> Markdown version of [/jobs/ext/2646866-associate-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2646866-associate-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Security Operations Engineer - **Company:** Conference of State Bank Supervisors - **Location:** Washington, DC, United States - **Experience:** Starter - **Salary:** $78,971.0 - $96,520.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Linux, Domain Name System (DNS), Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Log Analysis, Windows PowerShell, Phishing, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Data Logging, Scripting, Cloud Platform System, Okta, System Availability, Malware, Cyber Threat Analysis, Information Technology, Network Support, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17911442?backUrl=%2Fcareer%2F17911442%2FAssociate-Security-Operations-Engineer-D-C-Washington ## About the Role To perform this job successfully, an individual should possess the knowledge, skills, and abilities listed and meet the amount of education, training and/or work experience required. Education and Experience * B.S. degree in Computer Science or equivalent experience. * Microsoft and Security Certifications are highly desired. * 1-2 years of experience in cybersecurity, IT operations, system administration, or network support. * Demonstrated experience in security monitoring, log analysis, or incident response processes is preferred. * Experience working in cloud environments including AWS is a plus. * Basic scripting or automation experience (e.g., Python, PowerShell) to automate routine functions is a plus. Knowledge, Skills and Abilities * Knowledge of security tools and platforms (e.g., SIEM, EDR, IAM, and network security controls), with familiarity using tools such as CrowdStrike and Okta is a plus. * Knowledge of Cloud platforms and operations. * Familiarity with the NIST Cyber Security Framework. * Foundational understanding of cybersecurity principles, including threat detection, incident response, and vulnerability management. * Familiarity with common attack vectors and threats such as phishing, malware, and credential compromise. * Basic knowledge of IT infrastructure, including networking (TCP/IP, DNS), operating systems (Windows/Linux), and cloud environments. * Understanding of logging, monitoring, and alerting concepts used in security operations. * Analytical and problem-solving skills with the ability to investigate alerts and identify potential security concerns. * Ability to triage and prioritize security events based on risk, severity, and business impact. * Strong attention to detail when reviewing logs, alerts, and system activity. * Ability to follow established processes, playbooks, and standard operating procedures. * Effective written and verbal communication skills for documenting incidents, escalating issues, and collaborating with team members. * Basic technical troubleshooting skills across systems, endpoints, and network components. * Ability to think critically and distinguish between false positives and legitimate security threats. * Ability to collaborate with cross-functional teams, including IT, security, and business stakeholders. * Ability to recognize when to escalate issues and seek guidance appropriately. * Willingness to continuously learn and adapt to new technologies, tools, and evolving cybersecurity threats. * Working knowledge of system and network security engineering best practices, operating systems and application auditing. * Strong written and verbal communication skills. * Strong planning and task management skills. ## Description The Associate Security Operations Engineer supports CSBS's security operations by monitoring security tools, triaging alerts, and assisting with incident response and cyber threat hunting activities. This role works under the guidance of senior security staff to help detect, analyze, and respond to potential security events across the enterprise environment. The Associate Security Operations Engineer contributes to maintaining the confidentiality, integrity, and availability of systems by supporting security monitoring platforms, following established playbooks, and escalating issues as appropriate., To perform this job successfully, an individual must be able to perform each essential duty and responsibility satisfactorily. Reasonable accommodations may be made to enable individual with disabilities to perform the essential functions. Other duties may be assigned to meet business needs. * Monitor and support enterprise security tools, including SIEM, EDR, identity platforms, and cloud security solutions, to detect potential threats and anomalous activity. * Review, triage, and escalate security alerts in accordance with established procedures and playbooks. * Assist in incident response activities, including investigation, containment, documentation, and post-incident analysis. * Support cyber threat hunting efforts by analyzing logs, endpoint data, and system activity to identify indicators of compromise or suspicious behavior. * Support proactive cyber threat hunting and detection engineering efforts to improve overall security posture. * Assist with the collection and analysis of security event data from multiple sources (endpoints, network, identity, cloud platforms). * Help maintain and tune detection rules, alerts, and monitoring configurations to improve visibility and reduce false positives. * Document incidents, findings, and response actions in ticketing and case management systems. * Collaborate with senior engineers and cross-functional teams to support remediation and recovery efforts. * Support vulnerability management activities by tracking findings and assisting with remediation follow-up. * Assist in maintaining and updating security operations playbooks, runbooks, and standard operating procedures. * Participate in continuous monitoring and operational readiness activities. * Stay current on emerging threats, attacker techniques, and security best practices. Additional Responsibilities * Monitor industry trends for changes in compliance challenges and contribute to organization planning, policy and procedure changes in response. * Assist in the development and refinement of security detection use cases aligned to threat intelligence and organizational risk. * Support audit, compliance, and regulatory activities (e.g., NIST CSF, SOC 2, CJIS) by gathering evidence, logs, and documentation. * Help validate security controls through participation in internal assessments, tabletop exercises, and incident simulations. * Contribute to continuous improvement of SOC processes, including alert triage workflows and escalation procedures. * Assist in integrating and onboarding new security tools and log sources into monitoring platforms. * Support metrics and reporting efforts, including tracking incident trends, response times, and tool effectiveness. * Participate in knowledge sharing and team training activities to build security operations maturity. * Maintain awareness of evolving threat landscape, including common attacker tactics, techniques, and procedures (TTPs). ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)