Cybersecurity Operations Engineer II

USA Remote, United States

Everfox

Everfox has been defending the world's critical data and networks against the most complex cyber threats imaginable for more than 25 years.

View all jobs at Everfox

Apply now Apply later

Intelligent. Dynamic. Resilient. 


Everfox, formerly Forcepoint Federal, has been defending the world’s most critical data and networks against the most complex cyber threats imaginable for more than 25 years. As trailblazers in defense-grade, high assurance cyber security, we have been leading the way in developing and delivering innovative cyber security technology. We protect data wherever it resides. Our unwavering dedication and commitment to our customers and the critical missions they serve are what set us apart. We are dynamic, vigilant, and proactive in everything we do. Our suite of cross domain, threat protection and insider risk solutions empower governments and enterprise organizations to use data safely - where and however their people need it. At Everfox, we innovate, we invest, we achieve. We protect what matters most to our customers. And we offer protection like no other. We do all of this so our customers can focus on what matters most… their mission.

Title: Cybersecurity Operations Engineer II 

Location: Remote, USA

Job Summary:

The Cybersecurity Operations Engineer II plays a pivotal role in safeguarding the organization's digital assets by monitoring, detecting, and responding to security incidents and threats. This position requires a vigilant and detail-oriented professional with a strong understanding of security technologies, incident response, and a proactive approach to mitigating risks. 

Key Responsibilities: 

1. Security Monitoring and Incident Response

  • Level 2/3 incident response, triage and investigation 

  • Monitor and analyze security events using Security Information and Event Management (SIEM) and various security tools. 

  • Investigate potential security incidents and escalate findings to senior security members. 

  • Collaborate with cross-functional teams to develop and execute incident response plans. 

  • Document incident details, actions taken, and lessons learned for continuous improvement. 

2. Threat Detection and Analysis: 

  • Monitor and analyze network traffic, logs, and system events to identify patterns and anomalies indicative of security threats. 

  • Stay current with emerging cyber threats and vulnerabilities and adjust monitoring and detection strategies accordingly. 

  • Assist in the identification and coordination of appropriate teams to remediate security weaknesses or vulnerabilities. 

  • Insider Threat/FIT analyst 

  • Perimeter security administration and response 

3. Security Tool Management: 

  • Level 2/3 CSP (Cybersecurity Engineering) - administration/monitoring of tools within M365 G5 

  • Assist in the management and configuration of security tools such as SIEM (Security Information and Event Management), intrusion detection systems, and endpoint protection solutions. 

  • Contribute to the tuning and optimization of security tools to reduce false positives and enhance detection accuracy. 

  • Contribute to rule and detection tuning across security tools. 

  • Monitor and respond to shared email boxes and leverage case management tools to triage, escalate, or resolve potential security incidents within SLAs. 

4. Compliance and Reporting: 

  • Assist in maintaining compliance with security policies, procedures, and regulatory requirements. 

  • Research and assist on regular reports on security incidents, monitoring activities, and emerging threats for management and stakeholders. 

5. Security Awareness and Training: 

  • Participate in security awareness and training programs for employees to enhance the organization's overall security posture. 

Qualifications: 

  • Bachelor’s degree in information security, Computer Science, or a related field. 

  • A minimum of 2 years of professional experience in Information Security is preferred. 

  • Relevant certifications, such as CompTIA Security+, CompTIA Network+, CISSP, CISM are a plus. 

  • Knowledge of cybersecurity principles, threat landscape, and security technologies. 

  • Strong analytical skills and the ability to identify and respond to security incidents. 

  • Familiarity with security tools and technologies, including Google Chronicle (SIEM), Crowdstrike AV/EDR, Forcepoint DLP, Microsoft DLP, Zscaler (Web Proxy), Delinea Privilege Manager, Device42, Zabbix, RSA, Tenable.sc, Tenable.io, Digicert, Password Manager Pro, Intune, Windows Defender, CloudTrails, GuardDuty 

  • Effective communication and teamwork skills to collaborate with incident response teams and other stakeholders. 

  • Strong problem-solving skills and attention to detail. 

A reasonable estimate of the base salary range for this role is:

$74,490.26-112,548.80 USD

The actual salary offered may vary within the range based on a candidates' unique experience, locale, and business needs. In addition to a base salary and bonus plans, Everfox offers a generous benefits package including flexible PTO, a 401k match, and contribution to healthcare coverages. Our talent acquisition team will provide specific information regarding bonus eligibility and benefits offerings.

________________________________________________________________

Don’t meet every single qualification? Studies show people are hesitant to apply if they don’t meet all requirements listed in a job posting. If there is something slightly different about your previous experience, but it otherwise aligns and you’re excited about this role, we encourage you to apply. You could be a great candidate for this or other roles on our team.

The policy of Everfox is to provide equal employment opportunities to all applicants and employees without regard to race, color, creed, religion, sex, sexual orientation, gender identity, marital status, citizenship status, age, national origin, ancestry, disability, veteran status, or any other legally protected status and to affirmatively seek to advance the principles of equal employment opportunity. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company’s career webpage as a result of your disability. You may request reasonable accommodations by sending an email to HR@everfox.com 

Everfox is a Federal Contractor. Certain positions with Everfox require access to controlled goods and technologies subject to the International Traffic in Arms Regulations or the Export Administration Regulations. Applicants for these positions may need to be "U.S. Persons," as defined in these regulations. Generally, a "U.S. Person" is a U.S. citizen, lawful permanent resident, or an individual who has been admitted as a refugee or granted asylum.

Applicants must have the right to work in the location to which you have applied.

#LI-DO1
Apply now Apply later
Job stats:  2  1  0

Tags: CISM CISSP Compliance CompTIA Computer Science CrowdStrike EDR Incident response Intrusion detection Monitoring RSA SIEM SLAs Threat detection Vulnerabilities Windows

Perks/benefits: 401(k) matching Flex vacation Team events

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.