Security Operations Lead
EarnestFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Candidates should have experience with modern security principles such as security data lakes, detections as code, EDR, zero trust networking, and other security tooling, along with demonstrated experience in incident response and management. Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms is required. A strong understanding of common attack frameworks like MITRE ATT&CK and authentication/authorization schemes such as SAML, OpenID, OAuth2, and SCIM is necessary. Experience scripting/coding in Python, NodeJS, Ruby, or Bash is also required. Excellent communication skills and the ability to work cross-functionally are essential.
The Senior Security Operations Engineer will monitor security events and alerts using security tooling including MSSP, SIEM, AI, and CSPM tools to identify and triage potential threats. Responsibilities include developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms based on threat intelligence, the MITRE ATT&CK framework, and identified risks. The role involves conducting continuous tuning and optimization of existing detection logic, responding to issues identified by employees, and acting as a security incident response lead. Building, enhancing, and managing security playbooks, conducting security assessments through vulnerability testing and threat hunts, and performing security reviews of corporate properties are also key duties. The engineer will lead security incident response tabletop exercises, evolve and champion the use of Cribl products in the security tech stack, and collaborate with threat intelligence teams to integrate new indicators of compromise into detection strategies.
Data observability solutions for tech businesses
Cribl operates in the data observability market, helping tech businesses monitor, analyze, and visualize their data for better operational and security insights. The company offers two main products: Cribl Stream and Cribl Edge. Cribl Stream enables businesses to efficiently route and transform logs and metrics, either on their own infrastructure or through cloud services, ensuring timely data delivery. Cribl Edge focuses on collecting and processing real-time observability data from edge devices, which can then be sent to Cribl Stream or other destinations. Cribl distinguishes itself by integrating seamlessly with platforms like Office 365 and Microsoft Azure, allowing clients to enhance their data management capabilities. The company's goal is to create effective data ecosystems that empower organizations to make sense of their data.