Tech Stack
AWSDNSDockerKubernetesPython
About the role
- Serve as technical leader and go-to expert on security operations and engineering
- Lead and own incident response process and investigations end-to-end
- Perform AWS security operations including CloudTrail analysis, security monitoring, and threat hunting
- Operate and manage SIEM: log analysis, alert investigation, threat detection
- Administer and operate security platforms and investigative tools; build and maintain security tools
- Design and run vulnerability management programs including SLA tracking and process creation
- Implement and monitor container security for Docker and Kubernetes
- Automate security tasks via scripting (Python, Bash) and integrate with GRC platforms like Vanta
- Collaborate with engineering teams to ship secure, high-quality code and elevate the codebase
- Work remotely aligned with EST or PT time zones
Requirements
- 5+ years security operations experience - hands-on tool operation and incident response
- Expert AWS security operations - CloudTrail analysis, security monitoring, threat hunting
- Proven incident response leadership - owning complete IR process and investigations
- SIEM operation experience - log analysis, alert investigation, threat detection
- Security tool administration - operating security platforms and investigative tools
- Vulnerability management experience - building programs, SLA tracking, process creation
- Security tool building experience: IDS, web filtering, DNS security, SIEM deployment
- Security certifications (GCIH, GCFA, CISSP, AWS Security Specialty)
- Compliance frameworks - GDPR and SOC2
- Container security operations (Docker, Kubernetes security monitoring)
- Scripting for automation (Python, Bash)
- Experience with Vanta or similar GRC platforms
- Bachelor's degree in IT/Computer Science or equivalent experience (application queries)