Remotery

Security Operations Engineer

Posted 11 hours ago

This is a fully remote position, open to applicants in United States, +3 more states.

📋 Description

• Develop, configure, integrate, and optimize enterprise security tools across both cloud and on-premises environments.

• Create and sustain SIEM/SOAR detection content, correlation rules, and automate response processes.

• Onboard and validate log sources along with telemetry feeds.

• Manage and fine-tune endpoint detection and response tools.

• Connect security tools with related platforms via APIs.

• Enforce security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.

• Create security automation and infrastructure-as-code solutions using Terraform or a similar framework.

• Apply policy-as-code and proactive cloud guardrails.

• Assist in cloud security posture management, including deduplication of findings, theme mapping, and owner routing.

• Strengthen compute, storage, database, container, and serverless cloud resources.

• Set up Microsoft 365 and Entra ID security controls, such as conditional access, identity protection, and Defender workloads.

• Enforce least-privilege access models within cloud identity systems.

• Establish security controls for containers and Kubernetes.

• Uphold secrets management practices and eliminate hard-coded credentials.

• Operate vulnerability management tools and prioritize findings routed to owners.

• Offer remediation guidance and implement fixes for security-related tools and configurations.

• Assist in tracking remediation efforts for penetration tests and vulnerability assessments.

• Contribute to incident detection and response through technical investigations, including log, endpoint, identity, authentication, and cloud audit analysis.

• Provide support for escalations from external managed security partners.

• Fine-tune detections and alerts to minimize noise and enhance monitoring signals.

• Take part in post-incident reviews and implement improvements for controls and detections.

• Engage in tabletop exercises and resilience testing.

• Document changes to security controls, validation criteria, and rollback strategies.

• Produce runbooks, playbooks, and technical operating procedures.

• Write clear, well-documented, and reviewable code and configurations.

• Assist in audits, certifications, and customer assurance activities with technical evidence.

• Manage security tools, control coverage, licensing, and operating-status inventories.

• Ensure confidentiality of security testing, control configurations, and investigative materials.


⛳️ Requirements

• Minimum of 4 years of practical experience in security operations, security engineering, or a similar technical security role.

• Bachelor's degree in information technology, computer science, cybersecurity, or a related discipline, or equivalent professional experience.

• At least 2 years of hands-on experience in cloud security across at least one major cloud provider.

• Over 2 years of experience operating and tuning a SIEM platform, focusing on detection content and log sources.

• Minimum of 1 year administering Microsoft 365 and Entra ID security controls in a hybrid directory setup.

• Familiarity with security automation; scripting and infrastructure-as-code experience is essential.

• Knowledge of cloud security posture management and preventive controls.

• Understanding of container and Kubernetes security, including RBAC and image scanning.

• Knowledge of secrets management tools and practices.

• Proven experience with endpoint detection and response tools.

• Familiarity with vulnerability management and prioritizing findings based on risk.

• Scripting skills in Python, PowerShell, or Bash.

• Knowledge of NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2.

• Ability to communicate technical findings effectively to both technical and non-technical audiences.

• Capacity to manage assigned tasks independently and escalate issues as needed.

• Willingness to support incident response outside of standard business hours when necessary.

• Proficiency in Microsoft Office.

• Industry certifications like Security+, CompTIA CySA+, or a cloud provider security certification are preferred.

• Experience in healthcare, medical devices, or another regulated industry is advantageous.

• Experience working with a managed security service provider is a plus.

• Must be legally authorized to work in the United States without current or future sponsorship from DeepHealth.


🏝️ Benefits

• Flexible remote work arrangement.

• Option to work from the Somerville office, though not mandatory.

• Up to 10% travel for domestic and international purposes.

• Opportunity to contribute to professional security operations within a regulated healthcare environment.

People also viewed

Zscaler10 hours ago

Senior IT Security Operations Engineer

US flagCalifornia OnlyFull-timeSecurity Operations$134k – $167.5k/year
ApplyView job
Stripe11 hours ago

Security Incident Response Engineer

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job
DeepHealth11 hours ago

Security Operations Engineer

US flagUnited States, +3 more statesFull-timeSecurity Operations$110 – $120/year
ApplyView job
Mesh16 hours ago

Security Operations Engineer

EuropeFull-timeSecurity Operations
ApplyView job
Zepto1 day ago

Security Operations Analyst

AU flagAustralia OnlyFull-timeSecurity Operations
ApplyView job
Forward Financing1 day ago

Manager, Security Operations

CA flagCanada OnlyFull-timeSecurity OperationsC$172k – C$237k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers