Cyber Security Operations Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
The role will work closely with Security Operations Centre (SOC), Infrastructure, Cloud Engineering, DevOps, and Compliance teams to maintain a secure cloud ecosystem and strengthen the organization’s cybersecurity posture., Security Monitoring & Incident Response
- Monitor cloud environments for security threats, suspicious activities, and policy violations.
- Investigate security alerts and incidents generated by SIEM, XDR, and cloud-native security tools.
- Lead incident triage, containment, eradication, and recovery activities.
- Perform root cause analysis and document incident findings and remediation actions.
- Develop and maintain cloud security incident response playbooks.
Cloud Security Operations
- Manage and improve cloud security posture across Azure, AWS, and Google Cloud Platform.
- Identify and remediate cloud misconfigurations, vulnerabilities, and security gaps.
- Monitor compliance with cloud security baselines, policies, and regulatory requirements.
- Conduct cloud security risk assessments and security reviews.
Identity & Access Security
- Monitor privileged access and enforce least-privilege principles.
- Manage and review IAM policies, RBAC roles, MFA, Conditional Access, and Privileged Identity Management (PIM).
- Investigate identity-based threats and unauthorized access attempts.
Threat Hunting & Detection Engineering
- Perform proactive threat hunting across cloud workloads and services.
- Develop detection use cases and custom analytics rules.
- Leverage MITRE ATT&CK framework to enhance detection capabilities.
- Identify emerging cloud threats and recommend security improvements.
Security Automation & Reporting
- Support security automation initiatives using SOAR and scripting.
- Develop dashboards, reports, and security metrics for management review.
- Participate in cloud security governance and operational reviews.
- Recommend process improvements to enhance cloud security operations efficiency.
Cloud security responsibilities
- Understand and use corporate information security frameworks, policies, implementation, and support tools
- Translate and evolve corporate security policies into cloud requirements
- Identify compliance standards, craft policies and controls in support of standards, and implement Policy as Code (e.g. SOC-2 NIST 800-53, ISO 27001)
- Use Policy as Code to enforce pre-deployment compliance on IaC scripts (e.g. static code analysis of TF, Helm)
- Use Policy as Code to implement compliance and configuration monitoring of the running state of cloud environment.
- Use Policy as Code to prevent out of band (bypassing pipeline) misconfiguration via cloud vendor policy engine (Azure, GCO, OCI Policy)
- Evaluate and identify suite of security tooling to be used in partnership with product teams & Information Security for vulnerability scanning, alerting, & reporting (e.g. Azure Monitor, Azure Sentinel (SIEM), Azure Policy (policy enforcement), and Azure Security Center, CGP Security center, OCI cloud guard, CSPM etc)
- Establish security support processes in partnership with product teams and Information.
- Security for vulnerability scanning, alerting, and reporting, leveraging automated incident response and self-service tools, when possible
- Provide resolution support to address security and compliance infrastructure exposures identified through monitoring and alerts.
- Establish preventative procedures to resolve newly identified security exposures prior to impact.
Requirements
Technical Skills
- Strong experience with Microsoft Azure, AWS, or Google Cloud Platform.
-
Hands-on experience with:
- Microsoft Sentinel
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- AWS Security Hub
- CrowdStrike
Knowledge of cloud networking, firewalls, VPNs, WAF, and Zero Trust architecture.
Experience with Identity and Access Management (IAM), SSO, MFA, and RBAC.
Familiarity with Vulnerability Management and CSPM solutions.
Working knowledge of PowerShell, Python, Bash, or KQL.
CSPM, KSPM, SSPM
Security Knowledge
- Security Operations Center (SOC) processes.
- Incident Response and Threat Hunting.
- Security Monitoring and Log Analysis.
- Cloud Security Best Practices.
- MITRE ATT&CK Framework.
- NIST Cybersecurity Framework.
- CIS Benchmarks.
- ISO 27001
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks
Understanding and Mitigating Common Web Vulnerabilities
Best Coding Boot Camps in Germany