Cribl

Staff Security Operations Engineer

Cribl
Apply
21 days ago
Remote, United StatesStaff+
H1B Sponsor

Base Salary

$128k - $200k/yr

Responsibilities

  • Monitor security events and alerts using MSSP, SIEM, AI, and CSPM tooling to identify and triage potential threats.
  • Develop, implement, maintain, tune, and optimize high-fidelity detection rules and alerts across SIEM, EDR, and cloud security platforms.
  • Lead security incident response, investigations, and management while improving detection capabilities during incidents.
  • Build, enhance, and manage security playbooks using detection engineering best practices.
  • Conduct vulnerability testing, threat hunts, purple team activities, and internal and external security reviews to identify detection gaps.
  • Lead security incident response tabletop exercises.
  • Integrate indicators of compromise and attacker tactics, techniques, and procedures into detection strategies with threat intelligence teams.
  • Champion the use of Cribl products in the security technology stack to improve detection, analysis, and response.
  • Serve as a technical subject matter expert on security, compliance, and assurance topics.
  • Collaborate with Product Security, IT, Legal, and other cross-functional teams.

Requirements

  • Demonstrated experience with security operations, incident response, incident management, and modern security principles including SIEM, security data lakes, detection as code, EDR, and zero-trust networking.
  • Strong understanding of attack frameworks such as MITRE ATT&CK and mapping detections to attacker tactics, techniques, and procedures.
  • Understanding of authentication and authorization schemes including SAML, OpenID, OAuth2, and SCIM.
  • Scripting or coding experience in at least one of Python, NodeJS, Ruby, or Bash.
  • Proven experience developing, deploying, and maintaining detection rules using technologies such as Sigma, YARA, Splunk SPL, or KQL.
  • Familiarity with SIEM, EDR, cloud security, CSPM, MSSP, and other security tooling.
  • Familiarity with Panther and Wiz is a plus.
  • Familiarity with cloud-native security detection in AWS, Azure, or GCP.
  • Relevant cloud security or incident response certifications, such as SANS GIAC certifications, are valued.
  • Ability to communicate with technical and non-technical audiences and work effectively across functions.

Benefits

  • Remote-first work environment with occasional duties outside standard working hours across time zones.
  • Health, dental, vision, short-term disability, and life insurance.
  • Paid holidays and paid time off.
  • Fertility treatment benefit.
  • 401(k) and equity.
  • Eligibility for the Cribl Corporate Bonus Program for non-sales roles.

Tech Stack

Categories

Cribl

About Cribl

1,001-5,000 employees

Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents. Trusted by organizations worldwide, including half of the Fortune 100, Cribl bridges the gap between AI ambition and infrastructure reality. No lock-in. No data loss. No compromises. Cribl’s vendor-agnostic platform ensures data remains portable and interoperable. By cost-effectively handling increasing data volume and variety without delay, Cribl gives enterprises the choice, control, and flexibility to build what’s next.

Contact me