Resumo da vaga

Security Operations Engineer II (Employer of Record)

Requisitos e responsabilidades

Conteúdo da vaga extraído em seções para revisão mais rápida.

Outcomes and Activities

  • Operate and tune enterprise security tools (EDR, SIEM/SOAR, WAF/proxy, email security).
  • Manage proxy filtering policies, exceptions, SSL inspection, and performance troubleshooting.
  • Build automation and playbooks (Python/PowerShell, SOAR, APIs) to streamline SecOps tasks.
  • Implement CI/CD pipelines and Infrastructure-as-Code workflows for consistent, auditable security configuration changes.
  • Author and tune detection rules; improve signal quality and reduce false positives.
  • Maintain and author health dashboards, uptime/coverage metrics, and change governance documentation.
  • Conduct knowledge transfers through runbooks, how-to guides, tabletop exercises, and lunch & learn training sessions.
  • Maintain upgrade schedules, license compliance, configuration baselines, and key/secret rotations.
  • Administer URL/category policies, SSL inspection, identity-aware policies, geo/risk-based controls, and performance troubleshooting.
  • Analyze block events for false positives; measure impact; retire exceptions on schedule and report residual risk.
  • Build and maintain an automation backlog in partnership with SecOps, prioritizing high-frequency, high-toil tasks.
  • Provide on-call support for tooling availability and ingestion/normalization issues.
  • Report on metrics (uptime, coverage, MTTR, lead time, change success rate, exception aging).
  • Keep documentation, diagrams, and asset inventories current.
  • As needed, monitor and respond to alerts raised by various toolsets as part of an ongoing 24/7 Security Operations Center.
  • Report outages or incidents following guidelines and procedures.
  • Detect, analyze, and respond to incidents, coordinate with other stakeholders for containing, eradicating, and recovering from an incident.
  • Assist in developing testing criteria to implement new signatures/rules.

Outcomes and Activities

  • Perform all other duties as assigned.
  • Participate in on-call rotations, including nights, weekends, and holidays.
  • Remains compliant with our policies, processes and legal guidelines.
  • Works primarily remotely with some occasional travel to a Credit Acceptance building.

Competencies:

  • Customer Empathy: Customer Empathy is the ability to understand the perspectives, pain points, and experiences of customers. It involves actively putting oneself in the customer’s shoes, comprehending their needs and challenges, and using that understanding to provide a better, more customer-centric experience.
  • Engineering Excellence: Engineering Excellence is about bringing great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business. This involves the pursuit and achievement of high standards, best practices, innovation, and superior solutions.
  • One Team: A One Team mindset refers to a collaborative approach across the organization, where individuals work together seamlessly, without boundaries, as a single, cohesive team. Shared goals, open communication and mutual support create a sense of collective purpose. This enables teams to navigate challenges and pursue shared objectives more effectively.
  • Owner’s Mindset: Owner’s Mindset involves adopting a set of behaviors that reflect a sense of responsibility, accountability, strategic thinking, and a proactive approach to managing your domain. As an owner, you understand the business and your domain(s) deeply and solve for the right outcome for the domain(s) and the business.

Requirements:

  • Bachelor’s degree in computer science, Information Systems, Data Science or closely related field of study or equivalent experience
  • Minimum 2 years of experience in cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), operations incident response, network security or security engineering
  • Basic experience administering, deploying and managing security tools.
  • Basic experience operating WAF/proxy and SIEM/SOAR.
  • Scripting in Python and/or PowerShell and building API integrations; JSON/YAML proficiency.
  • CI/CD and Git workflows; Infrastructure-as-Code for security configurations.
  • Basic understanding of TLS/SSL, HTTP, identity-aware policies, and egress/ingress routing.
  • Documentation discipline and change management (ITIL basics).
  • Ability to produce formal and informal reports, briefings, and analysis of security controls.
  • Experience with Endpoint Detection and Response (EDR) or Intrusion Detection System or Intrusion Prevention System (IDS/IPS) monitoring tools.
  • Understanding of MITRE ATT&CK Framework and Cyber Kill Chain flow
  • Understanding of incident response processes and risk management.

Preferred:

  • Actively hold one or more of the following certifications:GSEC, GCIA/GCED, GCDA, AZ-500, SC-200/SC-100, Network+ or CCNA.Web Application Firewall rulesetsUtilizing automation through Infrastructure as Code.Detection engineering (KQL/SPL), log pipelines, and data normalization.Zero Trust architecture and ZTNA posture policies.
  • GSEC, GCIA/GCED, GCDA, AZ-500, SC-200/SC-100, Network+ or CCNA.
  • Web Application Firewall rulesets
  • Utilizing automation through Infrastructure as Code.
  • Detection engineering (KQL/SPL), log pipelines, and data normalization.
  • Zero Trust architecture and ZTNA posture policies.
  • Understands Credit Acceptance’s business model, operations and business terminology.

Details

  • GSEC, GCIA/GCED, GCDA, AZ-500, SC-200/SC-100, Network+ or CCNA.
  • Web Application Firewall rulesets
  • Utilizing automation through Infrastructure as Code.
  • Detection engineering (KQL/SPL), log pipelines, and data normalization.
  • Zero Trust architecture and ZTNA posture policies.

Knowledge and Skills:

  • Knowledge of Common Vulnerabilities and Exposures (CVEs), cyber threats, and vulnerability mitigation strategies.
  • Understanding of what constitutes network risk, cyberattacks, and the relationship between threats and vulnerabilities
  • Demonstrates pride in work with a high attention to detail and a sense of urgency in meeting goals
  • Critical thinking and proactive problem-solving skills
  • Quick learner with the ability to apply new concepts effectively
  • Skilled at managing multiple priorities and optimizing resources
  • Self-motivated with the ability to identify and act on tasks independently.
  • Clear and effective communicator, both written and verbal, tailored to the audience
  • Influences without authority and demonstrates leadership in cross-functional settings
  • Synthesizes complex information from multiple sources to drive sound decisions and the best possible outcomes
  • Actively listens and understands context to respond appropriately
  • Recognizes and escalates risks through appropriate channels in a timely manner.

  • You will be legally employed in India through our EoR partner
  • While your legal employer is the EoR partner, you will work full-time and be fully aligned to Credit Acceptance
  • Your day-to-day work, responsibilities, and performance expectations will be consistent with our global team members
  • You will receive locally compliant payroll, benefits, and statutory coverage through the EoR partner

Our Company Values:

  • Positive by maintaining resiliency and focusing on solutions.
  • Respectful by collaborating and actively listening.
  • Insightful by cultivating innovation, accumulating business and role specific knowledge, demonstrating self-awareness and making quality decisions.
  • Direct by effectively communicating and conveying courage.
  • Earnest by taking accountability, applying feedback and effectively planning and priority setting.

Expectations:

  • Regularly overlap with U.S. business hours to support collaboration with global team members.
  • Remain compliant with our policies, processes and guidelines
  • All other duties as assigned
  • Attendance as required by department
Vagas similares

Mantenha uma lista reserva.

Ver stack
FocoSecurity OperationsÁrea da vaga
Sinal de senioridadeMiddleNível do candidato
StackCI/CD, PythonSkills principais
Localização1 país aceitoElegibilidade

Stack

Use estas tags para comparar vagas remotas similares.

Elegibilidade de localização

Candidatos devem aplicar apenas quando o país do perfil estiver listado aqui.

Seu perfilPaís não definidoEntre para comparar seu país com esta vaga.

Fluxo de contratação

O WithMira mostra a vaga e depois envia candidatos para a aplicação da empresa.

1Confira fit da vaga, stack e elegibilidade de localização no WithMira.
2Abra a página de aplicação da empresa pelo link rastreado.
3Salve a vaga ou assine oportunidades similares antes de sair.
Aplicar no site da empresaSite da empresaAbrir link