Quick Overview
Job Description
Job Title: Cyber Security Operations Specialist
Experience: 12+ Years
Location: Pittsburgh, PA (Onsite) LOCALS ONLY
Work Mode: Client Location No Remote / No Relocation
The role will work closely with Security Operations Centre (SOC), Infrastructure, Cloud Engineering, DevOps, and Compliance teams to maintain a secure cloud ecosystem and strengthen the organization's cybersecurity posture.
Key Responsibilities
Security Monitoring & Incident Response
- Monitor cloud environments for security threats, suspicious activities, and policy violations.
- Investigate security alerts and incidents generated by SIEM, XDR, and cloud-native security tools.
- Lead incident triage, containment, eradication, and recovery activities.
- Perform root cause analysis and document incident findings and remediation actions.
- Develop and maintain cloud security incident response playbooks.
Cloud Security Operations
- Manage and improve cloud security posture across Azure, AWS, and Google Cloud Platform.
- Identify and remediate cloud misconfigurations, vulnerabilities, and security gaps.
- Monitor compliance with cloud security baselines, policies, and regulatory requirements.
- Conduct cloud security risk assessments and security reviews.
Identity & Access Security
- Monitor privileged access and enforce least-privilege principles.
- Manage and review IAM policies, RBAC roles, MFA, Conditional Access, and Privileged Identity Management (PIM).
- Investigate identity-based threats and unauthorized access attempts.
Threat Hunting & Detection Engineering
- Perform proactive threat hunting across cloud workloads and services.
- Develop detection use cases and custom analytics rules.
- Leverage MITRE ATT&CK framework to enhance detection capabilities.
- Identify emerging cloud threats and recommend security improvements.
Security Automation & Reporting
- Support security automation initiatives using SOAR and scripting.
- Develop dashboards, reports, and security metrics for management review.
- Participate in cloud security governance and operational reviews.
- Recommend process improvements to enhance cloud security operations efficiency.
Cloud security responsibilities
- Understand and use corporate information security frameworks, policies, implementation, and support tools
- Translate and evolve corporate security policies into cloud requirements
- Identify compliance standards, craft policies and controls in support of standards, and implement Policy as Code (e.g. SOC-2 NIST 800-53, ISO 27001)
- Use Policy as Code to enforce pre-deployment compliance on IaC scripts (e.g. static code analysis of TF, Helm)
- Use Policy as Code to implement compliance and configuration monitoring of the running state of cloud environment.
- Use Policy as Code to prevent out of band (bypassing pipeline) misconfiguration via cloud vendor policy engine (Azure, GCO, OCI Policy)
- Evaluate and identify suite of security tooling to be used in partnership with product teams & Information Security for vulnerability scanning, alerting, & reporting (e.g. Azure Monitor, Azure Sentinel (SIEM), Azure Policy (policy enforcement), and Azure Security Center, CGP Security center, OCI cloud guard, CSPM etc)
- Establish security support processes in partnership with product teams and Information.
- Security for vulnerability scanning, alerting, and reporting, leveraging automated incident response and self-service tools, when possible
- Provide resolution support to address security and compliance infrastructure exposures identified through monitoring and alerts.
- Establish preventative procedures to resolve newly identified security exposures prior to impact.
Required Skills & Qualifications
Technical Skills
- Strong experience with Microsoft Azure, AWS, or Google Cloud Platform.
- Hands-on experience with:
- Microsoft Sentinel
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- AWS Security Hub
- CrowdStrike
- Knowledge of cloud networking, firewalls, VPNs, WAF, and Zero Trust architecture.
- Experience with Identity and Access Management (IAM), SSO, MFA, and RBAC.
- Familiarity with Vulnerability Management and CSPM solutions.
- Working knowledge of PowerShell, Python, Bash, or KQL.
- CSPM, KSPM, SSPM
Security Knowledge
- Security Operations Center (SOC) processes.
- Incident Response and Threat Hunting.
- Security Monitoring and Log Analysis.
- Cloud Security Best Practices.
- MITRE ATT&CK Framework.
- NIST Cybersecurity Framework.
- CIS Benchmarks.
- ISO 27001
Similar jobs
- BA
Space Security Cooperation Analyst and Digital Solutions Integra with Security Clearance
NewBooz Allen Hamilton
Colorado Springs, CO🇺🇸$86.8k - $198k/yrOn-site22 hours agoAdministrative - BA
Cyber Automation Engineer with Security Clearance
NewBooz Allen Hamilton
McLean, VA🇺🇸$86.8k - $198k/yrOn-site22 hours agoDockerAWSMFA+4Technology - BA
Security Cooperation Logistics Analyst with Security Clearance
NewBooz Allen Hamilton
Washington, DC🇺🇸$53k - $108k/yrOn-site22 hours agoSupply Chain ManagementLogistics - BA
Cyber Wargame Analyst, Senior with Security Clearance
NewBooz Allen Hamilton
Fort Meade, MD🇺🇸$112.8k - $257k/yrOn-site22 hours agoTechnology - SA
Senior Principal Cyber Information Systems Security Engineer with Security Clearance
NewSAIC
Norfolk, VA🇺🇸$160.0k - $200k/yrHybrid22 hours agoTechnology - BS
Senior AI Security & Governance Engineer
NewBayOne Solutions
Greensboro, NC🇺🇸Hybrid22 hours agoAdministrative