we are looking for a SecOps Engineer.
As a SecOps Engineer, you'll be the operational nerve center of Guardicore's R&D Security Squad, the team protecting the platform we build. Embedded with the engineers creating Guardicore, you'll drive real-time detection, response, and full-lifecycle vulnerability management, turning every finding into measurable risk reduction. If you thrive on hunting threats, reducing signal-to-noise, and driving remediation to closure, this is your arena.
As a SecOps Engineer, you will be responsible for:
Ingesting and analyzing vulnerabilities from tools such as Wiz, Vulcan, Grype, and Tenable, while quantifying impact by exploitability and reachability.
Building AI automations that streamline the full security operations loop. Auto-triaging and containing SIEM alerts by prioritizing vulnerability data across tools.
Engineering signal quality by designing correlation searches and tuning detection rules. Automating SOAR playbooks to cut false positives and shrink MTTR.
Driving remediation governance by generating tickets, assigning owners, enforcing deadlines, verifying fixes through rescans, and collecting evidence comprehensively.
Building visibility and KPIs through live dashboards for monitoring remediation speed, SLA compliance, MTTR/MTTD, patch age, and risk trends
Running detection and response, monitoring SIEM telemetry, triaging alerts, mitigating threats, conducting root-cause analysis, aligning TTPs with MITRE ATT&CK, recommending safeguards.
Requirements: 5+ years in Security Operations, SOC, or Incident Response, handling live incidents and vulnerability remediation end-to-end.
Develop parsers, analytics, and automation scripts using Python, Bash, or Go; utilize SIEM tools such as Splunk and SOAR platforms.
Design vulnerability-management dashboards and SLA tracking for leadership visibility.
Experience triaging and analyzing vulnerabilities, assigning owners, recommending mitigations, and writing clear post-mortem reports.
Demonstrate expertise in network protocols, Linux/Windows internals, and cloud telemetry such as GCP or AWS.
Gain experience with vulnerability-management platforms and risk-based prioritization models.
Present metrics, incident summaries, and remediation roadmaps to both engineers and executives.
Proactive, clear communication with stakeholders across technical and business teams.
This position is open to all candidates.