Security Operations Administrator
United States
â ď¸ We'll shut down after Aug 1st - try foođŚ instead â ď¸
Coalfire
Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses in FedRAMP, cloud migration, AI Risk, penâŚCoalfire is on a mission to make the world a safer place by solving our clientsâ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.
But thatâs not who we are â thatâs just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
POSITION SUMMARY:Who We Are Coalfire is on a mission to make the world a safer place by solving our clientsâ toughest cybersecurity challenges. As a leading cybersecurity solutions provider serving both private and public sector clients, we work at the cutting edge of technologyâadvising, assessing, automating, and guiding organizations through the ever-changing security landscape. Our professionals thrive on delivering unbiased assessments, expert guidance, and innovative strategies tailored to each clientâs unique needs.âŻâŻÂ But thatâs not who we are â thatâs just what we do.âŻâŻÂ We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference. Headquartered in Denver, Colorado, with offices across the U.S. and U.K., we support clients around the globe. And weâre expanding fast.âŻâŻÂ  Why Join Us Weâre looking for a Security Operations Admin to work on our vulnerability management processes, driving compliance and security in cloud-based environments, as well as support our SIEM monitoring and alerting to meet FedRAMP requirements. If youâre driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place. Â
What You'll Do
- Support and maintain enterprise vulnerability management tools (Tenable, Burp, Microsoft Defender), ensuring timely updates and patchesÂ
- Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams (for example, SRE and client administrators) to create tickets for remediationÂ
- Track and document vendor dependencies, operational requirements, and open vulnerabilities on a monthly basis, producing clear reports and updates for clientsÂ
- Maintain, and update SIEM solutions (e.g., Splunk, Sentinel, ELK, LogRhythm, Sumo Logic) to enhance visibility and proactively mitigate cyber threats.Â
- Build and respond to critical security alerts as part of our incident monitoring process.
What You'll Bring
- 1-2 years' experience in 24x7x365 production security operations
- 1-2 years' experience participating in incident response and analysis activities
- 1-2 years' experience with vulnerability management, compliance monitoring, or related security operations rolesÂ
- Hands-on expertise with operating system, database, network, container, web application, and API vulnerability managementÂ
- 1+ years of hands-on technical experience supporting cloud operations and automation in Azure, AWS, and/or GCP
- Experience in Information Security with a focus on incident response and security engineering
- Exposure to threat identification using SIEM tools, log sources, and forensics tools and techniques
- Experience with ITSM solutions such as Jira and ServiceNow
- Experience or familiarity with Tenable.sc, Nessus Pro, or Nexpose
- Understanding of regular expression and query languages
- Experience analyzing events or incidents to triage the issue
- Fundamental skills and knowledge of Azure, AWS, or GCP
- Knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS)Â
- Ability to work efficiently with technical teams to investigate, prioritize, and remediate vulnerabilitiesÂ
- Familiarity with defining baseline configuration standards (for example, CIS Benchmarks) and reporting on compliance postureÂ
- Exposure to one SIEM platform (e.g., Splunk, Sentinel, ELK, LogRhythm, Sumo Logic) and enterprise antivirus (AV) solutions (e.g., Trend Micro, CrowdStrike, Microsoft Defender).Â
- Experience working in large scale enterprise environmentsÂ
- Effective communication, organizational, and documentation skills, with an emphasis on providing timely updates and clear reports to clientsÂ
Bonus Points
- Professional services background: Prior experience supporting external clients from within a consulting or professional services organization.Â
- Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible.Â
- Configuration baseline standards: Familiarity with CIS Benchmarks, DISA STIG, and other relevant guidelines.Â
- Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.Â
- Security-focused cloud certifications for Azure, AWS, or GCPÂ
- Security+Â
At Coalfire, youâll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where youâll work most effectively â whether youâre at home or an office.
Regardless of location, youâll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. Youâll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And youâll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: Ansible Antivirus APIs Automation AWS Azure Cloud Compliance CrowdStrike CVSS DISA ELK FedRAMP FISMA Forensics GCP GitHub GitLab HIPAA HITRUST Incident response Jira LogRhythm Monitoring Nessus Sentinel SIEM Splunk Terraform Vulnerabilities Vulnerability management
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Insurance Parental leave Salary bonus Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.