
Security Operations Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States, +3 more states.
• Develop, configure, integrate, and optimize enterprise security tools across both cloud and on-premises environments.
• Create and sustain SIEM/SOAR detection content, correlation rules, and automate response processes.
• Onboard and validate log sources along with telemetry feeds.
• Manage and fine-tune endpoint detection and response tools.
• Connect security tools with related platforms via APIs.
• Enforce security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.
• Create security automation and infrastructure-as-code solutions using Terraform or a similar framework.
• Apply policy-as-code and proactive cloud guardrails.
• Assist in cloud security posture management, including deduplication of findings, theme mapping, and owner routing.
• Strengthen compute, storage, database, container, and serverless cloud resources.
• Set up Microsoft 365 and Entra ID security controls, such as conditional access, identity protection, and Defender workloads.
• Enforce least-privilege access models within cloud identity systems.
• Establish security controls for containers and Kubernetes.
• Uphold secrets management practices and eliminate hard-coded credentials.
• Operate vulnerability management tools and prioritize findings routed to owners.
• Offer remediation guidance and implement fixes for security-related tools and configurations.
• Assist in tracking remediation efforts for penetration tests and vulnerability assessments.
• Contribute to incident detection and response through technical investigations, including log, endpoint, identity, authentication, and cloud audit analysis.
• Provide support for escalations from external managed security partners.
• Fine-tune detections and alerts to minimize noise and enhance monitoring signals.
• Take part in post-incident reviews and implement improvements for controls and detections.
• Engage in tabletop exercises and resilience testing.
• Document changes to security controls, validation criteria, and rollback strategies.
• Produce runbooks, playbooks, and technical operating procedures.
• Write clear, well-documented, and reviewable code and configurations.
• Assist in audits, certifications, and customer assurance activities with technical evidence.
• Manage security tools, control coverage, licensing, and operating-status inventories.
• Ensure confidentiality of security testing, control configurations, and investigative materials.
• Minimum of 4 years of practical experience in security operations, security engineering, or a similar technical security role.
• Bachelor's degree in information technology, computer science, cybersecurity, or a related discipline, or equivalent professional experience.
• At least 2 years of hands-on experience in cloud security across at least one major cloud provider.
• Over 2 years of experience operating and tuning a SIEM platform, focusing on detection content and log sources.
• Minimum of 1 year administering Microsoft 365 and Entra ID security controls in a hybrid directory setup.
• Familiarity with security automation; scripting and infrastructure-as-code experience is essential.
• Knowledge of cloud security posture management and preventive controls.
• Understanding of container and Kubernetes security, including RBAC and image scanning.
• Knowledge of secrets management tools and practices.
• Proven experience with endpoint detection and response tools.
• Familiarity with vulnerability management and prioritizing findings based on risk.
• Scripting skills in Python, PowerShell, or Bash.
• Knowledge of NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2.
• Ability to communicate technical findings effectively to both technical and non-technical audiences.
• Capacity to manage assigned tasks independently and escalate issues as needed.
• Willingness to support incident response outside of standard business hours when necessary.
• Proficiency in Microsoft Office.
• Industry certifications like Security+, CompTIA CySA+, or a cloud provider security certification are preferred.
• Experience in healthcare, medical devices, or another regulated industry is advantageous.
• Experience working with a managed security service provider is a plus.
• Must be legally authorized to work in the United States without current or future sponsorship from DeepHealth.
• Flexible remote work arrangement.
• Option to work from the Somerville office, though not mandatory.
• Up to 10% travel for domestic and international purposes.
• Opportunity to contribute to professional security operations within a regulated healthcare environment.
Zscaler
Stripe
DeepHealth
Get handpicked remote jobs straight to your inbox weekly.