Staff Security Operations Engineer

1 month, 2 weeks ago
Full-time
Lead
DevOps and Infrastructure
Cribl

Cribl

Cribl provides a unified data management platform specifically designed for IT and security data, enabling users to explore, collect, process, and access their data at scale while offering enhanced control and flexibility in managing their data workflows.

IT Services
251-1K
Founded 2018
$402M raised

Description

  • Lead security incident management, triage, and investigations, and improve detection capabilities during response efforts.
  • Monitor security events and alerts across security tooling to identify and triage potential threats.
  • Develop, implement, maintain, and tune high-fidelity detection rules and alerts across SIEM and other security platforms.
  • Design and optimize detection logic to identify sophisticated threats and reduce false positives.
  • Act as a security incident response lead and help improve investigation processes and outcomes.
  • Build, enhance, and manage security playbooks using detection engineering best practices.
  • Conduct security assessments through vulnerability testing, threat hunting, and purple team activities to identify detection gaps.
  • Perform internal and external security reviews of corporate properties and enterprise applications.
  • Lead security incident response tabletop exercises.
  • Collaborate with Product Security, IT, Legal, and threat intelligence teams to integrate IOCs, TTPs, and remediation strategies.

Requirements

  • Experience with modern security principles and tooling such as SIEM, security data lakes, detection as code, EDR, zero trust networking, MSSP, and CSPM.
  • Strong understanding of common attack frameworks such as MITRE ATT&CK and how to map detections to TTPs.
  • Knowledge of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM.
  • Experience scripting or coding in at least one language such as Python, NodeJS, Ruby, or Bash.
  • Demonstrated experience with incident response and management.
  • Ability to communicate effectively with both technical and non-technical audiences.
  • Comfort working in ambiguity, with strong analytical skills and the ability to work cross-functionally.
  • Willingness to occasionally work outside standard hours to support a global, remote-first team.
  • Experience with SIEM platforms like Panther and their detection capabilities is a plus.
  • Familiarity with Wiz and cloud-native security tooling in AWS, Azure, or GCP is a plus.
  • Relevant cloud security or incident response certifications, such as SANS GIAC certifications, are preferred.
  • Proven experience developing, deploying, and maintaining detection rules such as Sigma, YARA, Splunk SPL, or KQL.

Benefits

  • Base salary range of $128,000 to $200,000 USD, depending on location and experience.
  • Eligibility for the Cribl Corporate Bonus Program for non-sales roles.
  • Comprehensive health, dental, vision, short-term disability, and life insurance coverage.
  • Paid holidays and paid time off.
  • Fertility treatment benefit.
  • 401(k) retirement plan.
  • Equity in the company.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Customer Support Engineer - Endpoint/MTD (Device) & Cybersecurity

Zimperium 251-1K Professional Services

Zimperium is hiring a Customer Support Engineer to provide technical support for its mobile security platform, helping enterprise customers troubleshoot issues and resolve product problems in coordination with internal teams.

Android Android Studio AWS Cybersecurity Docker iOS Java JIRA JUnit Kafka Linux Machine Learning PostgreSQL Python SIEM Splunk SQL Unix Xcode
1 day, 13 hours ago

Director , Information Security and IT

Luna Physical Therapy 251-1K Health Care Providers & Services

Luna is hiring a Director of Information Security & IT to lead enterprise technology and security programs supporting secure operations and patient care in a HIPAA-regulated environment.

AWS Azure GCP HIPAA Penetration Testing
1 day, 13 hours ago

Senior MS Intune & Cloud Security Specialist (Freelance)

Coderio 51-250 Internet Software & Services

Coderio is seeking a Senior Cloud Security Architect / MS Intune Specialist to lead a greenfield Microsoft Intune, Entra ID, and Defender for Endpoint implementation for a multi-cloud environment spanning Google Workspace, AWS, and DevOps pipelines.

Active Directory Android AWS Bash GitHub GitLab iOS macOS PowerShell
1 day, 13 hours ago

Senior Security Engineer

Hummingbird 1K-5K Professional Services

Hummingbird is hiring a Senior Security Engineer to own and strengthen security for its remote-first SaaS platform that helps financial institutions fight financial crime.

AWS Azure CircleCI Docker Encryption GraphQL JavaScript Network Security PostgreSQL Python React Redis Ruby Ruby on Rails Terraform TypeScript
3 days, 12 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers