Coalfire

Security Operations Administrator

Join Coalfire in Denver as a Security Operations Administrator. Leverage ServiceNow for vulnerability management and SIEM monitoring. 1-2 years' experience required. Flexible work model and training reimbursement offered.

Department - JobBoardly X Webflow Template
Consulting
Job Level - JobBoardly X Webflow Template
Entry Level
ServiceNow Role Type:
ServiceNow Modules:
Department - JobBoardly X Webflow Template
DevOps
Department - JobBoardly X Webflow Template
IT Service Management
Department - JobBoardly X Webflow Template
Incident Management
Department - JobBoardly X Webflow Template
Security Operations
ServiceNow Certifications (nice to have):
Department - JobBoardly X Webflow Template
Certified Implementation Specialist - IT Service Management

Job description

Date - JobBoardly X Webflow Template
Posted on:
 
July 10, 2025

Coalfire is on a mission to make the world a safer place by solving clients' hardest cybersecurity challenges. We're looking for a Security Operations Admin to work on vulnerability management processes, drive compliance and security in cloud-based environments, and support SIEM monitoring and alerting to meet FedRAMP requirements.

Requirements

  • 1-2 years' experience in 24x7x365 production security operations
  • 1-2 years' experience participating in incident response and analysis activities
  • 1-2 years' experience with vulnerability management, compliance monitoring, or related security operations roles
  • Hands-on expertise with operating system, database, network, container, web application, and API vulnerability management
  • 1+ years of hands-on technical experience supporting cloud operations and automation in Azure, AWS, and/or GCP
  • Experience in Information Security with a focus on incident response and security engineering
  • Exposure to threat identification using SIEM tools, log sources, and forensics tools and techniques
  • Experience with ITSM solutions such as Jira and ServiceNow
  • Experience or familiarity with Tenable.sc, Nessus Pro, or Nexpose
  • Understanding of regular expression and query languages
  • Experience analyzing events or incidents to triage the issue
  • Fundamental skills and knowledge of Azure, AWS, or GCP
  • Knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS)
  • Ability to work efficiently with technical teams to investigate, prioritize, and remediate vulnerabilities
  • Familiarity with defining baseline configuration standards (for example, CIS Benchmarks) and reporting on compliance posture
  • Exposure to one SIEM platform (e.g., Splunk, Sentinel, ELK, LogRhythm, Sumo Logic) and enterprise antivirus (AV) solutions (e.g., Trend Micro, CrowdStrike, Microsoft Defender).
  • Experience working in large scale enterprise environments
  • Effective communication, organizational, and documentation skills, with an emphasis on providing timely updates and clear reports to clients

Benefits

  • Flexible work model
  • Paid parental leave
  • Flexible time off
  • Certification and training reimbursement
  • Digital mental health and wellbeing support membership
  • Comprehensive insurance options

Requirements Summary

1-2 years' experience in 24x7x365 production security operations, hands-on expertise with operating system, database, network, container, web application, and API vulnerability management, and 1+ years of hands-on technical experience supporting cloud operations and automation in Azure, AWS, and/or GCP