AHEAD

AHEAD

AHEAD accelerates the impact of technology on clients by engineering customized data, developer, and infrastructure platforms that improve IT operations. By weaving together cloud infrastructure, intelligent operations, and modern applications, we help...

IT Services
1K-5K
$43M raised

Description

  • Monitor and manage the health and performance of the client’s SIEM platform and deployed agents.
  • Implement and maintain cloud-based SIEM solutions and related integrations for the managed security program.
  • Design and create data visualizations, dashboards, and custom detection rules with the client security team.
  • Tune detection rules, filters, and policies to improve accuracy and visibility.
  • Attend client-facing security meetings and provide updates on SOC metrics, projects, and technical issues.
  • Join incident response bridges to analyze log data and provide technical support during security or IT incidents.
  • Onboard new data sources through ingestion, normalization, enrichment, and other integration methods.
  • Support remediation efforts for penetration test findings and validate infrastructure changes.
  • Provide evidence and documentation for audit and compliance questionnaires.
  • Perform capacity planning, data mining, and continuous improvement of SIEM content, workflows, and incident response processes.

Requirements

  • 2-4 years of experience in information security, incident response, or security automation.
  • Experience with Elastic Security and its components, including Elasticsearch, Logstash, Kibana, Filebeat, and Elastic Agent.
  • SIEM administration and configuration experience.
  • Experience writing automation tools or integrations in Python or another language.
  • Hands-on experience with common security technologies such as IDS, firewall, SIEM, SOAR, and EDR.
  • Incident handling and response experience.
  • Knowledge of common security analysis tools and techniques, security threats, attack vectors, vulnerabilities, and exploits.
  • Knowledge of regular expressions.
  • Bachelor’s degree in Computer Science, Information Security, or related/equivalent experience.
  • One or more certifications preferred, such as CISSP, GCIA, GCIH, GPYC, GMON, GCDA, or Elastic Certified Engineer.

Benefits

  • $100,000 - $130,000 annual OTE, including base salary and target bonus.
  • Medical, dental, and vision insurance.
  • 401(k) plan.
  • Paid company holidays.
  • Paid time off.
  • Paid parental and caregiver leave.
  • Cross-department training and development opportunities.
  • Sponsorship for certifications and credentials for continued learning.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps Engineer

INflow Federal 51-250 Aerospace & Defense

INflow Federal is seeking a fully remote DevSecOps Engineer to support an enterprise case management solution for Department of Defense mission partners by securing and automating cloud-based CI/CD and infrastructure operations in AWS GovCloud.

Agile AWS Bash CI/CD CloudFormation Docker ELK Stack Git GitLab CI Helm Jenkins Kubernetes PowerShell Prometheus Python Terraform
1 hour, 56 minutes ago

Lead Security Engineer, Enterprise Security

Klaviyo 1K-5K IT Services

Klaviyo is hiring a Lead Security Engineer to secure its corporate systems and platforms across SaaS, identity, endpoints, Zero Trust networking, and perimeter security.

AWS Azure Cloudflare CrowdStrike GCP OAuth Secrets Management Terraform Vercel
2 hours, 37 minutes ago

Senior Detection and Response Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Senior Detection and Response Engineer to build and operate defensive security controls that protect the infrastructure supporting its defense technology products.

AWS Azure CI/CD CloudFormation Docker GitHub Go Kubernetes Network Security Python Rust SQL Terraform
4 hours, 17 minutes ago

Lead Security Engineer, Enterprise Security

Klaviyo 1K-5K IT Services

Klaviyo is hiring a Lead Security Engineer to secure its corporate systems and platforms across SaaS, identity, endpoints, Zero Trust networking, and perimeter defenses in a hands-on technical leadership role.

AWS Azure Cloudflare CrowdStrike GCP OAuth OpenID Connect Secrets Management Terraform Vercel
4 hours, 50 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers