Threat Detection and Security Monitoring: Develop, maintain, and improve detection rules, alerts, dashboard, and monitoring workflows across infrastructure, cloud services, identity systems, endpoints, and application platforms.
Incident Response Coordination: Participate in incident response activities, including triage, investigation, containment, remediation coordination and post-incident analysis.
Help ensure incidents are handled consistently and that lessons learned lead to concrete improvements.
SIEM and Security Tooling Operations: Operate and improve security monitoring tooling, including SIEM, log aggregation, alerting, vulnerability management, and related detection and response platforms. Work to reduce false positives while improving visibility into meaningful risks.
Threat Hunting and Investigation: Proactively investigate suspicious activity, anomalous behavior, and emerging threats affecting infrastructure and services. Translate findings into improved detections, response procedures, and hardening recommendations.
Security Operations Process Improvement: Create and maintain incident response playbooks, escalation procedure, actionable security guidance, and operational documentation to cloud operations, product development, and systems engineering teams. Help define practical security workflows that can be followed during both routine operations and active incidents.
Infrastructure Security Hardening: Collaborate with the systems engineering team to identify and remediate security weaknesses in cloud, container, Linux, network, identity, and service configurations.
On-Call work: Some events may require time outside of regular hours to respond appropriately.
Disaster Recovery Execution: Actively participate in comprehensive disaster recovery planning, business continuity strategy formulation, and live simulations/exercises to validate system resilience and team readiness.
3–5+ years of professional experience in an active security operations, infrastructure security, incident response, or a related operational security role.
Hands-on experience with security monitoring, alert triage, incident investigation, and response workflows.
Experience with SIEM, log aggregation, alerting, or detection engineering tools.
Strong understanding of Linux systems, networking fundamentals, identity and access management, and common infrastructure attack techniques.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Familiarity with containerized environments (Docker, Kubernetes, OKD/OpenShift), and public cloud ecosystems (AWS, Azure, or GCP).
Experience writing or maintaining operational runbooks, response procedures, detection rules, or incident documentation.
Working knowledge of common security frameworks and attacker techniques, such as MITRE ATT&CK, CIS Controls, or similar.
Relevant certifications are highly desirable (e.g., CompTIA Security+, CEH, CSSLP, CCSP, or cloud security certifications).
Strong analytical and troubleshooting skills, especially under time-sensitive operational conditions.
Clear communication skills with the ability to articulate complex security incidents, risks, and remediation steps to both technical and non-technical stakeholders.
Strong diplomatic skills capable of facilitating alignment between developers and strict security compliance goals.
About Eclipse Foundation, Inc.
Software & SaaS96 employeesFounded 2004
International nonprofit association providing vendor-neutral governance and infrastructure for global open-source software collaboration.