Overview
Join CloudBees’ Global Security team as a Security Operations Engineer focused on building scalable security capabilities. You’ll design and tune detections, automate workflows, and enhance security telemetry across the CloudBees platform. You will collaborate with Product and Platform Engineering to improve observability and response capabilities. This role emphasizes automation, code and continuous improvement to move beyond traditional SOC. You’ll contribute to a security program that scales with business growth and complex environments.
Pay / Benefits
- Highly competitive benefits and vacation package
- Ability to work for one of the fastest growing companies with talented people
- Team outings
- Fun, Hardworking, and Casual Environment
- Endless Growth Opportunities
Responsibilities
- Design, build and continuously improve detection rules across cloud, endpoint, SaaS and applications
- Own the full detection lifecycle from hypothesis to deployment and tuning
- Create high-fidelity detections using threat intel and incident learnings
- Measure detection coverage using MITRE ATT&CK and reduce false positives
- Design and maintain SOAR playbooks for triage, enrichment, containment and response
- Automate repetitive analyst workflows via APIs, scripting and orchestration
- Build integrations across SIEM, EDR, CNAPP, vulnerability management and ticketing systems
- Collaborate with Product/Platform Engineering to improve security telemetry and logging
- Participate in vulnerability assessment and threat intelligence incorporation
- Lead or support incident response activities and proactive threat hunting
- Translate operational findings into practical engineering improvements
Key requirements
- 3+ years in Security Operations, Detection Engineering or Security Engineering
- Hands-on experience with enterprise SIEMs (Splunk, Microsoft Sentinel, Elastic, Chronicle, QRadar)
- Experience building and tuning detection rules
- Experience developing SOAR playbooks or security automation
- Strong scripting skills (Python, PowerShell or similar)
- Cloud experience (AWS preferred; Azure/GCP valued)
- Solid understanding of MITRE ATT&CK
- Experience supporting security incident response
- Comfort with Git, APIs and engineering workflows
- Excellent communication with Security and Engineering teams
- excellent communication
- collaboration
- analytical mindset
- SIEM proficiency (Splunk, Microsoft Sentinel, Elastic, Chronicle, QRadar)
- Detection rule design and tuning
- SOAR playbooks and security automation
…
