Logo for Schoox

Security Operations Engineer, Cloud & Endpoint Defense

Role overview

Qualifications

  • 3-5 years of experience in security operations, cloud security, incident response, detection and response, or related security engineering role
  • Hands-on experience with endpoint security tools such as CrowdStrike Falcon
  • Experience with AWS security services, especially GuardDuty
  • Strong incident response fundamentals

Responsibilities

  • Operate, maintain, and tune key security platforms including CrowdStrike, AWS GuardDuty, Cloudflare WAF/rules
  • Review security findings, validate severity, and determine appropriate next steps
  • Support incident response activities including triage and remediation tracking
  • Collaborate with DevOps and infrastructure teams to implement remediations and improve security visibility

About the company

Schoox logo

Schoox

Corporate Learning Platforms

Schoox is workplace learning software with a people-first twist. People aren’t cogs, and Schoox was designed for how humans actually learn. We keep learners curious by letting you deliver more kinds of content wherever they are, from the front line to the corporate office. And by making learning easy, accessible, rewarding, and fun, we help you get everyone more excited about their career development. Learners can “up” their skills, grow on the job, and get more done—and you can measure the impact of their awesome accomplishments. At Schoox, our culture is rooted in the Greek philosophy of Philotimo. We treat each other with empathy, respect, kindness, honesty, integrity, humility and compassion. Our schoox values are: Demonstrate Integrity, Pursue Excellence, Be Authentic, Practice Compassion and Stay Curious.

Company details

Company typeSME
IndustryCorporate Learning Platforms
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Schoox

Schoox is a uniquely agile learning and talent development platform. We help businesses of all sizes shift from traditional, compliance-based training to an approach that unlocks and accelerates employee potential and business growth. Our platform goes beyond basic learning management, enabling companies to measure the true impact of their learning and development programs on overall business performance.

In a competitive market with more than 500 providers, Schoox has rapidly become one of the fastest-growing talent development platforms due to our disruptive product vision, our commitment to reimagining corporate training, and our passion for fostering happy customers through happy employees.

Position Description

We are seeking a hands-on, motivated, and detail-oriented Security Operations Engineer to join our Security Operations team. This role will work under the Security Operations Manager and help operate, tune, and improve key security tools across endpoint, cloud, and edge security.

This is not a traditional SOC analyst role focused only on watching alert queues. Our existing tooling, agents, dashboards, and automated workflows already support much of the initial review, triage, and log investigation process. We are looking for someone who can bring strong technical judgment, curiosity, work ethic, and follow-through to help maintain and improve our security operations function.

In this role, you will work with tools such as CrowdStrike, AWS GuardDuty, and Cloudflare rules/WAF. You will help review security findings, investigate suspicious activity, tune alerts and configurations, support incident response, and collaborate closely with DevOps and infrastructure teams.

The ideal candidate is hungry to learn, takes pride in doing excellent work, and wants to grow into a highly capable security operations professional. We want someone who is not satisfied with simply closing tasks, but who wants to understand systems deeply, improve processes, reduce noise, strengthen coverage, and contribute to a high-performing security function.

How You Will Impact Schoox

Security Tool Operations: Operate, maintain, and tune key security platforms, including CrowdStrike, AWS GuardDuty, Cloudflare WAF/rules, and related security tooling.

Tool Configuration & Tuning: Configure rules, alerts, policies, exceptions, thresholds, and workflows under the guidance of the Security Operations Manager.

Finding Review & Triage: Review security findings that require human judgment, validate severity, investigate context, and determine appropriate next steps.

Incident Response Support: Support incident response activities, including triage, investigation, containment coordination, remediation tracking, and post-incident documentation.

Cloud & Infrastructure Investigation: Investigate suspicious activity across AWS, endpoint, network, application, and edge security telemetry.

DevOps Collaboration: Work closely with DevOps and infrastructure teams to validate findings, gather context, implement remediations, and improve security visibility.

Security Operations Improvement: Identify gaps in logging, visibility, alert quality, documentation, or process, and help improve the day-to-day effectiveness of security operations.

Runbooks & Documentation: Help maintain and improve security runbooks, investigation notes, operational procedures, and incident response documentation.

Tool Health & Coverage: Monitor security tool health, endpoint agent status, cloud detection coverage, WAF effectiveness, and configuration consistency.

Continuous Learning: Stay current with evolving threats, cloud security practices, endpoint defense, incident response methods, and security tooling capabilities.

Requirements

  • 3-5 years of experience in security operations, cloud security, incident response, detection and response, infrastructure security, or a related security engineering role.
  • Hands-on experience with endpoint security tools such as CrowdStrike Falcon or similar EDR/XDR platforms.
  • Experience with AWS security services, especially GuardDuty. Familiarity with CloudTrail, IAM, VPC networking, CloudWatch, and cloud logging is strongly preferred.
  • Experience with WAF, CDN, or edge security controls. Cloudflare experience is highly valuable.
  • Strong incident response fundamentals, including triage, investigation, containment, remediation, and documentation.
  • Ability to read and interpret logs from endpoint, cloud, web, network, and application sources.
  • Comfortable working with DevOps, infrastructure, and engineering teams.
  • Strong technical curiosity and desire to understand how systems, alerts, and security controls work.
  • High ownership mindset with strong follow-through and attention to detail.
  • Strong work ethic and pride in delivering high-quality work.
  • Hunger to learn, improve, and grow within the security operations discipline.
  • Ability to distinguish real risk from noise and make practical, business-aware decisions.
  • Clear written and verbal communication skills, especially when documenting findings, explaining issues, or coordinating response activities.
  • Ability to work independently and thrive in a remote work environment.

Nice to Have

  • Experience with SIEM, SOAR, detection engineering, or security automation.
  • Experience with scripting, APIs, Terraform, infrastructure as code, or automation workflows.
  • Familiarity with AWS Security Hub, AWS Config, IAM Access Analyzer, CloudTrail Lake, or similar services.
  • Experience contributing to incident response runbooks or operational security processes.
  • Experience in SaaS, cloud-native, or DevOps-heavy environments.
  • Relevant certifications such as CrowdStrike, AWS Security Specialty, Security+, CySA+, GIAC, or similar are helpful but not required.

What Success Looks Like

  • Security tools are operating reliably and are continuously tuned.
  • Alert noise is reduced while meaningful detection coverage improves.
  • Security findings are reviewed with good judgment and appropriate urgency.
  • Incidents are investigated carefully, documented clearly, and escalated when needed.
  • DevOps and infrastructure teams receive practical security support during investigations and remediation.
  • Security operations processes become more efficient, better documented, and easier to repeat.
  • The Security Operations Manager has a reliable, capable partner who can execute day-to-day security operations work with care, curiosity, and accountability.

Benefits

  • Competitive salary and productivity-based bonus
  • Stock options
  • Prepaid meal card benefits
  • Free physiotherapy sessions
  • Free English lessons with an in-house instructor
  • Gifts for birthdays, weddings, and baby arrivals
  • Additional PTO for each child, plus maternity and paternity leave
  • Flexible remote working
  • Lego workshops as part of our development process
  • Continuous learning and development opportunities
  • Employee Assistance Program (EAP)

Schoox is most decidedly an equal-opportunity employer. We want applicants of diverse backgrounds and hire without regard to race, color, gender, religion, national origin, ancestry, citizenship, disability, age and sexual orientation.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Security Engineer Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.