Build and maintain SIEM for log collection and detection rules across corporate and production environments.
Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.
Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.
Monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources.
Perform structured investigations on escalated or ambiguous alerts to build coherent timelines.
Participate in incident response, including evidence collection and containment actions.
AlphaSense provides AI-driven market intelligence and search to help enterprises make informed decisions. The company has over 2,000 employees globally and fosters a culture of innovation and collaboration.
Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.
Second Front Systems is a public-benefit software company that accelerates secure software development and deployment for government and regulated networks. Founded by national security veterans, the company is a high-growth startup backed by top-tier venture capital with a culture of accountability and technical craft.
Design, develop, and maintain secure cloud environments for distributed LogRhythm deployments.
Act as a technical escalation point for SIEM engineers, solving complex security and infrastructure issues.
Build automation and operational tooling using PowerShell, SQL, Bash, or Python.
The company specializes in cybersecurity and managed SIEM services, focusing on protecting and scaling distributed LogRhythm environments. They offer a remote work environment with a collaborative culture and opportunities for professional growth.
Monitor, investigate, and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, firewall, cloud, identity, and endpoint security platforms.
Perform incident response and threat hunting activities, including alert triage, root cause analysis, containment, and documentation.
Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise and suspicious behavior.
Clear Capital is a national real estate analytics, data solutions, and valuation technology company that builds confidence in real estate decisions. The company values integrity, kindness, grit, empathy, attention to detail, and raising the bar.
Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
Develop and automate detection capabilities and incident response processes.
Collaborate with engineering and product teams to improve security posture and respond to incidents.
We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms.
Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation.
Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis.
Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million users in 100+ countries with a focus on security and innovation.
Lead investigation and response for security incidents, suspicious activity, and emerging threats.
Design, implement, and improve security monitoring, detection, and response capabilities across AWS.
Develop detection rules, conduct post-incident reviews, and partner with teams to strengthen security controls.
CoLab is an AI platform that helps mechanical engineering teams bring life-changing products to market faster by driving stronger engineering decisions. Founded in 2019 and based in St. John's, Newfoundland, CoLab has grown rapidly, earning recognition on Deloitte's Fast 50 and Fast 500 lists.
Monitor security events and provide technical analysis on alerts
Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.
Log source onboarding and telemetry analysis for SIEM integration in live client environments.
Write and tune detection logic to reduce false positives and address coverage gaps.
Turn vulnerability scanner output into prioritized findings using exploitability and asset criticality.
EVOCS is an IT consulting firm helping businesses operate effectively and solve complex challenges through technology solutions. The company serves a loyal customer base with a focus on quality, consistency, and building lasting client relationships based on trust and mutual success.
Analyze, investigate, document, and report on security alerts and potential incidents in customer environments.
Serve as an incident coordinator for urgent security events requiring response, containment, and remediation.
Stay up-to-date on security training, certifications, and emerging threats while providing security consultation to customers.
CyberSheath is a rapidly growing Managed Security Services Provider offering cybersecurity compliance and threat mitigation for the Defense Industrial Base. The company is expanding its team and fosters a fully remote work environment with a focus on security operations.
Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
Collaborate with product and engineering teams to evolve human-led agentic workflows.
Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.
Execute day-to-day implementation, monitoring, and optimization of cybersecurity systems and data pipelines.
Support log onboarding, normalization, and validation, as well as detection engineering and SIEM platform operations.
Assist in client engagements, security architecture reviews, and automation of response workflows.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and maintains a culture of collaboration and mentorship.
Manage, tune, and continuously improve EDR and SIEM platforms to enhance detection quality.
Develop dashboards, reports, alerts, and security use cases to monitor threats.
Collaborate with infrastructure and IT teams to onboard new systems and improve visibility.
Sporty is a remote-first company focused on building sustainable technology. They offer a competitive salary, quarterly bonuses, and a global team culture.
Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.
Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.
Design and implement robust security monitoring, logging, and incident response for FSA IAM systems.
Ensure compliance with FISMA, NIST RMF, and FedRAMP through advanced logging (EL3) and SIEM processes.
Manage security remediation, POA&M tracking, and vulnerability management to maintain Authority to Operate.
PingWind delivers outstanding services to the federal government in cybersecurity, development, IT infrastructure, and supply chain management. It is an SBA-certified Service-Disabled Veteran-Owned Small Business with offices in Northern Virginia and Huntsville, AL.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Provide technical guidance and recommendations to clients to enhance their overall security posture within managed products.
Handle daily proactive maintenance and reactive troubleshooting/repair functions for security tools and systems.
Utilize SIEM and other tools to assist in network investigations, including firewalls, IDS/IPS and monitoring tools.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. The company provides a stimulating work environment with cutting-edge security technologies and opportunities for professional growth.