FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in deploying and maintaining SIEM, SOAR, and EDR environments, with a strong focus on Python service development and automated detection workflows. Proven ability to manage platform reliability and integrate complex vendor APIs while ensuring security and compliance.
Highest-signal resume keywords
SIEM/SOAR/EDR Platform ManagementPython Service DevelopmentAutomated Detection and Response WorkflowsPlatform Reliability OwnershipVendor API Integration
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
PythonGoSIEMSOAREDRAPI IntegrationAutomated WorkflowsDetection-as-CodeProduction OwnershipPerformance Tuning
Tools & Technologies
CrowdStrikeSentinelOneMicrosoft DefenderSplunkMicrosoft SentinelGoogle SecOpsKubernetes
Certifications & Qualifications
AWS Professional EngineerGCP Professional EngineerSecurity-Related Credentials
Industry Keywords
MDRMSSPDetection and ResponseSecurity ToolingMulti-Tenant EDR
Tech Stack
Tools & technologiesAWSGoogle Cloud PlatformKubernetesPythonSplunkGo
About the role
Key responsibilities & impact- Deploy, configure, and maintain SIEM, SOAR, and EDR environments across vendors including CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Microsoft Sentinel, and Google SecOps
- Manage EDR prevention policies, host groups, custom IOAs, exclusions, SIEM detection content, and SOAR connectors
- Troubleshoot and resolve EDR agent issues, including performance impacts, kernel or driver conflicts, upgrade rollouts, and false-positive tuning
- Develop, test, and deploy production Python services, APIs, workers, queues, tests, CI, and containers
- Build automated containment and remediation workflows such as host isolation, process termination, file quarantine, account disabling, and ticket creation
- Architect safety guardrails including approval thresholds, critical-host allow lists, isolation-action rate limits, audit trails, and safe release or rollback paths
- Own platform reliability and latency outcomes, including time from alert to containment
- Participate in the on-call rotation for security tooling
- Create and maintain observable internal tooling with logging, metrics, and alerting
Requirements
What you’ll need- Deep, hands-on experience operating multiple SIEM/SOAR/EDR platforms
- Proven software engineering experience building and maintaining production Python services and APIs
- Experience integrating with complex vendor APIs and managing authentication, rate limits, and retries
- Demonstrated experience building automated detection and response workflows with carefully designed safety guardrails
- Track record of taking end-to-end production ownership of a platform
- Bachelor's or Master's degree in Computer Science, Engineering, or a related field
- Relevant certifications are a plus, including AWS/GCP Professional Engineer, Kubernetes, or security-related credentials
- Experience managing multi-tenant EDR structures is a nice-to-have
- Proficiency in Go and/or Python is a nice-to-have
- Detection-as-code experience is a nice-to-have
- Background working at MDR/MSSP providers, SOAR vendors, EDR vendor engineering teams, or detection and response teams of security-mature technology companies is a nice-to-have
- Ability to work onsite four days per week, Monday through Thursday
- Ability to work in the United States; the application asks whether the candidate is legally authorized to work in the United States and whether sponsorship will be required
Benefits
Comp & perks- Competitive salary and benefits package
- Culture of growth and development
- Opportunities to expand knowledge in AI, cybersecurity, and emerging technologies
- Opportunity to work with cutting-edge AI-driven cybersecurity technologies and Google SecOps solutions
- Collaborate with a talented and innovative team focused on continuously improving security operations
