Jobs and Careers
CO

Lead Security Engineer | US Remote

Coalfire
United States, United StatesRemotefull_timeVerifiedPosted 27 Jan 2023
💰 $163,000/yr($94,000/yr$163,000/yr)

About the role

About Coalfire Coalfire is on a mission to make the world a safer place by solving our clients’ toughest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.  But that’s not who we are – that’s just what we do.  We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.    And we’re growing fast.  We’re looking for a Lead Security Operations Engineer to support our Managed Services team. This can be a remote position (must be located in the United States). Position Summary As a Lead Security Operations Engineer at Coalfire within our Managed Services group, you will be a self-starter, passionate about cloud security, and thrive on problem solving. You will work within major public clouds and best-of-breed tools, utilizing your technical abilities to monitor security for the most cutting-edge offerings from Cloud Service Providers (CSPs). This role directly supports leading cloud software companies to provide security of their SaaS product to the largest enterprises and government agencies around the world.

What You'll Do

  • Be a point of escalation for our 24x7x365 security monitoring for multiple clients while working closely with DevOps and product teams
  • Work across a myriad of technology stacks in leading cloud providers like AWS, Azure, and GCP
  • Automate/Oversee the process to analyze security events using logs and open-source knowledge to determine legitimate or false positive nature
  • Maintain a record of security monitoring activities via case management and ticketing technologies
  • Develop processes & best practices/procedures for intrusion detection, file integrity, endpoint protection, log management and SIEM solutions
  • Develop overall architecture and standards for security tools using a wide variety of data sources that use various protocols
  • Set standards for environment-specific rules, alerts, and dashboards in SIEM tooling via custom queries
  • Consult with clients to customize and configure SIEM tools in order to meet security and compliance requirements.
  • Support incident response process to address security anomalies in the environment.
  • Apply technical writing skills to create formal documentation such as analytical reports and briefings
  • Develop and maintain standard operating procedures and training materials
  • Participate in on-call rotations as needed to support client operational needs that may lay outside of business hours
  • Conduct testing and data reviews to evaluate the effectiveness of current security and operational measures
  • Lead the administration and maintenance of SIEM, Log Management, and Data Analytical Platform
  • Conduct System Health Checks on managed technologies and provide recommendations on performance improvements.
  • Schedule and run regular technical changes such as version updates, security patches, major software releases following best practices for change management policies and procedures
  • Lead the resolution for customer-initiated requests such as Log Source configuration, App installation, Data Parsing, Use Case Development, and Troubleshoot complex issues for managed technologies.
  • Develop technical solutions to automate repeatable tasks
  • Provide overall guidance, instruction, and leadership to the Security Analysts
  • Areas of responsibility will include onboarding new data sources, developing alerting, developing run books, conducting security investigations, responding to incidents, and deploying security solutions in a rapidly growing environment

What You'll Bring

  • BS or above in related Information Technology field or equivalent combination of education and experience
  • 5-7 years experience in 24x7x365 production security operations
  • 5-7 years experience administering and operating security tooling such as SIEM, IDS, and endpoint protection
  • 4+ years of hands-on technical experience supporting cloud operations and automation in Azure, AWS, and/or GCP
  • Must have ELK stack experience
  • Experience with ITSM solutions such as Jira and ServiceNow
  • Certifications such as Splunk Enterprise Certified Admin/Splunk Power User or ELK Certification.
  • Proven experience configuring, implementing, and supporting Splunk Enterprise components deployed in the Cloud
  • Knowledge of scripting languages such as Python
  • Understanding of regular expression and query languages
  • Practical experience in administration of Linux infrastructure.
  • Experience in Information Secur

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Coalfire

View company profile →