
201 - 500 employees
Founded 1989
đ Cybersecurity
đ Education
âď¸ SaaS
Cybersecurity ⢠Education ⢠SaaS
SANS Institute is a leading organization specializing in cybersecurity training and education, providing a wide range of hands-on courses, certifications, and degree programs aimed at enhancing the skills and expertise of cybersecurity professionals. Founded in 1989, it offers expert-led training sessions globally, alongside resources like webinars and podcasts to support ongoing learning and development in the cybersecurity field. SANS Institute is dedicated to helping individuals and organizations mitigate cyber risks through rigorous training that aligns with industry standards and best practices.
đĽ 2 hours ago
đŚ Maryland â Remote
đľ $155k - $205k / year
â° Full Time
đ Senior
đĄď¸ Security Operations
đť Ghost score 0%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 1989
đ Cybersecurity
đ Education
âď¸ SaaS
Cybersecurity ⢠Education ⢠SaaS
SANS Institute is a leading organization specializing in cybersecurity training and education, providing a wide range of hands-on courses, certifications, and degree programs aimed at enhancing the skills and expertise of cybersecurity professionals. Founded in 1989, it offers expert-led training sessions globally, alongside resources like webinars and podcasts to support ongoing learning and development in the cybersecurity field. SANS Institute is dedicated to helping individuals and organizations mitigate cyber risks through rigorous training that aligns with industry standards and best practices.
⢠Design the architecture of the agentic SOC ⢠Define data flows through detection and response pipelines ⢠Define agent structure, orchestration, human-in-the-loop checkpoints, and system evolution ⢠Write, tune, and maintain detections across the internal SIEM environment ⢠Establish a detection lifecycle of design, deploy, measure, tune, and improve ⢠Identify alert triage, investigation, and response work suitable for agent augmentation ⢠Build integrations, scripts, and playbooks across MSSP, EDR, SIEM, cloud infrastructure, and identity platforms ⢠Partner with AI Engineering to build and govern the agent stack ⢠Co-design MCP servers and tool integrations ⢠Contribute to prompt design, evaluation harnesses, and feedback loops ⢠Own audit trails and checkpoints for safe and accountable agent actions ⢠Monitor agent performance, investigate failures, tune behavior, and incorporate real-world outcomes ⢠Own vulnerability identification, prioritization, and remediation tracking ⢠Assess and improve AWS and Azure cloud security posture ⢠Review IAM policies, harden configurations, implement cloud-native detection, and monitor posture ⢠Partner on identity architecture, access reviews, privilege management, and authentication standards ⢠Conduct code reviews, threat models, and security assessments for internal applications and integrations ⢠Evaluate technologies, integrations, and infrastructure changes for security risk ⢠Provide pragmatic, risk-based security guidance ⢠Support compliance activities, evidence collection, and audit engagements ⢠Respond to security incidents ⢠Perform other related duties as assigned
⢠7+ years in security operations, detection engineering, or security automation ⢠First-hand experience with alert triage workflows, escalation paths, investigation patterns, and incident response lifecycle ⢠Detection engineering experience, including writing and tuning detections, measuring efficacy, and managing false positives ⢠Expert-level command of at least one detection query language: KQL, SPL, Lucene, Sigma, or equivalent ⢠MITRE ATT&CK fluency ⢠Hands-on experience with EDR and SIEM platforms in production environments ⢠Ability to design end-to-end security operations pipelines ⢠Systems thinking and ability to reason about data flows, dependencies, failure modes, and architectural implications ⢠Experience designing for scale and maintainability ⢠Exposure to threat modeling concepts applied to security infrastructure ⢠Strong Python, including production-quality code, testing, version control, and code review discipline ⢠Experience building integrations against REST APIs across heterogeneous security tools ⢠Experience with SOAR platforms, security automation frameworks, or equivalent tooling ⢠Git-based workflows and as-code mindset ⢠Working knowledge of AWS ⢠Curiosity about LLM-based agents and traditional automation ⢠Willingness to learn agent frameworks, MCP, and prompt engineering ⢠Comfort with JSON and Markdown ⢠Calibrated skepticism about over-automation ⢠Operator empathy ⢠Comfort with ambiguity ⢠Unrestricted authorization to work in the USA; visa sponsorship is not available ⢠Preferred: experience with MSSP-managed detection and response environments ⢠Preferred: detection-as-code experience, including CI/CD pipelines, automated testing, and content packaging ⢠Preferred: prior SOAR playbook experience with Tines, Torq, Cortex XSOAR, Splunk SOAR, or equivalent ⢠Preferred: incident response experience beyond Tier 1 ⢠Preferred: cloud detection and response experience ⢠Preferred: identity-focused detection experience with Entra, Okta, Active Directory, or similar ⢠Preferred: hands-on LLM tooling experience ⢠Preferred: familiarity with agentic development workflows such as CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar ⢠Preferred: prompt injection and LLM adversarial thinking experience
⢠Competitive base salary ⢠Bonus opportunities ⢠401(k) plan with company match ⢠Medical, dental, and vision plans ⢠Company-provided short term disability ⢠Optional long-term disability ⢠Supplemental life and AD&D insurance for employees and dependents ⢠Voluntary accident insurance ⢠Identity theft protection ⢠Fitness and wellness programs ⢠Company-paid employee assistance program (EAP) ⢠Generous paid time off, including volunteer time ⢠Professional development opportunities ⢠SANS training opportunities ⢠Primarily remote work environment ⢠Tools and flexibility to thrive professionally and personally
Apply NowđĽ 22 hours ago
Tier III SOC Analyst conducting forensic investigations, detection engineering, and incident escalation. Supporting Valiant Solutionsâ public-sector cybersecurity contracts through remote telework.
đ Yesterday
Program Manager overseeing embedded employees, vendors, and protective operations for Concentric, a global risk consultancy. Managing client relationships, security resources, compliance, and operational delivery.
đşđ¸ United States â Remote
đľ $165k - $175k / year
â° Full Time
đ Senior
đ´ Lead
đĄď¸ Security Operations
đ 2 days ago
Operations Analyst supporting MondelÄz Internationalâs cyber defense operations. Assessing information security risks, testing controls, implementing security technology, and training teams.
đşđ¸ United States â Remote
đľ $97.3k - $133.8k / year
â° Full Time
đĄ Mid-level
đ Senior
đĄď¸ Security Operations
đ 2 days ago
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsaraâs Connected Operations IoT platform. Building security automation and supporting insider-threat investigations.
đşđ¸ United States â Remote
đľ $135.5k - $227.7k / year
đ° Seed Round on 2014-08
â° Full Time
đ Senior
đĄď¸ Security Operations
đŚ H1B Visa Sponsor
đ 2 days ago
Senior Manager building Motiveâs AI-first SOC across cloud, production, enterprise and connected-device environments. Leading detection, incident response, threat hunting and security automation.
đşđ¸ United States â Remote
đľ $140k - $200k / year
â° Full Time
đ Senior
đĄď¸ Security Operations
đŚ H1B Visa Sponsor