> Markdown version of [/jobs/ext/2694288-staff-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2694288-staff-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Operations Engineer - **Company:** Cribl, Inc. - **Location:** Lansing, MI, United States (Remote available) - **Salary:** $128,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Bash Shell, Cyber Security, Python (Programming Language), Node.Js, OAuth, OpenID, Ruby, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Security, Mitre Att&ck, Data Lakes - **Published:** September 3, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/405776071 ## About the Role to TTPs * Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM * Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash * Be the go-to technical subject matter expert on security, compliance, and assurance topics * Communicate ideas to technical and non-technical audiences * Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally * We are a remote-first company and work happens across many time-zones - you may be required to occasionally perform duties outside your standard working hours If You've Got It - We Want It * Monitoring security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats * Developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security ## Description our security posture through robust security operations and advanced threat detection. You will help lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Sr. Director, Security Engineering and Operations under the CISO. As An Active Member Of Our Team, You Will... * Provide knowledge and experience in working with modern security principles e.g. SIEM, security data lakes, detection as code, EDR, zero trust networking, and other security tooling, as well as demonstrated experience with incident response and management. * Utilize a strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)