Role Overview:
As the SecOps Security Engineer at Cellebrite, you will be part of a team of security professionals responsible for defining and executing our security operations strategy, driving initiatives to enhance our overall security posture. You will identify security issues and risks, develop mitigation plans, and implement security-focused tools and services. You will also be responsible for developing and interpreting security policies and procedures, delivering training materials, and evaluating and recommending new and emerging security products and technologies. Additionally, you will participate in tier 3 security operations support and incident handling.
Responsibilities:
- Design, implement, and maintain security tools and controls across endpoint, identity, cloud, and network layers.
- Identify security gaps and risks across the environment and develop and execute mitigation plans.
- Manage and tune security platforms including EDR/EPP, PAM/EPM, NAC, VPN, web Proxy, and identity providers (Okta, Entra ID).
- Administer and optimize Palo Alto firewall and Prisma Access (and Strata Cloud Manager, where applicable) policies and egress controls.
- Monitor cloud environments for misconfigurations and risk using CSPM/DSPM tooling (e.g., Wiz), across AWS and other cloud providers.
- Develop, document, and maintain security policies, procedures, and standards, and deliver related training materials to stakeholders.
- Provide tier 3 security operations support, including advanced troubleshooting and incident handling/response.
- Apply the MITRE ATT&CK framework to map threats, build detection logic, and inform mitigation strategies.
- Evaluate and recommend new and emerging security products and technologies to strengthen the organization's security posture.
- Conduct proof-of-concept (POC) evaluations on various security products, leading each POC end to end from scoping through evaluation and recommendation.
- Leverage AI-powered tools and automation (e.g., Claude Code, LLM-based workflows) to improve efficiency in security operations, while applying MCP and AI guardrail principles to ensure secure, governed use of AI tooling.
- Write and maintain scripts (Python, Bash, Batch) to automate security operations, reporting, and remediation tasks.
- Collaborate cross-functionally with IT, R&D, and compliance teams to align security initiatives with business needs.
- Mentor other team members as needed, sharing knowledge and best practices to strengthen overall team capability.