security engineer in cloud environments

HireHi

United States

Remote

USD 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cision ищет специалиста по кибербезопасности для мониторинга инцидентов и анализа логов в облаке и локальных средах. Вы будете писать скрипты для автоматизации задач, поддерживать аудит и соответствие требованиям, и работать с командами для устранения рисков.

Требуется 3–5 лет опыта в SOC/IR, сильные навыки скриптинга (Python, Bash, PowerShell), знание SIEM (Splunk/Chronicle/Sentinel) и базовые знания AD. Возможен гибридный формат работы.

Qualifications

  • Опыт работы в центрах оперативной кибербезопасности.
  • Опыт работы с облачными концепциями безопасности, IAM и логами.
  • Навыки скриптов: Python, Bash или PowerShell.
  • Знание SIEM: Splunk, Chronicle, Sentinel или аналогичные.
  • Умение читать логи и документировать инциденты.

Responsibilities

  • Мониторинг и расследование инцидентов безопасности в облаке и локальных средах.
  • Анализ логов из AWS, GCP, AD, Linux и Windows, сбор доказательств.
  • Поддержка реагирования на инциденты: сбор данных, документирование выводов.
  • Написание скриптов для автоматизации повторяющихся задач и анализа логов.
  • Участие в проверках безопасности по IAM, доступу и конфигурациям.

Skills

Scripting
Cloud security
SIEM
Linux/Windows
AD basics
Log analysis
Communication
Incident response

Tools

Splunk
Chronicle
Sentinel
GitHub/GitLab

Job description

Описание: Cision provides PR, marketing, and social media management technology and intelligence that helps brands and organizations identify, connect with, and engage customers and stakeholders. Its solutions include PR Newswire, monitoring and analytics services, and the Brandwatch and Falcon.io social media platforms.

Задачи:
  • Monitor and investigate security alerts across cloud, identity, endpoint, and network environments
  • Review logs and activity from AWS, GCP, Active Directory, Linux and Windows systems, and security tools
  • Support incident response by gathering evidence, validating suspicious activity, and documenting findings
  • Write scripts to automate repetitive security tasks, log analysis, reporting, and enrichment
  • Assist with security reviews covering IAM, storage exposure, compute workloads, and network configurations
  • Investigate authentication activity, user behavior, privilege changes, and potential account compromise
  • Work with internal teams to understand systems, identify risks, and support remediation, compliance, and audit activities
  • Be available for after-hours incident response when urgent security events require investigation or support
Требования:
  • Experience with cloud security concepts, services, logs, and IAM
  • Strong scripting ability, preferably with Python, Bash, or PowerShell
  • Experience with SIEM platforms such as Splunk, Chronicle, Sentinel, or similar tools
  • Working knowledge of Linux and Windows systems, command-line usage, permissions, processes, and logs
  • Basic to intermediate understanding of Active Directory, including users, groups, authentication, and privilege changes
  • Ability to read and interpret logs from cloud platforms, operating systems, and security tools
  • Understanding of common security concepts, including phishing, credential compromise, privilege escalation, lateral movement, and exposed services
  • Strong analytical, documentation, and communication skills
  • 3-5 Years of experience in security operations, incident response, systems administration, cloud operations, or a similar technical role
  • Hands-on experience using scripts to solve operational or security problems
  • Comfortable working in cloud and Linux command-line environments
  • Будет плюсом: Google Cloud Platform security experience, including IAM, Cloud Logging, Compute Engine, Cloud Storage, VPCs, and service accounts; exposure to Kubernetes, containers, or cloud-native workloads; experience creating automation for security monitoring or response; experience with Github/Gitlab
Условия:

Candidates must be available for after-hours incident response when urgent security events require investigation or support

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer- Incident Response & IAM Automation
Cloud Security Engineer- Incident Response & IAM Automation

HireHi • United States

Remote
USD 90,000 - 130,000
security engineer for external vulnerability operations
security engineer for external vulnerability operations

HireHi • United States

Remote
USD 93,000 - 159,000
Cloud Security Engineer
Cloud Security Engineer

Fabergent • Miami (FL)

On-site
USD 100,000 - 130,000
security engineer for financial and payment data
security engineer for financial and payment data

HireHi • United States

Hybrid
USD 110,000 - 150,000
Relocation support to company hubs
Flexible work from offices or remote
Healthcare coverage
+3
devops engineer for hybrid infrastructure
devops engineer for hybrid infrastructure

HireHi • United States

Remote
USD 120,000 - 160,000
AWS/GCP stack
Microsoft 365 stack
cloud engineer in energy
cloud engineer in energy

HireHi • Germany (OH)

Hybrid
EUR 70,000 - 110,000
Competitive remuneration
International work environment
Professional development opportunities
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
security engineer for enterprise AI services
security engineer for enterprise AI services

HireHi • United States

Remote
USD 140,000 - 190,000
devsecops engineer
devsecops engineer

HireHi • United States

On-site
USD 140,000 - 180,000
Cloud Security Engineer
Cloud Security Engineer

ALLTECH CONSULTING SVC INC • Alpharetta (GA)

On-site
USD 120,000 - 150,000