Haystack
← Back to Jobs
Technology
WI

Cyber Security Operations Specialist

Wissen InfotechPittsburgh, PA🇺🇸United StatesPosted Sep 18, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Pittsburgh, PA, United States
Posted
22 hours ago
AWSMFASSOAzureBashGoogle CloudHelmPowerShellPythonWAFZero Trust

Job Description

Job Title: Cyber Security Operations Specialist

Experience: 12+ Years
Location: Pittsburgh, PA (Onsite) LOCALS ONLY

Work Mode: Client Location No Remote / No Relocation

The role will work closely with Security Operations Centre (SOC), Infrastructure, Cloud Engineering, DevOps, and Compliance teams to maintain a secure cloud ecosystem and strengthen the organization's cybersecurity posture.

Key Responsibilities

Security Monitoring & Incident Response

  • Monitor cloud environments for security threats, suspicious activities, and policy violations.
  • Investigate security alerts and incidents generated by SIEM, XDR, and cloud-native security tools.
  • Lead incident triage, containment, eradication, and recovery activities.
  • Perform root cause analysis and document incident findings and remediation actions.
  • Develop and maintain cloud security incident response playbooks.

Cloud Security Operations

  • Manage and improve cloud security posture across Azure, AWS, and Google Cloud Platform.
  • Identify and remediate cloud misconfigurations, vulnerabilities, and security gaps.
  • Monitor compliance with cloud security baselines, policies, and regulatory requirements.
  • Conduct cloud security risk assessments and security reviews.

Identity & Access Security

  • Monitor privileged access and enforce least-privilege principles.
  • Manage and review IAM policies, RBAC roles, MFA, Conditional Access, and Privileged Identity Management (PIM).
  • Investigate identity-based threats and unauthorized access attempts.

Threat Hunting & Detection Engineering

  • Perform proactive threat hunting across cloud workloads and services.
  • Develop detection use cases and custom analytics rules.
  • Leverage MITRE ATT&CK framework to enhance detection capabilities.
  • Identify emerging cloud threats and recommend security improvements.

Security Automation & Reporting

  • Support security automation initiatives using SOAR and scripting.
  • Develop dashboards, reports, and security metrics for management review.
  • Participate in cloud security governance and operational reviews.
  • Recommend process improvements to enhance cloud security operations efficiency.

Cloud security responsibilities

  • Understand and use corporate information security frameworks, policies, implementation, and support tools
  • Translate and evolve corporate security policies into cloud requirements
  • Identify compliance standards, craft policies and controls in support of standards, and implement Policy as Code (e.g. SOC-2 NIST 800-53, ISO 27001)
  • Use Policy as Code to enforce pre-deployment compliance on IaC scripts (e.g. static code analysis of TF, Helm)
  • Use Policy as Code to implement compliance and configuration monitoring of the running state of cloud environment.
  • Use Policy as Code to prevent out of band (bypassing pipeline) misconfiguration via cloud vendor policy engine (Azure, GCO, OCI Policy)
  • Evaluate and identify suite of security tooling to be used in partnership with product teams & Information Security for vulnerability scanning, alerting, & reporting (e.g. Azure Monitor, Azure Sentinel (SIEM), Azure Policy (policy enforcement), and Azure Security Center, CGP Security center, OCI cloud guard, CSPM etc)
  • Establish security support processes in partnership with product teams and Information.
  • Security for vulnerability scanning, alerting, and reporting, leveraging automated incident response and self-service tools, when possible
  • Provide resolution support to address security and compliance infrastructure exposures identified through monitoring and alerts.
  • Establish preventative procedures to resolve newly identified security exposures prior to impact.

Required Skills & Qualifications

Technical Skills

  • Strong experience with Microsoft Azure, AWS, or Google Cloud Platform.
  • Hands-on experience with:
    • Microsoft Sentinel
    • Microsoft Defender for Cloud
    • Microsoft Defender XDR
    • AWS Security Hub
    • CrowdStrike
  • Knowledge of cloud networking, firewalls, VPNs, WAF, and Zero Trust architecture.
  • Experience with Identity and Access Management (IAM), SSO, MFA, and RBAC.
  • Familiarity with Vulnerability Management and CSPM solutions.
  • Working knowledge of PowerShell, Python, Bash, or KQL.
  • CSPM, KSPM, SSPM

Security Knowledge

  • Security Operations Center (SOC) processes.
  • Incident Response and Threat Hunting.
  • Security Monitoring and Log Analysis.
  • Cloud Security Best Practices.
  • MITRE ATT&CK Framework.
  • NIST Cybersecurity Framework.
  • CIS Benchmarks.
  • ISO 27001

Similar jobs