Job Description
Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it!
Who We Are
Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business.Â
Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.
Deepwatch recognition includes:
- 2023, 2022 and 2021 Great Place to Work® Certified
- 2023 and 2022 Forbes America’s Best Startup Employers
- 2023 and 2022 Fortress Cybersecurity Award
- 2023 $180M Series C investment from Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners of Vista Equity Partners
- 2022 Cigna Healthy Workforce Silver Designation
- 2022 Cybersecurity Excellence Award for MDR
Reporting directly to the Manager, SIEM Operations, the SIEM Administrator provides consistent and high quality support for the Deepwatch managed security platform as part of a 24/7 team delivering configuration, operation, management, monitoring, and optimization of all SIEM systems and resources within Deepwatch. The SIEM Administrator focuses heavily on the daily monitoring and administration of a variety of SIEM deployment models across many customer environments at a foundational level, employing the idea of “a mile wide and an inch deep.” Candidates must display aptitude and ability to adapt and stay positive in an ever evolving environment.Â
This position is virtual / remote working from a home office unless traveling to a corporate office. This position will have an assigned shift that may include nights and/or weekends.
If you want to be a part of a dynamic team that will leverage your skills to innovate and maximize customer experience, enable you to maintain a strong work life balance, and assist you in reaching your career goals within the Information Security industry, look no further - this is a great opportunity for you.Â
In this role, you’ll get to:
- Deliver frontline support to enhance our First Call Resolution rate, efficiently resolving issues prior to involving Tier 2 resources.Â
- Contribute to our 24/7 schedule, guaranteeing uninterrupted customer coverage and vigilantly monitoring critical production support for potential outages. Â
- Manage, monitor, and maintain SIEM deployments to include clustering and high availability scenarios
- Manage access accounts for a variety of customer environments
- Manage, monitor, maintain, and troubleshoot Linux and Windows systems to support SIEM
- Review infrastructure performance in AWS
- Monitor and manage performance of all deployed Splunk Enterprise systems
- Remediate critical log ingest gaps to support continuous security monitoring
- Communicate effectively with external customer contacts and internal leadership and fellow deepwatch experts
- Manage case request/incident statuses and provide follow up, based on SLAs, to internal and external customers driving efficient resolutions
- Interact professionally with customers to resolve issues, provide additional information, and answer questions through various channels including: Messaging platforms, phone, case systems, and email.
- Proactively identify and communicate environmental and platform risks to management, mitigating potential risks and minimizing exposure to unnecessary risks.
- Create and maintain documentation for customer environments, processes, and best practices
- Keep up-to-date with information security news, techniques, and trends
You’ll be successful in this role, if you:
- Have or be willing to obtain, in your first 6 months, SIEM Certifications (Splunk Core Certified Advanced Power User preferred) or be able to demonstrate foundational experience with SIEM administration
- Demonstrate basic administrative knowledge of SIEM infrastructure components and configurations including, but not limited to: Cluster Master, Deployer, Deployment Server, Heavy Forwarder, Universal Forwarder, and License Master in a at least one of the deployment models: public cloud, private cloud, and on-premise
- Have or be willing to obtain, within your first year, your CompTIA Linux+ certification and/or possess foundational demonstrable Linux System Administration skills (e.g., CentOS, RHEL, Ubuntu, etc.) including experience with file permissions, certificates, manipulation & editing of files, system tuning, security permissions, troubleshooting, and network connectivity
- Demonstrate a working knowledge in at least one of the following areas: Enterprise network administration, Enterprise Network Infrastructure administration, Cloud administration, Endpoint Engineering and Administration, Identity and Access Management, Security Operations Center (SOC), or SIEM Administration
- Respond to monitoring software alerts to ensure high availability of customer environments
- Provide high quality operational support while achieving business KPIs within a 24/7 operations team
- Consistently demonstrate and understand case management best practices
- Provide high quality operational support while achieving business KPIs within a 24/7 operations team
- Have strong written & verbal communication skills and an excellent customer service mentality
- Consistently deliver value as a member of a highly collaborative customer centric team
ITAR Compliance
This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following:
- A citizen of the U.S.;
- A lawful permanent resident of the United States;Â
- A person admitted to the United States as a refugee; or
- A person that has been granted asylum by the United States government.
The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment.
Statutory Pay Disclosure:
For applicants in NYC, CO, CA, RI, and WA, the salary range for this role is $93,500 to $132,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level.
#LI-KL1
What We Offer:
Deepwatch is excited to provide benefits designed to support team members and their families. Including:
- Medical, dental, vision, and disability insurance
- Flexible Time Off (FTO), 9 company holidays, sick leave and 8-Weeks Paid Parental Leave
- Unique professional development benefits, starting at $3,000 annually
- Wellness contests and monthly educational programs
- 401(K) retirement program with employer match
- Learn more here: Deepwatch Benefits
We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you. Please review our DEI Statement here.
Deepwatch welcomes and encourages applications from people with disabilities and accommodations are available on request for candidates taking part in all aspects of the selection process. Please inform your recruiter or contact [email protected] for further information.
All Deepwatch employees are expected to:
- Be interested in and able to work remotely from a home office when not at a corporate office
- Pass a pre-employment background and drug screen in accordance with applicable laws
Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law. Â In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.
By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information.Â
Explore More
Date Posted
11/15/2023
Views
39