and respond to potential security events across the enterprise environment. The Associate Security Operations Engineer contributes to maintaining the confidentiality, integrity, and availability of systems by supporting security monitoring platforms, following established playbooks, and escalating issues as appropriate.
Essential Functions
To perform this job successfully, an individual must be able to perform each essential duty and responsibility satisfactorily. Reasonable accommodations may be made to enable individual with disabilities to perform the essential functions. Other duties may be assigned to meet business needs.
• Monitor and support enterprise security tools, including SIEM, EDR, identity platforms, and cloud security solutions, to detect potential threats and anomalous activity.
• Review, triage, and escalate security alerts in accordance with established procedures and playbooks.
• Assist in incident response activities, including investigation, containment, documentation, and post-incident analysis.
• Support cyber threat hunting efforts by analyzing logs, endpoint data, and system activity to identify indicators of compromise or suspicious behavior.
• Support proactive cyber threat hunting and detection engineering efforts to improve overall security posture.
• Assist with the collection and analysis of security event data from multiple sources (endpoints, network, identity, cloud platforms).
• Help maintain and tune detection rules, alerts, and monitoring configurations to improve visibility and reduce false positives.
• Document incidents, findings, and response actions in ticketing and case management systems.
• Collaborate with senior engineers and cross-functional teams to support remediation and recovery efforts.
• Support vulnerability management activities by tracking findings and assisting with remediation follow-up.
• Assist in maintaining and updating security operations playbooks, runbooks, and standard operating procedures.
• Participate in continuous monitoring and operational readiness activities.
• Stay current on emerging threats, attacker techniques, and security best practices.
Additional Responsibilities
• Monitor industry trends for changes in compliance challenges and contribute to organization planning, policy and procedure changes in response.
• Assist in the development and refinement of security detection use cases aligned to threat intelligence and organizational risk.
• Support audit, compliance, and regulatory activities (e.g., NIST CSF, SOC 2, CJIS) by gathering evidence, logs, and documentation.
• Help validate security controls through participation in internal assessments, tabletop exercises, and incident simulations.
• Contribute to continuous improvement of SOC processes, including alert triage workflows and escalation procedures.
• Assist in integrating and onboarding new security tools and log sources into monitoring platforms.
• Support metrics and reporting efforts, including tracking incident trends, response times, and tool effectiveness.
• Participate in knowledge sharing and team training activities to build security operations maturity.
• Maintain awareness of evolving threat landscape, including common attacker tactics, techniques, and procedures (TTPs).
Minimum Qualifications
To perform this job successfully, an individual should possess the knowledge, skills, and abilities listed and meet the amount of education, training and/or work experience required.
Education and Experience
• B.S. degree in Computer Science or equivalent experience.
• Microsoft and Security Certifications are highly desired.
• 1–2 years of experience in cybersecurity, IT operations, system administration, or network support.
• Demonstrated experience in security monitoring, log analysis, or incident response processes is preferred.
• Experience working in cloud environments including AWS is a plus.
• Basic scripting or automation experience (e.g., Python, PowerShell) to automate routine functions is a plus.
Knowledge, Skills and Abilities
• Knowledge of security tools and platforms (e.g., SIEM, EDR, IAM, and network security controls), with familiarity using tools such as CrowdStrike and Okta is a plus.
• Knowledge of Cloud platforms and operations.
• Familiarity with the NIST Cyber Security Framework.
• Foundational understanding of cybersecurity principles, including threat detection, incident response, and vulner
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s