Responsibilities
- Operate and improve SIEM, EDR, cloud, identity, email, and security-monitoring capabilities.
- Develop and tune detection rules, analytics, dashboards, alert routing, and investigation playbooks.
- Investigate security alerts and incidents, including scoping, evidence collection, containment, remediation coordination, recovery tracking, and post-incident improvements.
- Triage, prioritize, assign, track, and verify remediation of vulnerabilities, endpoint-patching issues, and CSPM/CWP findings.
- Partner with Cloud Security on posture-management rules, alert tuning, cloud logging, and recurring misconfiguration analysis.
- Define monitoring and detection requirements for new cloud services, SaaS capabilities, and significant architecture changes.
- Develop detections for risky identity, endpoint, and cloud-administration behavior and support endpoint-hardening efforts.
- Build scripts, integrations, workflows, and playbooks for triage, enrichment, notification, containment, remediation tracking, and reporting.
- Improve telemetry coverage and monitor log-source and connector health across cloud, identity, endpoint, SaaS, and network sources.
- Maintain metrics, runbooks, technical documentation, and operational records covering detection, response, vulnerability, exposure, and remediation performance.
- Assess AI tools, agents, plugins, and MCP integrations for data-access, identity, execution, retention, and supply-chain risks.
- Design and operate AI-security guardrails involving least privilege, read-only connectors, sandboxed execution, network-egress restrictions, and human approval.
- Monitor AI prompts, retrieved content, model outputs, tool calls, agent actions, and administrative changes for injection, data exposure, unsafe code, abnormal behavior, and policy violations.
- Onboard AI audit and runtime telemetry into the SIEM and build detections and playbooks for rogue tools, connector misuse, data exfiltration, and agent compromise.
- Run controlled AI pilots and adversarial tests, measure false positives and user impact, and promote controls from monitoring to blocking based on evidence.
- Provide practical security guidance, mentor analysts and engineers, and translate findings into clear actions, owners, priorities, and deadlines.
Requirements
- At least 5 years of hands-on experience in Security Operations, Security Engineering, Detection Engineering, Incident Response, or a related field.
- Strong experience with SIEM operations, detection engineering, alert triage, investigations, and incident response.
- Practical experience with vulnerability management, endpoint patching and hardening, CSPM/CWP, cloud security posture, or attack-surface analysis.
- Experience with Azure, AWS, or comparable cloud environments; multi-cloud experience is preferred.
- Understanding of identity and access risks, privileged activity, risky sign-ins, cloud administration, and modern AI-security risks.
- Ability to query and analyze security data using KQL, SQL, or an equivalent language.
- Ability to automate with Python, PowerShell, JavaScript, or a comparable language, including API integration.
- Experience with endpoint, email, SaaS, cloud, and identity-security telemetry.
- Strong technical writing and communication skills and the ability to work with distributed, cross-functional teams.
- Experience with Microsoft Sentinel, Microsoft Defender, Log Analytics, SOAR, MITRE ATT&CK, Sigma, YARA, threat hunting, or detection testing is preferred.
- Experience with infrastructure-as-code, containers, or Kubernetes security is preferred.
- Experience securing LLMs, AI agents, MCP or plugin ecosystems, AI-enabled SaaS tools, or AI runtime environments is preferred.
- Experience with endpoint privilege management, privileged access workstations, application control, least-privilege measures, or attack-surface reduction is preferred.
- Experience supporting SOC 2, ISO 27001, NIST, FedRAMP, or similar assurance requirements is preferred.
- Relevant security certifications or equivalent practical experience are preferred.
- Ability to work independently, make sound decisions under pressure, and manage competing priorities.
Benefits
- Hybrid work model where a required location is specified, with up to three days per week in the office and the remaining days remote.
Tech Stack
Categories
About Semperis
For security teams charged with defending hybrid and multi-cloud environments, Semperis ensures the integrity and availability of critical enterprise directory services at every step in the cyber kill chain and cuts recovery time by 90%. Purpose-built for securing hybrid identity environments—including Active Directory, Entra ID, and Okta—Semperis’ AI-powered technology protects over 100 million identities from cyberattacks, data breaches and operational errors. The world’s leading organizations trust Semperis to spot directory vulnerabilities, intercept cyberattacks in progress and quickly recover from ransomware and other data integrity emergencies. Semperis is headquartered in Hoboken, New Jersey, and operates internationally, with its research and development team distributed throughout the United States, Canada and Israel. Semperis hosts the award-winning Hybrid Identity Protection conference and podcast series (www.hipconf.com) and built the community hybrid Active Directory cyber defender tools, Purple Knight (www.semperis.com/purple-knight/) and Forest Druid. The company has received the highest level of industry accolades, recently named to Inc. Magazine’s list of best workplaces for 2024 and ranked the fastest-growing cybersecurity company in America by the Financial Times. Semperis is a Microsoft Enterprise Cloud Alliance and Co-Sell partner and is a member of the Microsoft Intelligent Security Association (MISA).
