Oath has flagged the Paranoids Security Operations Intern job as unavailable. Let’s keep looking.

Principal Cloud Security Operations Analyst

Pega Systems

Meet Our Team:

The Pega Cloud Security Operations Center (CSOC) is a team of information security professionals charged to protect Pega’s commercial cloud assets and offerings. Our mission is to protect Pega Cloud by deterring, detecting, denying, delaying, and defending against internal and external security threats. The CSOC provides detection, monitoring, and incident response services for Pega Cloud.

Picture Yourself at Pega:

Pega is a leader in customer engagement and digital process automation offering a commercial SaaS version of our industry-leading platform to our global clients. As a Principal Cloud Security Operations Analyst, you will play a critical role in ensuring the confidentiality, integrity, and availability of Pega's commercial cloud infrastructure and assets. You will be key in the continuous monitoring and protection of all global cloud security operations at Pega as well as a leader during incident response efforts. As a key member of a team consisting of highly capable and talented problem-solving analysts and engineers, you’ll help develop processes that drive proactive, automated detection and incident response tactics to support the quick resolution of cloud security events and incidents. 

You will accomplish this by collaborating with cross-functional teams – including other security analysts, threat detection engineers, vulnerability analysts, security engineers, system administrators, and developers – to proactively identify potential security risks and vulnerabilities within our cloud environment. You will leverage your strong analytical skills to assess and prioritize threats, applying your deep knowledge of industry best practices and cloud security frameworks.

As a Principal Cloud Security Operations Analyst at Pega, you’ll contribute to the success of our globally recognized brand. Your efforts will directly impact the security and trust our clients place in us, as we help them transform their business processes and drive meaningful digital experiences. So, picture yourself at Pega, where your expertise in cloud security is valued, and your passion for protecting data is celebrated. Join us in shaping the future of secure cloud operations and make a lasting impact on the world of technology.

What You'll Do at Pega:

  • Function as a trusted advisor for the CSOC staff and the larger security organization within Pega’s Technical Services Operations (TSO) branch
  • Perform security monitoring of Pega Cloud commercial environments using multiple security tools/dashboards
  • Lead security investigations to identify indicators of compromise (IOCs) and better protect Pega Cloud and our clients from unauthorized or malicious activity
  • Function as the lead incident responder during incident response activities 
  • Take the lead in developing and enhancing security incident response plans, conducting thorough investigations, and recommending remediation measures to prevent future incidents.
  • Work closely with stakeholders to design and implement robust security controls, detection mechanisms, and incident response methodologies ensuring compliance with relevant regulations and standards
  • Perform regular, structured threat hunts for adversarial activities within Pega Cloud to identify evidence of attacker presence that may have not been identified by existing detection mechanisms
  • Contribute to standard operating procedure (SOP) and policy development for CSOC detection and analysis tools and methodologies
  • Assist the threat detection team in developing high confidence Splunk notables focused on use cases for known and emerging threats, based on hypotheses derived from the Pega threat landscape
  • Develop dashboards, Splunk applications, and other non-alert based content to maintain and improve situational awareness of Pega Cloud’s security posture
  • Assist in the development of playbooks for use by analysts to investigate both high confidence and anomalous activity
  • Mentor and coach the CSOC analyst staff regarding analysis, investigations, incident response, threat hunting/detection, and other related operational work
  • Work closely with cloud and security engineering teams to ensure that the CSOC has all necessary logs to properly monitor our cloud environments, detect potential threats, perform digital forensics, and adhere to the relevant compliance mandates

Who You Are:

You have an insatiable curiosity with an inborn tenacity for finding creative ways to deter, detect, deny, delay, and defend against bad actors of all shapes and sizes. You have been in the “security trenches” and you know what an efficient security operations center looks like. You have conducted in-depth analyses of various security events/incidents, performed comprehensive incident response efforts, developed new methods for detecting and mitigating badness wherever you see it, and helped build successful security teams. You bring a wealth of cloud security experience to the table and are ready to harness that expertise to dive into cloud-centric, technical analysis and incident response to make Pega Cloud the most secure it can be. 

You have a rich history of success in the information security industry. 

Your list of accolades include:

  • SANS, Offensive Security, or other top-tier industry recognized technical security certifications focused on analysis, detection, and/or incident response
  • Automation experience leveraging tool Application Programming Interfaces
  • Industry recognition for identifying security gaps to secure applications or products 

What You've Accomplished:

  • A demonstrated working knowledge of cloud architecture, infrastructure, and resources, along with the associated services, threats, and mitigations
  • Extensive operational experience analyzing security detections, advisories, and raw logs in multi-cloud (AWS/GCP/Azure) environments
  • Extensive operational experience performing investigations, threat hunts, and incident response within Linux and Windows hosts as well as AWS, GCP, and related Kubernetes environments (EKS/GKE)
  • Extensive operational experience with MITRE ATT&CK and how it applies to detection and response
  • 4+ years of operational Splunk usage – primarily for analysis, investigations, and incident response including an in-depth use of Splunk Enterprise Security (ES); creating working Knowledge Objects such as correlation searches, notable events, dashboards, etc. 
  • 4+ years of operational AWS usage including knowledge and analysis of CloudTrail, CloudWatch, GuardDuty, VPCFlow, Trusted Advisor, and WAF logs.
  • 2+ years of operational GCP usage including knowledge and analysis of Cloud Audit, Security Command Center, VPCFlow, and WAF logs
  • 2+ years of operational experience with EDR/XDR platforms and related analysis and response techniques
  • Solid working knowledge of the Linux OS and common attack methodologies 
  • Solid working knowledge of MITRE ATT&CK framework and the associated TTP's and how to map detections against it, particularly the cloud matrix portion 
  • Experience developing standard operating procedures (SOPs), incident response plans, runbooks/playbooks for repeated actions, and security operations policies
  • A solid foundational understanding of computer, OS, and network architecture concepts, and various related exploits
  • Excellent verbal and written communication skills, including poise in high pressure situations
  • Demonstrated ability to work in a team environment and foster a healthy, productive team culture
  • Bachelor’s Degree in Cybersecurity, Computer Science, Data Science, or related field

Pega Offers You:

  • A robust global benefits program including a competitive pay + bonus incentive and Employee Equity in the company
  • An innovative, inclusive, agile, flexible, and fun work environment full of opportunities to learn and grow
  • At Pega, we believe in continuous learning and growth. You will have access to cutting-edge technologies and training resources, allowing you to stay at the forefront of cloud security.
  • Pega's culture fosters collaboration, innovation, and work-life balance. You’ll participate in team-building activities and engage in open discussions during daily/weekly team meetings
  • You will have the flexibility to work remotely when needed, allowing you to maintain a healthy work-life integration
  • Gartner Analyst acclaimed technology leadership across our categories of products
Read Full Description
Confirmed 42 minutes ago. Posted 30+ days ago.

Discover Similar Jobs

Suggested Articles