1

Sentinel Blue Jobs (NOW HIRING)

Cybersecurity Lead

San Jose, CA · On-site

$140 - $185/hr

This role will lead the Blue Team in managing and enhancing security monitoring tools, detection ... Azure Sentinel), EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft Defender), SOAR automation ...

Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...

Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...

CSIRT Analyst

Buffalo, NY

$111K - $125K/yr

Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that ... EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace ...

CSIRT Analyst

Buffalo, NY

$111K - $125K/yr

Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that ... EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace ...

Experiencia con SIEM como Splunk, QRadar o Microsoft Sentinel. * Capacidad de analisis de logs ... Certificaciones Security+, GCIH, Blue Team Level 1, GCIA o CISSP segun nivel. * Experiencia en SOC ...

Experiencia con SIEM como Splunk, QRadar o Microsoft Sentinel. * Capacidad de analisis de logs ... Certificaciones Security+, GCIH, Blue Team Level 1, GCIA o CISSP segun nivel. * Experiencia en SOC ...

Medical, Dental & Vision (Blue Cross Blue Shield & EyeMed) * Veracross LLC Fidelity 401(k) Plan - Managed by Sentinel Benefits Salary at Veracross is determined by a variety of factors including, but ...

Medical, Dental & Vision (Blue Cross Blue Shield & EyeMed) * Veracross LLC Fidelity 401(k) Plan - Managed by Sentinel Benefits Salary at Veracross is determined by a variety of factors including, but ...

Showing results 21-40

Sentinel Blue information

What is a Sentinel Blue?

Sentinel Blue professionals are cybersecurity experts who focus on monitoring, detecting, and responding to security threats within an organization's network. They typically work in Security Operations Centers (SOCs) and use specialized tools to analyze network traffic and identify potential vulnerabilities or attacks. Their primary goal is to protect sensitive data and maintain the integrity of IT systems by proactively identifying and mitigating security risks.

What are the key skills and qualifications needed to thrive as a Sentinel Blue?

I'm sorry, but 'Sentinel Blue' is not recognized as a real-world professional occupation, so I am unable to provide relevant career information.

What are some typical challenges faced by professionals in a Sentinel Blue team, and how can new hires best prepare for them?

Professionals in a Sentinel Blue team, which specializes in proactive cybersecurity defense and threat monitoring, often face challenges such as rapidly evolving cyber threats, high-pressure incident response situations, and the need to stay current with emerging technologies. New hires can best prepare by developing strong analytical skills, gaining familiarity with popular security information and event management (SIEM) tools, and actively participating in cybersecurity training or simulations. Collaboration with other IT and security teams is common, so effective communication and teamwork are also essential to succeed in this dynamic environment.

What is the difference between Sentinel Blue vs Security Guard?

AspectSentinel BlueSecurity Guard
CertificationsTypically requires security licenses and specialized trainingRequires security licenses, basic training often sufficient
Work EnvironmentCorporate, high-security facilities, or specialized environmentsVarious settings including retail, events, and residential areas
Employer & Industry UsageUsed by private security firms, corporations, and government agenciesCommonly employed by retail stores, malls, and private clients

Sentinel Blue often refers to a specialized security role with advanced training and specific industry applications, whereas Security Guard is a broader term for personnel providing general security services across various environments. Both roles require licensing, but Sentinel Blue typically involves more technical or high-security responsibilities.

More about Sentinel Blue jobs

What cities are hiring for Sentinel Blue jobs?

Cities with the most Sentinel Blue job openings:

What states have the most Sentinel Blue jobs?

States with the most job openings for Sentinel Blue jobs include:

Infographic showing various Sentinel Blue job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 74% Full Time, 13% Part Time, 10% Contract, and 1% Nights. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Cybersecurity Lead

A10 Networks, Inc.

San Jose, CA • On-site

$140 - $185/hr

Other

Re-posted 23 hours ago


Job description

Cybersecurity Lead

Cybersecurity Lead serves as a hands‑on technical leader responsible for uniting offensive and defensive security operations to continually improve the company’s ability to detect, respond to, and recover from cyber threats. This role will lead the Blue Team in managing and enhancing security monitoring tools, detection pipelines, and incident response processes, while also coordinating Red Team simulations that measure and improve the company’s defensive posture. Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the mission to emulate adversaries, strengthen controls, and transform findings into actionable defense improvements.

Key ResponsibilitiesBlue Team Operations and Tool Management
  • Lead and oversee the management, configuration, and tuning of security detection and response platforms, including SIEM (e.g., Splunk, PANW, or Azure Sentinel), EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft Defender), SOAR automation platforms, Network IDS/IPS, NDR, and threat intelligence platforms (TIPs).
  • Ensure all detection tools are integrated for end‑to‑end visibility across endpoints, cloud environments, and production systems.
  • Define standards for log collection, parsing, and correlation to enhance alert accuracy and reduce false positives.
  • Drive continuous tuning of detection rules, signatures, and use cases to align with MITRE ATT&CK and emerging threats.
  • Collaborate with IT and Engineering teams to ensure security telemetry is fully integrated into cloud and CI/CD environments.
  • Oversee threat hunting, alert triage, and incident response playbook execution across the security stack.
  • Partner with DevOps and infrastructure teams to embed security monitoring hooks into hybrid environments and new deployments.
Red Team and Offensive Security
  • Design and conduct controlled adversary emulation exercises to test detection and response capabilities.
  • Execute attack chains, including phishing, privilege escalation, persistence, and lateral movement, using real‑world TTPs.
  • Develop and maintain custom adversary scripts and payloads to simulate targeted threats.
  • Provide detailed post‑exercise reports with actionable defensive improvement recommendations.
  • Collaborate with Blue Team engineers to operationalize detections based on Red Team findings.
Incident Response and Continuous Improvement
  • Lead or co‑lead major incident response efforts, coordinating containment, investigation, and recovery.
  • Build and maintain detailed incident response runbooks, integrating lessons learned from purple team exercises.
  • Conduct root cause analysis and lead retrospectives that drive measurable improvements in detection and resilience.
  • Integrate threat intelligence and forensic insights into detection content and defensive playbooks.
  • Plan and execute adversarial simulations that validate threat detection, alert fidelity, and incident response readiness.
  • Develop the roadmap for continuous improvement of detection coverage, response automation, and control validation.
  • Serve as a technical escalation point for complex investigations, guiding both Red and Blue Team staff.
  • Translate technical results into executive‑level insights that demonstrate risk reduction and readiness improvement.
Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
  • 8+ years of cybersecurity experience, with proven leadership across Blue, Red, or Purple Team operations.
  • Demonstrated ownership of enterprise security detection tools, including SIEM, EDR/XDR, SOAR, and threat intel platforms.
  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and threat emulation frameworks.
  • Deep technical expertise in one or more of the following areas: Endpoint and network forensics; Cloud security monitoring (AWS, Azure, GCP); Scripting and automation (Python, PowerShell, Bash); Security engineering in hybrid or production environments.
  • Proven ability to lead incident response and purple team exercises from start to finish.
  • Certifications such as OSCP, GCFA, GCIH, GPEN, GXPN, or GCTI highly desirable.
  • Strong communication and leadership skills, with ability to engage both executive stakeholders and technical teams.
Preferred Experience
  • Experience in enterprise or production‑scale environments, ideally within SaaS, networking, or hybrid cloud infrastructures.
  • Familiarity with DevSecOps practices, CI/CD pipeline security, and cloud-native monitoring.
  • Prior experience mentoring Blue Team analysts and managing tool life cycles and vendor relationships.
  • Exposure to purple team automation frameworks (e.g., AttackIQ, Caldera, Scythe).
Compensation

Hybrid Targeted compensation guideline: $140,000 - $185,000. Compensation will vary based on number of factors, including market demand for specific skills, role type, job level, and individual qualifications. Final salary offers are determined by considerations including, but not limited to, subject matter expertise, demonstrated skill level, relevant experience, geographic location, education, certifications, and training.

Equal Opportunity Employer

A10 Networks is an equal opportunity employer and a VEVRAA federal subcontractor. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. A10 also complies with all applicable state and local laws governing nondiscrimination in employment.

#J-18808-Ljbffr