Responsibilities:
- Support the Onit security function during US Central Time business hours.
- Implement and manage cloud-native security tools and third-party solutions for threat detection and incident response.
- Define, maintain, and execute the Incident Response plan, investigating and resolving incident escalations.
- Perform regular risk assessments and vulnerability scans of cloud infrastructure, ensuring timely remediation.
- Collaborate with Dev, DevOps, and Infra teams to remediate identified vulnerabilities, discuss security best practices, and assist with security incident response.
- Analyze EDR alerts and logs to identify potential security incidents, taking appropriate action.
- Continuously evaluate and implement security tools and practices to enhance the security posture of the Onit environment.
- Assist with application security reviews and threat modeling.
- Assist with security awareness programs for employees regarding security best practices
Requirements:
- Minimum of 5 years of experience in information security, with at least 3 years focused on cloud security for enterprise SaaS applications.
- Proficient in AWS with a strong understanding of AWS networking/VPC, IAM, Security Groups, EC2, RDS, S3, and containers (EKS/ECS).
- Extensive hands-on experience investigating security incidents, along with the creation, management, and execution of security runbooks / playbooks.
- This includes the ability to search logs in CloudTrail, CloudWatch, VPC Flow logs, etc.
- Experience with tooling for network (e.g. Wireshark) and host forensics
- Knowledge of various AWS Native Security tools, security frameworks, and CSPM tools.
- Experience in security tools such as vulnerability scanners, IDS/IPS, SIEM, firewalls, and endpoint security monitoring.
- Experience with threat detection and threat intelligence.
- Must be proficient in Linux.
- Application security experience with an understanding of SAST, DAST, SBOMs, and other scans and artifacts to help improve application security posture
- Experience with AWS Guard Duty and CrowdStrike or equivalent.
- Strong communication, problem-solving, and collaboration skills.
Desired:
- Experience with Cloudflare and/or AWS WAF configurations.
- Automation experience with one or more of the following: AWS CLI, Bash, Python, Ansible to verify security configurations and automate runbooks is a plus.
- Experience with Microsoft Entra and Mimecast.
- Familiarity with security frameworks such as NIST CSF 2.0.
- Experience with container security (beyond EKS/ECS, e.g., image scanning tools like Trivy).
- Familiarity with CI/CD pipeline security.
- Knowledge of Zero Trust architecture.
- Certifications such as CCSP, AWS Security, OSCP, or equivalent are a plus.
Similar Jobs
What We Do
Onit is a global leader of enterprise software and artificial intelligence platforms and products for legal, compliance, sales, IT, HR and finance departments. Our software transforms best practices into smarter workflows, better processes and operational efficiencies. With a focus on enterprise legal management, matter management, legal spend management, contract lifecycle management and legal holds, we operate worldwide and help global companies and billion-dollar legal departments bridge the gap between systems of record and systems of engagement. Onit is the only company in our space with two platforms: Our leading no-code business process automation platform, Apptitude, and our business intelligence platform, Precedent. Apptitude allows customers to create, modify and deploy new software products and custom workflows. Onit’s legal AI platform, Precedent, enables our software products to read, write, and reason like a lawyer. Combined, the two platforms enable customers to digitally transform legal operations by automating processes, reducing costs and maximizing productivity with industry-leading cloud-based software.

.png)







