Tech Stack
AWSDNSDockerKubernetesPython
About the role
- Lead and execute security operations and incident response activities
- Perform AWS security operations including CloudTrail analysis, security monitoring, threat hunting
- Operate and administer SIEM and security investigative tools; analyze logs and alerts
- Build and manage vulnerability management programs, SLAs, and processes
- Develop and deploy security tooling (IDS, web filtering, DNS security, SIEM) and automation scripts
- Collaborate with teams to elevate security posture and act as technical security leader
Requirements
- 5+ years security operations experience - hands-on tool operation and incident response
- Expert AWS security operations - CloudTrail analysis, security monitoring, threat hunting
- Proven incident response leadership - owning complete IR process and investigations
- SIEM operation experience - log analysis, alert investigation, threat detection
- Security tool administration - operating security platforms and investigative tools
- Vulnerability management experience - building programs, SLA tracking, process creation
- Preferred: Security tool building experience (IDS, web filtering, DNS security, SIEM deployment)
- Preferred: Security certifications (GCIH, GCFA, CISSP, AWS Security Specialty)
- Preferred: Compliance frameworks experience (GDPR and SOC2)
- Preferred: Container security operations (Docker, Kubernetes security monitoring)
- Preferred: Scripting for automation (Python, Bash)
- Preferred: Experience with Vanta or similar GRC platforms