Himalayas logo
CriblCR

Security Operations Engineer

What started as a vision to revolutionize data management in 2017 has grown into a robust platform known as Cribl, the Data Engine for IT and Security.

Cribl

Employee count: 201-500

Salary: 130k-172k USD

United States only

Cribl does differently.

What does that mean? It means we are a serious company that doesn’t take itself too seriously; and we’re looking for people who love to get stuff done, and laugh a bit along the way. We’re growing rapidly - looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a remote-first company we believe in empowering our employees to do their best work, wherever they are.

As the data engine for IT and Security many of the biggest names in the most demanding industries trust Cribl to solve their most pressing data needs. Ready to do the best work of your career? Join the herd and unlock your opportunity.

Why You’ll Love This Role

The Security Operations Engineer will be a pivotal member of Cribl’s Information Security team, primarily responsible for strengthening our security posture through robust security operations and advanced threat detection. You will lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Chief Information Security Officer.


As An Active Member Of Our Team, You Will...

  • Knowledge of, and experience in, working with modern security principles e.g. security data lakes, detections as code, EDR, zero trust networking, and other security tooling, as well as demonstrated experience with incident response and management.
  • Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms.
  • Strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections to TTPs
  • Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM
  • Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash
  • Be the go-to technical subject matter expert on security, compliance, and assurance topics
  • Excellent communication skills and ability to communicate ideas to technical and non-technical audiences
  • Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally


If You’ve Got It - We Want It

  • Monitoring security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats
  • Developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security tools) based on threat intelligence, MITRE ATT&CK framework, and identified risks
  • Conducting continuous tuning and optimization of existing detection logic to reduce false positives and improve detection efficacy
  • Responding to issues identified by our Cribl employees
  • Acting as a security incident response lead, including leveraging and improving detection capabilities during investigations
  • Building, enhancing, and managing security playbooks, incorporating detection engineering best practices
  • Conducting security assessments of corporate assets through vulnerability testing, threat hunts, and purple team activities, with a focus on identifying detection gaps and opportunities
  • Performing both internal and external security reviews of corporate properties e.g., the corporate website and enterprise applications
  • Leading security incident response tabletop exercises
  • Continuing to evolve and champion the use of Cribl products in our security tech stack to enhance detection, analysis, and response capabilities
  • Collaborating with threat intelligence teams to integrate new indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) into detection strategies
  • Experience with SIEM platforms like Panther is a plu,s and its detection capabilities
  • Familiarity with Wiz and cloud native security tooling for detection in AWS, Azure, or GCP
  • Relevant certifications in cloud security or incident response (e.g., SANS GIAC certifications)


Salary Range
($130,000 - $172,000)

The salary for this role is dependent on geographic location. The salary offered within the range described will be based on the individual candidate’s job-related knowledge, skills, and experience. In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), equity, and eligibility for a discretionary company-wide bonus.

Bring Your Whole Self
Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Salary

Salary: 130k-172k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Cribl

Learn more about Cribl and their company culture.

View company profile

What started as a vision to revolutionize data management in 2017 has grown into a robust platform known as Cribl, the Data Engine for IT and Security. From a small San Francisco startup to a key player in the data management space, Cribl defines itself by empowering organizations to gain unprecedented control over their telemetry data. The company has developed a unified data management platform that not only simplifies but also optimizes how organizations explore, collect, process, and access their data at scale.

Through innovative product offerings like Stream, Edge, and Search, Cribl distinguishes itself by providing extensive connectivity while maintaining flexibility and choice. With a solution that integrates seamlessly into existing infrastructures, Cribl enables IT and security teams to efficiently manage their data without the burden of vendor lock-in. As businesses continue to evolve, so do their data needs—Cribl stands at the forefront, ensuring organizations can adapt quickly, respond to changes in data volume, and derive valuable insights. With over 40% of Fortune 100 companies relying on Cribl solutions, it is clear that Cribl is not just about managing data; it’s about transforming how organizations view and utilize their data assets.

Claim this profileCribl logoCR

Cribl

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

47 remote jobs at Cribl

Explore the variety of open remote roles at Cribl, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Cribl

Remote companies like Cribl

Find your next opportunity by exploring profiles of companies that are similar to Cribl. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan