À propos de ce poste Security Operations Engineer, Cloud & Endpoint Defense chez Schoox, LLC
About Schoox
Schoox is a uniquely agile learning and talent development platform. We help businesses of all sizes shift from traditional, compliance-based training to an approach that unlocks and accelerates employee potential and business growth. Our platform goes beyond basic learning management, enabling companies to measure the true impact of their learning and development programs on overall business performance.
In a competitive market with more than 500 providers, Schoox has rapidly become one of the fastest-growing talent development platforms due to our disruptive product vision, our commitment to reimagining corporate training, and our passion for fostering happy customers through happy employees.
Position Description
We are seeking a hands-on, motivated, and detail-oriented Security Operations Engineer to join our Security Operations team. This role will work under the Security Operations Manager and help operate, tune, and improve key security tools across endpoint, cloud, and edge security.
This is not a traditional SOC analyst role focused only on watching alert queues. Our existing tooling, agents, dashboards, and automated workflows already support much of the initial review, triage, and log investigation process. We are looking for someone who can bring strong technical judgment, curiosity, work ethic, and follow-through to help maintain and improve our security operations function.
In this role, you will work with tools such as CrowdStrike, AWS GuardDuty, and Cloudflare rules/WAF. You will help review security findings, investigate suspicious activity, tune alerts and configurations, support incident response, and collaborate closely with DevOps and infrastructure teams.
The ideal candidate is hungry to learn, takes pride in doing excellent work, and wants to grow into a highly capable security operations professional. We want someone who is not satisfied with simply closing tasks, but who wants to understand systems deeply, improve processes, reduce noise, strengthen coverage, and contribute to a high-performing security function.
How You Will Impact Schoox
Security Tool Operations: Operate, maintain, and tune key security platforms, including CrowdStrike, AWS GuardDuty, Cloudflare WAF/rules, and related security tooling.
Tool Configuration & Tuning: Configure rules, alerts, policies, exceptions, thresholds, and workflows under the guidance of the Security Operations Manager.
Finding Review & Triage: Review security findings that require human judgment, validate severity, investigate context, and determine appropriate next steps.
Incident Response Support: Support incident response activities, including triage, investigation, containment coordination, remediation tracking, and post-incident documentation.
Cloud & Infrastructure Investigation: Investigate suspicious activity across AWS, endpoint, network, application, and edge security telemetry.
DevOps Collaboration: Work closely with DevOps and infrastructure teams to validate findings, gather context, implement remediations, and improve security visibility.
Security Operations Improvement: Identify gaps in logging, visibility, alert quality, documentation, or process, and help improve the day-to-day effectiveness of security operations.
Runbooks & Documentation: Help maintain and improve security runbooks, investigation notes, operational procedures, and incident response documentation.
Tool Health & Coverage: Monitor security tool health, endpoint agent status, cloud detection coverage, WAF effectiveness, and configuration consistency.
Continuous Learning: Stay current with evolving threats, cloud security practices, endpoint defense, incident response methods, and security tooling capabilities.
Requirements
- 3-5 years of experience in security operations, cloud security, incident response, detection and response, infrastructure security, or a related security engineering role.
- Hands-on experience with endpoint security tools such as CrowdStrike Falcon or similar EDR/XDR platforms.
- Experience with AWS security services, especially GuardDuty. Familiarity with CloudTrail, IAM, VPC networking, CloudWatch, and cloud logging is strongly preferred.
- Experience with WAF, CDN, or edge security controls. Cloudflare experience is highly valuable.
- Strong incident response fundamentals, including triage, investigation, containment, remediation, and documentation.
- Ability to read and interpret logs from endpoint, cloud, web, network, and application sources.
- Comfortable working with DevOps, infrastructure, and engineering teams.
- Strong technical curiosity and desire to understand how systems, alerts, and security controls work.
- High ownership mindset with strong follow-through and attention to detail.
- Strong work ethic and pride in delivering high-quality work.
- Hunger to learn, improve, and grow within the security operations discipline.
- Ability to distinguish real risk from noise and make practical, business-aware decisions.
- Clear written and verbal communication skills, especially when documenting findings, explaining issues, or coordinating response activities.
- Ability to work independently and thrive in a remote work environment.
Nice to Have
- Experience with SIEM, SOAR, detection engineering, or security automation.
- Experience with scripting, APIs, Terraform, infrastructure as code, or automation workflows.
- Familiarity with AWS Security Hub, AWS Config, IAM Access Analyzer, CloudTrail Lake, or similar services.
- Experience contributing to incident response runbooks or operational security processes.
- Experience in SaaS, cloud-native, or DevOps-heavy environments.
- Relevant certifications such as CrowdStrike, AWS Security Specialty, Security+, CySA+, GIAC, or similar are helpful but not required.
What Success Looks Like
- Security tools are operating reliably and are continuously tuned.
- Alert noise is reduced while meaningful detection coverage improves.
- Security findings are reviewed with good judgment and appropriate urgency.
- Incidents are investigated carefully, documented clearly, and escalated when needed.
- DevOps and infrastructure teams receive practical security support during investigations and remediation.
- Security operations processes become more efficient, better documented, and easier to repeat.
- The Security Operations Manager has a reliable, capable partner who can execute day-to-day security operations work with care, curiosity, and accountability.
Benefits
- Competitive salary and productivity-based bonus
- Stock options
- Prepaid meal card benefits
- Free physiotherapy sessions
- Free English lessons with an in-house instructor
- Gifts for birthdays, weddings, and baby arrivals
- Additional PTO for each child, plus maternity and paternity leave
- Flexible remote working
- Lego workshops as part of our development process
- Continuous learning and development opportunities
- Employee Assistance Program (EAP)
Schoox is most decidedly an equal-opportunity employer. We want applicants of diverse backgrounds and hire without regard to race, color, gender, religion, national origin, ancestry, citizenship, disability, age and sexual orientation.