
Security Operations Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States, +3 more states.
• Design, configure, integrate, and optimize the enterprise security toolset across both cloud and on-premises environments.
• Create and maintain SIEM detection content, correlation rules, and automate SOAR responses.
• Integrate log sources and telemetry feeds while ensuring ingestion, parsing, and field normalization are validated.
• Manage and optimize endpoint detection and response tools, including policy configurations, exclusion governance, and coverage assessments.
• Connect security tools with related platforms via APIs.
• Enforce security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.
• Develop and sustain security automation and infrastructure-as-code using Terraform or similar frameworks.
• Implement policy-as-code and preventive guardrails.
• Assist with cloud security posture management, which includes finding deduplication, theme mapping, and routing to responsible teams.
• Fortify compute, storage, database, container, and serverless cloud resources against defined benchmarks.
• Configure and manage security controls for Microsoft 365 and Entra ID, including conditional access, identity protection, and Defender workloads.
• Apply least-privilege access models, roles, and policies across cloud identity systems.
• Establish security controls for containers and Kubernetes, including RBAC, workload security standards, image scanning, and runtime protection.
• Manage secrets effectively and eliminate hard-coded credentials.
• Operate vulnerability management tools and translate scanner outputs into prioritized, owner-assigned findings.
• Provide remediation guidance and implement fixes for security-related tools and configurations.
• Aid in tracking remediation from penetration tests and vulnerability assessments.
• Contribute to incident detection and response by analyzing logs, examining endpoints, tracing identity and authentication, and reviewing cloud audit logs.
• Support escalations from external managed security partners.
• Fine-tune alerts and participate in post-incident reviews, tabletop exercises, and resilience testing.
• Document changes in security controls, validation criteria, and rollback strategies.
• Produce runbooks, playbooks, technical procedures, code, and configuration documentation.
• Assist with audits, certifications, and customer assurance activities by providing technical evidence.
• Maintain an inventory of security tools, control coverage, licensing status, and operational health.
• Ensure the confidentiality of security testing results, control configurations, and investigative materials.
• Report to the Director of Security Operations, with future reporting to the Manager of Security Operations.
• Over 4 years of practical experience in security operations, security engineering, or a similar technical security role.
• Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience.
• More than 2 years of hands-on cloud security experience with at least one major cloud provider; preference for Google Cloud Platform and Amazon Web Services.
• Over 2 years of experience operating and tuning a SIEM platform, including detection content and log sources.
• At least 1 year of experience administering Microsoft 365 and Entra ID security controls in a hybrid directory environment.
• Solid understanding of security automation; experience with scripting and infrastructure-as-code is essential.
• Knowledge of cloud security posture management and preventive controls.
• Familiarity with container and Kubernetes security, including role-based access control and image scanning.
• Understanding of secrets management tools and practices.
• Practical experience with endpoint detection and response tools.
• Familiarity with vulnerability management and risk-based finding prioritization.
• Proficiency in scripting with Python, PowerShell, or Bash.
• Understanding of the NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2.
• Ability to clearly communicate technical findings to both technical and non-technical audiences.
• Capability to manage assigned work independently and escalate issues appropriately.
• Availability to support incident response outside of standard business hours as necessary.
• Experience with Microsoft Office.
• Must be legally authorized to work in the United States without current or future sponsorship from DeepHealth.
• Industry certifications such as Security+, CompTIA CySA+, or a cloud provider security certification are preferred.
• Experience in healthcare, medical devices, or other regulated industries and knowledge of HIPAA obligations is preferred.
• Experience collaborating with or integrating with a managed security service provider is preferred.
• Flexible remote work arrangement.
• Option to work from the Somerville office, though not mandatory.
• Up to 10% travel required for domestic and international purposes.
• Opportunity to collaborate with global teams and security environments.
• Professional development through hands-on experience in cloud security, automation, compliance, and regulated healthcare environments.
Zscaler
Stripe
DeepHealth
Get handpicked remote jobs straight to your inbox weekly.