Security Operations Specialist

The University of North Carolina

Charlotte (NC)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The University of North Carolina is looking for a Security Operations Specialist to defend its digital infrastructure and lead AI-enabled improvements to the security toolset.

You will work on proactive threat hunting, automated containment, and reducing alert fatigue while integrating ML models into SOC workflows. A Bachelor’s degree in a computing field and 2+ years of security experience are preferred.

Qualifications

  • Bachelor’s degree or higher in a computing or security field and related experience.
  • 2+ years of relevant work experience or equivalent.
  • Experience in security operations and handling SOC tasks.

Responsibilities

  • Contribute to SIEM monitoring processes for on-premise, cloud, and third-party systems.
  • Review logs and real-time alerts to identify trends and report exceptions.
  • Tune and create analytic detection policies across the IT ecosystem.
  • Improve Security Operations tasks and vulnerability management.
  • Create and maintain dashboards and reports to identify vulnerabilities.
  • Threat Hunting with ML and AI-driven analytics to catch threats.
  • Design and maintain AI-assisted agents to triage alerts and automate responses.
  • Develop policies to optimize Security tools and SOAR systems.
  • Participate in incident response and investigations with SIEM/vulnerability data.

Skills

Coding Experience
LLMs
Security operations
Automation tooling

Education

Bachelor’s degree in computer science, computer engineering, information security, or related field
Equivalent combination of education and relevant work experience
2+ years of relevant work experience

Tools

EDR
XDR
SIEM
Vulnerability Scanning

Job description

Please see Special Instructions for more details.

8:00 am – 5:00 pm; Monday – Friday with occasional evening and weekend hours required, as necessary.


Hours per week 40


FLSA Status


FLSA Status Exempt


Division


Division OneIT


Department


Department Office of OneIT (Adm)


Work Location


Salary Range


Primary Purpose of Department


The Office of OneIT provides highly reliable information technology infrastructure, tools, and services to empower the University to achieve its academic, research, administrative, and service goals.


Primary Purpose of Position


The Security Operations Specialist is a highly technical, action-oriented role focused on defending the University’s digital infrastructure from active threats. This position will lead the initiative to integrate AI within the University’s security toolset. Instead of relying on passive compliance checklists, this position leverages cutting-edge artificial intelligence, machine learning, and automated orchestration to enable proactive threat hunting, accelerate real-time threat containment, and lower alert fatigue.


Summary of Position Responsibilities


Security Operations Support



  • Contribute to continuous improvement of the security information and event management ( SIEM ) system, developing processes and procedures for monitoring, alerting, detection, and response functions for on-premise, cloud-based, and, as appropriate, third‑party systems and services.

  • Review system logs and real-time alerts to identify trends, investigate abnormalities, and report exceptions.

  • Tune and create analytic detection policies for detecting and monitoring anomalous and malicious activity across the University Information Technology ecosystem.

  • Contribute to continuous improvement in Security Operations tasks and functions.

  • Support vulnerability management operations for the University and affiliates.

  • Create and maintain data dashboards and reports based on various systems of record to help the University IT community identify vulnerabilities, enabling them to focus their efforts to mitigate IT security risks across our environment.


Proactive Defense & AI-Augmented SOC Support

  • Threat Hunting:Deploy machine learning models and AI-driven behavior analytics to actively hunt for hidden threat actors.

  • SOC Augmentation: Design and maintain AI-assisted agents to triage alerts and automate response, reducing alert fatigue and response time.

  • Dynamic Optimization:Continuously build, tune, and refine policies across the Security tools to accurately catch modern, fast-moving attacker techniques.

  • Automated Defense: Assist Security Engineers to optimize and maintain Security Orchestration, Automation, and Response ( SOAR ) systems.

  • Adversarial Simulation: Develop and automate scripts and AI attack simulations to test existing defenses.

  • Perform the role of an incident response team member in the event of a successful attack to support technical response actions, incident mitigation, and recovery activities.

  • Participate in investigations of security incidents and provide resolutions based on alerts and events provided by security dashboards ranging from a Security Information and Event Management ( SIEM ) system to vulnerability scans or penetration testing assessments.

  • Contribute to procedures for proactive and reactive Incident Response to be used University-wide.

  • Bachelor’s degree in computer science, computer engineering, information security, or other closely related field and

  • 2+ years of relevant work experience; or an

  • Equivalent combination of education and relevant work experience.



  • Coding Experience

  • Experience working with Small and Large Language Models

  • Experience in a higher education environment

  • Experience within a security operations team

  • Understanding of how to utilize automation tools to increase the productivity and responsiveness of a SOC .

  • Ability to perform comfortably in a fast-paced, deadline-oriented work environment.

  • Ability to successfully execute many complex tasks in rapid succession.

  • Experience with security tools ( EDR , XDR , SIEM , Vulnerability Scanning)

  • One or more information security certifications such as GCIH , GPEN , SSCP are preferable, but not required.


Necessary Certifications/Licenses


Preferred Certifications/Licenses


Security+, CASP , ISC2 SSCP , GIAC GCIH , GPEN .


9201 University City BlvdCharlotte, NC 28223

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Specialist
Security Operations Specialist

University of North Carolina Charlotte • Charlotte (NC)

On-site
USD 70,000 - 120,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Senior Cybersecurity Ops Analyst
Senior Cybersecurity Ops Analyst

Jobtailor • Santa Ana (CA)

On-site
USD 75,000 - 120,000
Engineer, Cyber Security II
Engineer, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 120,000 - 160,000
Cybersecurity Operations Specialist
Cybersecurity Operations Specialist

Jobtailor • Los Angeles (CA)

On-site
USD 90,000 - 140,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
SOC Operator
SOC Operator

Altice USA • Norwalk (CT)

On-site
USD 70,000 - 90,000
Security Administrator Cyber Defense
Security Administrator Cyber Defense

Compunnel, Inc. • Midland (TX)

On-site
USD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Syracuse University • New York (NY)

On-site
USD 87,000 - 92,000
Security Operation Center (SOC) Analyst II
Security Operation Center (SOC) Analyst II

P-11 Security Inc • Colorado Springs (CO)

On-site
USD 90,000 - 130,000