Monitor, analyze, and respond to complex security incidents, guiding Level 1 engineers and contributing to the organization's security posture.
Conduct in-depth forensic analysis, manage vulnerabilities, and optimize security tools such as SIEM, IDS/IPS, and endpoint protection.
Collaborate with IT and security teams, participate in on-call support, and stay updated on the latest cybersecurity threats and best practices.
CTS delivers comprehensive IT solutions for mission-driven organizations, with deep expertise in nonprofits and education. The company is headquartered in Brooklyn, NY with 90+ employees across the US and several other countries, fostering a culture of growth and innovation.
Support the security team by monitoring and triaging security activity, investigating potential threats, and improving security operations across endpoint, network, and cloud platforms.
Assist with developing SIEM detection rules, analyzing security telemetry for anomalous behavior, and conducting targeted threat-hunting activities.
Work with vulnerability management, threat intelligence, and documentation to strengthen security practices and ensure adherence to policies.
SimSpace is an AI Proving Ground that helps organizations train, test, and outmaneuver adversaries through realistic cyber simulations. Founded in 2015 by experts from U.S. Cyber Command and MIT Lincoln Laboratory, the company fosters a culture of continuous learning and professional growth, consistently outperforming industry benchmarks in internal mobility and promotions.
Participate in assessing client environments against frameworks like NIST CSF 2.0, CIS Controls, and ISO 27001.
Design and implement secure solutions across cybersecurity, networking, and cloud technologies.
Perform configuration, installation, and maintenance of security products and services.
Apollo Information Systems is a cybersecurity services company delivering unified security and compliance programs through a subscription-based platform. Backed by Series A funding, the company is growing rapidly with a collaborative, mission-driven culture and a remote-first team with a hub in Denver.
Execute day-to-day implementation, monitoring, and optimization of cybersecurity systems and data pipelines.
Support log onboarding, normalization, and validation, as well as detection engineering and SIEM platform operations.
Assist in client engagements, security architecture reviews, and automation of response workflows.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and maintains a culture of collaboration and mentorship.
Manage day-to-day security operational availability and supportability of a 24x7x365 infrastructure.
Make recommendations on enhancements to security hardware, software, and tools, and perform risk analysis.
Configure, implement, monitor, and support security software/systems including firewalls, VPNs, IDS/IPS, DLP, etc.
eMoney Advisor is a wealth management system that offers transparency, security, mobile access, and superior organization. We serve more than 109,000 financial professionals and support over 6 million end clients, fostering a culture that values diversity and inclusion.
Independently execute endpoint security, identity management, and vulnerability remediation across Windows, macOS, Linux, and cloud platforms.
Monitor and analyze alerts within SIEM and EDR, conduct initial investigations, and escalate complex findings as needed.
Partner with IT, Engineering, DevOps, and IAM teams to maintain security controls and support compliance frameworks like SOC 2, HIPAA, and ISO 27001.
Accela is an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement, and enable the development of thriving communities. The company has been operating for nearly 20 years, fosters a diverse and inclusive culture, and is committed to equity and belonging.
Provide technical guidance and recommendations to clients to enhance their overall security posture within managed products.
Handle daily proactive maintenance and reactive troubleshooting/repair functions for security tools and systems.
Utilize SIEM and other tools to assist in network investigations, including firewalls, IDS/IPS and monitoring tools.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. The company provides a stimulating work environment with cutting-edge security technologies and opportunities for professional growth.
Design and implement secure network architectures and manage operational delivery of managed services.
Lead and mentor technical teams while ensuring SLA compliance and client satisfaction.
Utilize SIEM tools and AIOps to enhance monitoring, threat detection, and automation.
Myriad360 is a managed services provider focused on networking and security solutions. They are a recognized best place to work with a culture centered on collaboration, ownership, and continuous improvement.
Lead DLP incident response, including investigation, containment, and remediation.
Deploy and tune DLP controls across endpoints, network, and cloud.
Develop DLP policies and automated playbooks.
Included Health is a healthcare company that delivers integrated virtual care and navigation. They have a remote-first culture and offer comprehensive benefits.
Lead complex incident response investigations end-to-end with minimal supervision.
Perform alert triage, phishing investigations, endpoint forensics, and data exfiltration analysis.
Mentor junior analysts and drive improvements to security processes.
Version 1 is a technology and transformation solutions provider trusted by global brands. With over 3,300 employees and €350m revenue, it has been recognized as a Great Place to Work for over a decade.
Design, develop, and maintain secure cloud environments for distributed LogRhythm deployments.
Act as a technical escalation point for SIEM engineers, solving complex security and infrastructure issues.
Build automation and operational tooling using PowerShell, SQL, Bash, or Python.
The company specializes in cybersecurity and managed SIEM services, focusing on protecting and scaling distributed LogRhythm environments. They offer a remote work environment with a collaborative culture and opportunities for professional growth.
Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
Own security awareness programming and use automation to shorten research, triage, and reporting cycles.
Major League Baseball (MLB) is the most historic professional sports league in the United States and Canada. With a league office, 30 Clubs, and affiliates, MLB fosters a culture of growth, teamwork, and professionalism, empowering employees to take initiative and put the team first.
Manage, tune, and continuously improve EDR and SIEM platforms to enhance detection quality.
Develop dashboards, reports, alerts, and security use cases to monitor threats.
Collaborate with infrastructure and IT teams to onboard new systems and improve visibility.
Sporty is a remote-first company focused on building sustainable technology. They offer a competitive salary, quarterly bonuses, and a global team culture.
Combine security operations, software engineering, and site reliability to protect complex digital infrastructure.
Design, build, and operate security platforms, tooling, and automation for threat detection and incident response.
Mentor engineers, influence operational strategy, and contribute to open source security initiatives.
They build and operate a world-class Security Operations function. They are a distributed, agile engineering organization that values technical excellence and continuous learning.
Monitor, investigate, and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, firewall, cloud, identity, and endpoint security platforms.
Perform incident response and threat hunting activities, including alert triage, root cause analysis, containment, and documentation.
Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise and suspicious behavior.
Clear Capital is a national real estate analytics, data solutions, and valuation technology company that builds confidence in real estate decisions. The company values integrity, kindness, grit, empathy, attention to detail, and raising the bar.
Design and implement enterprise security architecture and cyber security protection initiatives.
Install, upgrade, and maintain security hardware and software systems to ensure data integrity.
Serve as Tier-3 escalation support and collaborate on vulnerability remediation plans.
We are shaping the healthcare of the future by providing actively managed care that prevents disease and supports chronic conditions. We are the largest Independent Physician Association in Northern California and have been recognized as one of the Best Places to Work in the Bay Area.
Lead incident response across platforms and applications, from triage to recovery.
Hunt proactively for threats using system logs, user behavior, and threat intelligence.
Build and automate incident response workflows and strengthen detection with MITRE ATT&CK.
Xplor provides cloud-based technology solutions that help small and medium-sized businesses manage operations and get paid securely. With over 130,000 businesses in 72+ countries processing $47B annually, the company fosters a culture of simplicity, purpose, and community.
Design and implement robust security monitoring, logging, and incident response for FSA IAM systems.
Ensure compliance with FISMA, NIST RMF, and FedRAMP through advanced logging (EL3) and SIEM processes.
Manage security remediation, POA&M tracking, and vulnerability management to maintain Authority to Operate.
PingWind delivers outstanding services to the federal government in cybersecurity, development, IT infrastructure, and supply chain management. It is an SBA-certified Service-Disabled Veteran-Owned Small Business with offices in Northern Virginia and Huntsville, AL.
Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
Drive AI security strategy and partner with cross-functional teams to build robust detection controls.
Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.