← Back to results

mitre-att-ck jobs in San Diego

$105,400 – $207,800 · Posted 1 day ago

Design and implement secure, scalable Google SecOps architectures for SIEM and SOAR deployments aligned with enterprise security policies and regulatory requirements (GDPR, PCI DSS). Lead log ingestion pipelines using data fabric technologies, develop threat detection content, translate security operations into automated SOAR playbooks, and mentor junior team members.… Requires 7+ years in security operations or threat detection engineering, hands-on experience with Google Chronicle/Siemplify, Python automation, Logstash/Gostash, ETL technologies (Cribl, Bindplane, Kafka), and familiarity with security frameworks like MITRE ATT&CK.

San DiegoLast seen today
Posted 1 day ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen today
$134,500 – $265,100 · Posted 2 days ago

Lead security operations and threat detection engineering for enterprise clients using Google SecOps (Chronicle SIEM and Siemplify SOAR). Design and deploy log ingestion pipelines, develop threat detection rules, translate SOC processes into automated playbooks, and manage integrations across security platforms.… Mentor junior SOC engineers and collaborate with threat detection teams to reduce alert fatigue and scale response capabilities.

San DiegoLast seen today
$69,300 – $158,000 · Posted 7 days ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, with responsibility for Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Guide a small engineering team through technical workstreams that strengthen cloud security, modernize cyber operations, improve security telemetry, and advance continuous security assurance aligned with federal requirements.… Move fluidly between architecture and hands-on engineering to drive work from concept through operational adoption, including identifying configuration drift, automating response, and creating measurable evidence of security control effectiveness. Modernize security data and logging architectures to optimize telemetry collection and maintain visibility against sophisticated threats.

San DiegoLast seen 5 days ago
$157,675 – $238,500 · Posted 14 days ago

Build, deploy, and continuously improve MITRE ATT&CK–aligned threat detections across cloud, endpoint, identity, email, and application telemetry. Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement, advancing a detection-as-code platform with version control, peer review, automated testing, and CI/CD.… Evaluate AI-powered security capabilities including LLMs, anomaly detection, and response automation. Partner with Security Operations on investigations, incidents, and detection maintenance.

San DiegoLast seen 12 days ago
$117,000 – $130,000 · Posted 17 days ago

The Cybersecurity Analyst leads Bumble Bee's day-to-day cybersecurity operations, investigating and responding to security incidents, hunting threats, and tuning detection tooling. The role owns the full incident response lifecycle, manages vulnerability remediation, optimizes SIEM platforms, conducts security risk assessments for platforms and vendors, and maintains compliance through access control reviews and policy development.… The analyst builds incident response playbooks, monitors threat intelligence and CVE disclosures, and advises on third-party cyber risk. The position requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management, MITRE ATT&CK framework, and knowledge of NIST, SOC, and ISO standards.

San DiegoLast seen 15 days ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across Azure security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, and Infrastructure as Code. You will architect cloud security solutions, modernize security data and logging architectures, automate configuration-drift detection and response, and guide a small engineering team from concept through operational adoption.… The role requires 5+ years of Azure security engineering experience, expertise with Azure Government, Sentinel, Defender, Azure Monitor, Terraform, and cloud identity platforms, plus the ability to move between architecture and hands-on engineering work.

San DiegoLast seen 1 month ago
$86,900 – $198,000 · Posted 1 month ago

Lead the design and implementation of advanced security capabilities within Microsoft Azure Government, driving technical workstreams across cloud security architecture, Microsoft Sentinel, Defender, Azure Policy, identity, logging, DevSecOps, and Infrastructure as Code. Modernize security data and logging architectures to collect appropriate telemetry, identify configuration drift, validate security controls, automate response, and create measurable evidence of security posture.… Guide a small engineering team from concept through operational adoption, balancing architecture-level strategy with hands-on engineering execution. This role requires 5+ years of Azure security experience, hands-on expertise with Sentinel, Defender, and Azure Monitor, and the ability to align solutions with federal security requirements.

San DiegoLast seen 1 month ago
$117,000 – $130,000 · Posted 1 month ago

The Cybersecurity Analyst owns Bumble Bee's day-to-day security operations, investigating and responding to incidents, hunting threats, and tuning detection tooling to close coverage gaps. Responsibilities include managing the full incident response lifecycle, optimizing SIEM platforms, conducting vulnerability assessments, performing access control audits, and building incident response playbooks and procedures.… The role requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management platforms, and hands-on knowledge of Windows/Linux, networking, and the MITRE ATT&CK framework. Success demands both technical operations expertise and cross-functional collaboration to strengthen security posture, ensure compliance, and assess third-party cyber risk.

San DiegoLast seen 1 month ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
$113,200 – $141,500 · Posted 1 month ago

This Cybersecurity Manager role owns vulnerability and exposure management, leads penetration testing, threat hunting, and threat intelligence programs. The position integrates AI and machine learning into security operations to enhance threat detection and anomaly identification, manages security tools and incident response, and ensures the security of AI/ML systems across the enterprise.… The candidate will develop automation scripts and SOAR workflows, conduct forensic investigations, and drive continuous improvement in the security posture. Required qualifications include 5+ years of cybersecurity experience, a relevant bachelor's degree, and an industry-recognized certification (Security+, SSCP, CCNP Security, CISSP, or equivalent).

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
$80,000 – $110,000 · Posted 1 month ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines.… The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 25 days ago
$80,000 – $110,000 · Posted 1 month ago

This role is a hands-on cybersecurity engineer responsible for securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications. Key duties include vulnerability scanning and penetration testing, threat modeling, Web Application Firewall (WAF) deployment and tuning, CI/CD security integration (SAST, DAST, SCA), incident response, and compliance support.… The engineer will work closely with DevOps and application teams to embed security controls, conduct code and architecture reviews, and provide risk-based guidance. Required experience includes 3–5+ years in cybersecurity or security engineering, hands-on SIEM/EDR/vulnerability management tools, cloud platforms, WAF configuration, and scripting (Python, Bash, PowerShell).

San DiegoLast seen 1 month ago
Posted 1 month ago

This is a hands-on security engineering role focused on running Saronic's cyber threat intelligence program. The engineer will track nation-state and advanced criminal adversaries targeting the defense industrial base, operationalize indicators and TTPs into detections and hunts, produce finished intelligence products, and fuse external threat feeds with internal telemetry to prioritize real exposures.… The role requires 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis with demonstrable experience tracking sophisticated or state-sponsored adversaries.

San DiegoLast seen 29 days ago