freehire launches on Product Hunt on 26 August.

Follow →

Staff SecOps Engineer

Open 23d

You'll be one of the most senior technical voices on the team: a hands-on generalist who can dig deep into any layer of the stack, step back to see the whole picture, and bring clear, calm judgment when the stakes are highest. You'll anchor critical-incident response, set the direction on detection and threat hunting, evolve the architecture and the Agentic SOC, and raise the bar across the team through standards, playbooks, and mentoring.

Responsibilities

  • Bring senior technical leadership to complex incidents across cloud, corporate, endpoints, identities, and data center environments
  • Lead complex investigations end to end including root cause analysis, forensics, timeline reconstruction, and remediation
  • Serve as a trusted escalation point and keep handling, escalation, and documentation rigorous and consistent
  • Set the direction of detection strategy, architecture, and methodology
  • Contribute to proactive threat hunting by turning CTI and OSINT into risks caught before they reach Ledger
  • Translate threat intel into concrete posture improvements
  • Drive evolution of the Splunk and Torq (SOAR) setup for detection, triage, and response
  • Focus on detection quality, data standardization (CIM, data models), and usability
  • Contribute to the architecture of the Agentic SOC and log/data pipeline
  • Help automate the team's reporting
  • Bring cloud-security judgment using AWS and EKS/Kubernetes
  • Use Wiz to prioritize exposure at scale
  • Define the standards, playbooks, and runbooks the team relies on
  • Grow senior and junior engineers through review, pairing, and knowledge sharing
  • Partner with Engineering, Infrastructure, IT, and Cloud to align operational security with company direction

Requirements

  • ~9 years or a track record that speaks for itself in security operations, incident response, and CSIRT with real depth in complex, end-to-end investigations
  • Ability to lead technically under pressure and stay structured when things are ambiguous
  • Hands-on SIEM experience, ideally Splunk, writing and refining queries for investigation and detection
  • Solid cloud-security fundamentals, ideally AWS, including IAM/identity, audit logs (CloudTrail, GuardDuty), and understanding of workloads, containers, and Kubernetes (EKS)
  • Comfort automating with Python, Bash, APIs, GitHub Actions, or a SOAR platform
  • Clear communication of complex topics, strong documentation habits, and sound judgment with sensitive information

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available