Primary Responsibilities/Duties:
- Triage, investigate, and respond to security alerts and incidents from our SIEM and other monitoring tools, leading investigations and performing forensics on IT systems as necessary to rapidly identify and mitigate potential threats.
- Execute, develop, and document incident management runbooks and processes
- Prepare incident reports of analysis methodology and results.
- Prioritizes events using existing tools to correlate data for the purpose of reducing false positives and detecting threats.
- Analyze and tune security alerts and interpret events, as well as create new signals based on signatures and behavioral activities.
- Assist with implementation of counter-measures or mitigating controls
- Recognize potential, successful, and unsuccessful intrusion attempts and potential compromises through thorough reviews and analyses of relevant event detail and summary information.
- Partner with key stakeholders and communicate effectively to continuously improve the feedback loop of preparation, identification, analysis, containment, and post mortem activities.
- Prepare executive summaries and conduct briefings on significant investigations.
- Ability to prioritize competing tasks and responsibilities.
Additional Responsibilities/Opportunities for growth:
- Depending on your skillset and interest level, the following responsibilities are available to all members of the security team:
- Contribute to our Threat Modeling, Threat Hunting, and Threat Assessment efforts.
- Partner with engineering teams to promote secure coding practices.
- Pentesting and Red Team Operations.
You have:
- Expertise in building and operating security information/event management systems (SIEM), centralized logging, and enrichment solutions (Endpoint protection/detection, Network telemetry data, ELK, DataDog, SumoLogic, Snowflake, AWS and GCP services, HR systems, codebase infrastructure, build infrastructure).
- Expertise with Linux, Windows, and MacOS security and best practices.
- Practical experience working with and knowledge of AWS & GCP security best practices.
- Ability to automate workflows via scripting languages: Python, Go, & Shell.
- Superb communication skills and capacity; ability to partner effectively with diverse company stakeholders.
- Active and current knowledge of campaign behavior, trending threats, IoCs, TTPs, and mitigation techniques as blue team operations.
- Competency in integrating Threat data, enrichments, for higher-value outcomes and behavioral situational awareness.
- Industry certifications such as GCIH, GCIA, CFCE, GCFA and/or GCFE are a plus.
Personal Characteristics you have:
- Views security as an enabler, not an inhibitor to innovation
- Results oriented
- High level of integrity
- Ownership and accountability
- High level of autonomy, but still a team player
- Clear communication skills
- Creative problem solver
- Passionate about Security
Top Skills
What We Do
JumpCloud’s mission is to Make Work Happen®, providing simple, secure access to an organization’s technology resources from any device, or any location. The JumpCloud Open Directory Platform gives IT, security operations, and DevOps a single, cloud-based solution to control and manage employee identities and their devices, and apply conditional access controls based on Zero Trust principals. Since launching in 2012, our global user base has grown to more than 150,000 organizations, with more than 5,000 paying customers including Cars.com, GoFundMe, Grab, ClassPass, Uplight and Peloton. JumpCloud has raised over $400M from world-class investors including Sapphire Ventures, General Atlantic, Sands Capital, Atlassian, and CrowdStrike. Our teams are growing fast, too, and we're looking for talent across engineering, sales, customer success, marketing, product management, and more. Join our team of dedicated, passionate, and creative people who are eager to change the IT industry forever.
We live by our core values which are:
Build Connections
Think Big
1% Better Every Day
Why Work With Us
We offer an incredible opportunity to see your impact. Each team member gets an up close personal view and education into building a fast growing startup. We are transparent about what we are doing, how we are doing it, and the decisions that we are making. There is opportunity to progress and flexibility to find unique approaches to our business
Gallery
JumpCloud Offices
Remote Workspace
Employees work remotely.
JumpCloud is committed to being remote-first across the world. We have team members in most U.S. states and in 14 countries.









