
Cybersecurity Operations Engineer
Posted Aug 31

Posted Aug 31
This is a fully remote position, open to applicants in Colorado.
• Manage, oversee, and enhance cybersecurity measures that safeguard a mission-critical SaaS product.
• Conduct daily security operations and engineering for the assigned SaaS product and its associated AWS environment.
• Implement security controls, perform continuous monitoring, conduct control testing, gather audit evidence, execute corrective actions, and maintain authorization activities.
• Identify gaps in controls, configuration issues, and emerging technical risks; address or escalate concerns appropriately.
• Utilize endpoint detection and response, centralized security logging and analytics, vulnerability scanning and management, along with related cloud security capabilities.
• Keep asset inventories, security telemetry, agents, sensors, log sources, dashboards, integrations, and operational reports up to date.
• Carry out vulnerability scans, prioritize risks, coordinate remediation efforts, track exceptions, and confirm corrective actions.
• Monitor alerts and telemetry, triage events, manage cases, and investigate activities across identity, endpoint, network, application, and cloud platforms.
• Develop, test, and refine detection mechanisms, correlation logic, and investigative queries.
• Support or execute incident response tasks, including scoping, preserving evidence, containment, eradication, recovery, root-cause analysis, and tracking corrective actions.
• Implement incident response playbooks, escalation procedures, notification protocols, exercises, and post-incident evaluations.
• Maintain thorough records of investigations, incident timelines, evidence, decisions, and necessary reports; be available for after-hours response when needed.
• Enhance runbooks, operational procedures, quality standards, service metrics, shift handoffs, and escalation protocols.
• Carry out operational tasks for the enterprise data protection program, including discovery, classification, access, encryption, monitoring, retention, and secure disposal controls.
• Investigate suspected data breaches, misuse, or policy violations while maintaining data protection workflows and metrics.
• Leverage AI-assisted analysis, scripting, APIs, query languages, and workflow orchestration to automate and enhance security processes.
• Collaborate with Product, Engineering, Cloud, Compliance, Privacy, Legal, and business teams on architecture, release processes, remediation efforts, risk assessments, and customer assurance.
• Assist with additional cybersecurity projects and operational tasks as assigned.
• In-depth knowledge of security operations and engineering for cloud-based SaaS products.
• Familiarity with AWS environments and the shared-responsibility model of the cloud.
• Practical understanding of FedRAMP continuous monitoring, NIST SP 800-53 security controls, and the CJIS Security Policy.
• Proven ability to operate endpoint detection and response systems, centralized logging, security analytics, vulnerability management, and cloud security monitoring capabilities.
• Strong grasp of AWS identity, networking, compute, storage, logging, encryption, key management, and security-related configuration practices.
• Capability to maintain reliable security telemetry pipelines.
• Proficient in writing and modifying investigative queries, detections, and correlation logic.
• Solid incident response skills.
• Knowledge of vulnerability management techniques.
• Familiarity with enterprise data protection practices.
• Experience utilizing scripting, APIs, query languages, and workflow automation.
• Ability to responsibly utilize AI-enhanced capabilities.
• Competence in maintaining operational metrics, runbooks, case records, evidence, and technical documentation.
• Strong analytical, troubleshooting, and decision-making capabilities.
• Ability to convert cybersecurity and compliance requirements into actionable technical measures.
• Excellent collaboration and communication skills.
• Capacity to manage multiple priorities independently and recognize when escalation is necessary.
• Minimum of 3 years' experience in cybersecurity engineering, security operations, cloud security, incident response, or related fields.
• Demonstrated hands-on experience managing security monitoring, endpoint protection, vulnerability management, and incident response capabilities within an AWS-hosted production cloud or SaaS environment.
• Experience in triaging and investigating security incidents and supporting them through containment, recovery, and lessons learned.
• Knowledge of cloud and application logs, security analytics, detection queries, case management, and vulnerability remediation workflows.
• Must reside in the United States.
• Must be able to obtain and maintain the personnel screening and access authorization required for CJIS-regulated environments.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
• Experience in a FedRAMP-authorized, CJIS-regulated, or similarly controlled environment is highly preferred.
• Experience in supporting operational data protection activities and applying automation or AI-assisted capabilities is preferred.
• Relevant certifications in cybersecurity, cloud security, incident response, or security operations are preferred.
• Flexible Time Off
• Company-Wide Wellbeing Days
• Work From Home Reimbursement
• Multiple Health Plan Options, including a 100% employer-paid plan
• Employer HSA Contributions when enrolled in a High-Deductible Health Plan
• Fitness Reimbursement Program
• On-Demand Mental Health Support, including Headspace and other wellness tools
• Paid Parental Leave for birthing and non-birthing parents
• Traditional & Roth 401(k) with a generous company match
• 100% employer-paid Life & AD&D Insurance
• Online Learning Platforms
• Competitive Salary & Bonuses
VMD Corp
GR8 Tech
Modern Health
Accumulus Technologies
Get handpicked remote jobs straight to your inbox weekly.