FlexHired LogoFlexHired
Logo of Cribl

Cribl

Security Operations Engineer

Job Summary

The Security Operations Engineer at Cribl is responsible for enhancing the company's security posture through incident management, threat detection, and developing detection logic across various security platforms. The role involves conducting security assessments, supporting incident response, and collaborating with threat intelligence teams to improve detection capabilities. The candidate should have expertise in security principles, detection rule development, scripting, and familiarity with security frameworks like MITRE ATT&CK. The position emphasizes cross-functional collaboration and continuous improvement of security processes within a remote-first, innovative environment.

Required Skills

Cloud Security
Security Frameworks
Threat Intelligence
Incident Response
OpenID
Security Assessments
Threat Hunting
SAML
SIEM
Threat Detection
EDR
MITRE ATT&CK
OAuth2
Detection Engineering
Security Tooling
Security Playbooks
SCIM
CSPM
Vulnerability Testing
Security Incident Management
Detection Rules Development
Security Data Lakes
Detections as Code
Zero Trust Networking
Scripting (Python, NodeJS, Ruby, Bash)
Purple Team Activities
Detection Optimization
Detection Tuning
Detection Integration

Benefits

Health Insurance
Paid Time Off
Dental Insurance
Vision Insurance
Life Insurance
Paid Holidays
Equity
401(k)
Short-term Disability
Discretionary Bonus
Fertility Treatment Benefit

Job Description

Cribl does differently.

What does that mean? It means we are a serious company that doesn’t take itself too seriously; and we’re looking for people who love to get stuff done, and laugh a bit along the way. We’re growing rapidly - looking for collaborative, curious, and motivated team members who are passionate about putting customers first. As a remote-first company we believe in empowering our employees to do their best work, wherever they are.

As the data engine for IT and Security many of the biggest names in the most demanding industries trust Cribl to solve their most pressing data needs. Ready to do the best work of your career? Join the herd and unlock your opportunity.

Why You’ll Love This Role

The Security Operations Engineer will be a pivotal member of Cribl’s Information Security team, primarily responsible for strengthening our security posture through robust security operations and advanced threat detection. You will lead security incident management, triage, and investigations, and be instrumental in developing innovative solutions to remediate current threats and proactively prevent future attacks. A key aspect of this role will be designing, implementing, and optimizing detection logic to identify sophisticated threats across our environment. You will partner closely with Product Security, IT, and Legal teams, and report to the Chief Information Security Officer.


As An Active Member Of Our Team, You Will...

  • Provide knowledge and experience in working with modern security principles e.g. security data lakes, detections as code, EDR, zero trust networking, and other security tooling, as well as demonstrated experience with incident response and management.
  • Utilize a strong understanding of common attack frameworks (e.g., MITRE ATT&CK) and how to map detections to TTPs
  • Understanding of authentication and authorization schemes such as SAML, OpenID, OAuth2, and SCIM
  • Experience scripting/coding in at least one of the following languages: Python, NodeJS, Ruby, Bash
  • Be the go-to technical subject matter expert on security, compliance, and assurance topics
  • Communicate ideas to technical and non-technical audiences
  • Comfortable with ambiguity, have a strong analytical acumen, self-motivated, able to work cross-functionally
  • We are a remote-first company and work happens across many time-zones – you may be required to occasionally perform duties outside your standard working hours


If You’ve Got It - We Want It

  • Monitoring security events and alerting via our security tooling, including MSSP, SIEM, AI, and CSPM tooling, to identify and triage potential threats
  • Developing, implementing, and maintaining high-fidelity detection rules and alerts within SIEM and other security platforms (e.g., EDR, Cloud Security tools) based on threat intelligence, MITRE ATT&CK framework, and identified risks
  • Conducting continuous tuning and optimization of existing detection logic to reduce false positives and improve detection efficacy
  • Responding to issues identified by our Cribl employees
  • Acting as a security incident response lead, including leveraging and improving detection capabilities during investigations
  • Building, enhancing, and managing security playbooks, incorporating detection engineering best practices
  • Conducting security assessments of corporate assets through vulnerability testing, threat hunts, and purple team activities, with a focus on identifying detection gaps and opportunities
  • Performing both internal and external security reviews of corporate properties e.g., the corporate website and enterprise applications
  • Leading security incident response tabletop exercises
  • Continuing to evolve and champion the use of Cribl products in our security tech stack to enhance detection, analysis, and response capabilities
  • Collaborating with threat intelligence teams to integrate new indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) into detection strategies
  • Experience with SIEM platforms like Panther is a plu,s and its detection capabilities
  • Familiarity with Wiz and cloud native security tooling for detection in AWS, Azure, or GCP
  • Relevant certifications in cloud security or incident response (e.g., SANS GIAC certifications)
  • Proven experience in developing, deploying, and maintaining detection rules (e.g., Sigma, YARA, Splunk SPL, KQL) across various security platforms


Salary Range
($172,600 - $207,100)

The salary for this role is dependent on geographic location. The salary offered within the range described will be based on the individual candidate’s job-related knowledge, skills, and experience. In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), equity, and eligibility for a discretionary company-wide bonus.


#LI-LK1
#LI-Remote

Bring Your Whole Self
Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us.

Interested in this job?

Application deadline: Open until filled

Logo of Cribl

Cribl

Cribl is built for IT and Security data and provides a unified data management platform for exploring, collecting, processing, and accessing that data at scale.

See more jobs
Date PostedJuly 30th, 2025
Job TypeFull Time
LocationRemote - United States
Salary$172,600 - $207,100
Exciting remote opportunity (requires residency in United States) for a Security Operations Engineer at Cribl. Offering $172,600 - $207,100 (full time). Explore more remote jobs on FlexHired!

Safe Remote Job Search Tips

Verify Employer Thoroughly

Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.

Never Pay to Get a Job

Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.

Safeguard Your Personal Information

Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.

Scrutinize Communication & Interviews

Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.

Beware of Unrealistic Offers

If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.

Insist on a Formal Contract

Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.

Related Jobs

Full Time
$175,000 - $210,000
Remote - United States
Full Time
$184,000 - $230,000
Remote - United States
Full Time
$190,000 - $221,000
Remote - United States
Full Time
$187,000 - $220,000
Remote - United States
Full Time
$200,000 - $225,000
Remote - United States

Subscribe Newsletter

Never miss a remote job opportunity. Subscribe to our newsletter today and receive exclusive job alerts, career advice, and industry insights delivered straight to your inbox.