Security Operations Engineer
Washington Staffing - Olympia, Washington, United States, 98502
Work at Washington Staffing
Overview
- View job
Overview
B2B SAAS data observability software. Cribl does differently. What does that mean? It means we are a serious company that doesn't take itself too seriously; and we're looking for people who love to get stuff done, and laugh a bit along the way. We're growing rapidly - looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a remote-first company we believe in empowering our employees to do their best work, wherever they are. As the data engine for IT and Security many of the biggest names in the most demanding industries trust Cribl to solve their most pressing data needs. Ready to do the best work of your career? Join the herd and unlock your opportunity. The Security Operations Engineer will be a pivotal member of Cribl's Information Security team, primarily responsible for strengthening our security posture through robust security operations and advanced threat detection. You will lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Chief Information Security Officer. As an active member of our team, you will... Knowledge of, and experience in, working with modern security principles e.g. security data lakes, detections as code, EDR, zero trust networking, and other security tooling, as well as demonstrated experience with incident response and management. Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms. Strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections to TTPs Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash Be the go-to technical subject matter expert on security, compliance, and assurance topics Excellent communication skills and ability to communicate ideas to technical and non-technical audiences Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally If you've got it - we want it... Monitoring security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats Developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security tools) based on threat intelligence, MITRE ATT&CK framework, and identified risks Conducting continuous tuning and optimization of existing detection logic to reduce false positives and improve detection efficacy Responding to issues identified by our Cribl employees Acting as a security incident response lead, including leveraging and improving detection capabilities during investigations Building, enhancing, and managing security playbooks, incorporating detection engineering best practices Conducting security assessments of corporate assets through vulnerability testing, threat hunts, and purple team activities, with a focus on identifying detection gaps and opportunities Performing both internal and external security reviews of corporate properties e.g., the corporate website