Intermediate SecOps Engineer

Posted 5ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Intermediate SecOps Engineer at the Eclipse Foundation managing security operations. Focused on threat detection, incident response, and operational resilience across infrastructure.

Responsibilities:

  • Develop, maintain, and improve detection rules, alerts, dashboard, and monitoring workflows across infrastructure, cloud services, identity systems, endpoints, and application platforms.
  • Participate in incident response activities, including triage, investigation, containment, remediation coordination and post-incident analysis.
  • Operate and improve security monitoring tooling, including SIEM, log aggregation, alerting, vulnerability management, and related detection and response platforms.
  • Proactively investigate suspicious activity, anomalous behavior, and emerging threats affecting infrastructure and services.
  • Create and maintain incident response playbooks, escalation procedure, actionable security guidance, and operational documentation to cloud operations, product development, and systems engineering teams.
  • Collaborate with the systems engineering team to identify and remediate security weaknesses in cloud, container, Linux, network, identity, and service configurations.
  • Actively participate in comprehensive disaster recovery planning, business continuity strategy formulation, and live simulations/exercises to validate system resilience and team readiness.

Requirements:

  • 3–5+ years of professional experience in an active security operations, infrastructure security, incident response, or a related operational security role.
  • Hands-on experience with security monitoring, alert triage, incident investigation, and response workflows.
  • Experience with SIEM, log aggregation, alerting, or detection engineering tools.
  • Strong understanding of Linux systems, networking fundamentals, identity and access management, and common infrastructure attack techniques.
  • Familiarity with containerized environments (Docker, Kubernetes, OKD/OpenShift), and public cloud ecosystems (AWS, Azure, or GCP).
  • Experience writing or maintaining operational runbooks, response procedures, detection rules, or incident documentation.
  • Working knowledge of common security frameworks and attacker techniques, such as MITRE ATT&CK, CIS Controls, or similar.
  • Relevant certifications are highly desirable (e.g., CompTIA Security+, CEH, CSSLP, CCSP, or cloud security certifications).

Benefits:

  • Fully remote positions
  • Work-life balance support
  • Friday flex-time
  • Right-to-disconnect policy
  • Corporate Recharge days
  • Comprehensive benefits package