1

Wazuh Jobs (NOW HIRING)

Deploy/tune Wazuh agents across hosts and workloads. * Configure pipelines from Wazuh Elastic Tines. * Write and maintain Elastic SIEM detection rules. SOAR Automation & AI SOC Buildout * Develop ...

Sr. DevSecOps Engineer

San Diego, CA · On-site

$120K - $150K/yr

Deploy/tune Wazuh agents across hosts and workloads. * Configure pipelines from Wazuh → Elastic → Tines. * Write and maintain Elastic SIEM detection rules. SOAR Automation & AI SOC Buildout

Senior Associate Support Engineer

OR · On-site +1

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Support SIEM operations in Splunk/Wazuh by querying logs, building dashboards, and tuning alerts. Scripting & automation * Write and maintain scripts to automate repetitive IT/Security tasks - log ...

Senior Associate Support Engineer

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Support SIEM operations in Splunk/Wazuh by querying logs, building dashboards, and tuning alerts. Scripting & automation * Write and maintain scripts to automate repetitive IT/Security tasks - log ...

IT Systems Support Technician

Johns Creek, GA · On-site

$65K - $75K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Exposure to SIEM/EDR tooling (Wazuh, Microsoft Defender for Endpoint) * Basic networking knowledge (DNS, DHCP, VPN troubleshooting) Compensation and benefits * Salary: $65,000 - $75,000 per year ...

Cyber Security Auditor

Albuquerque, NM · On-site

$101K - $137K/yr

... Wazuh, Elastic Stack, Splunk, Graylog • Support cybersecurity awareness and best practices across the company Required Qualifications • Bachelor's degree in Cybersecurity, IT, a related field, or ...

Cyber Security Auditor

Albuquerque, NM · On-site

$107K - $145K/yr

... Wazuh, Elastic Stack, Splunk, Graylog • Support cybersecurity awareness and best practices across the company Required Qualifications • Bachelor's degree in Cybersecurity, IT, a related field, or ...

Cyber Security Auditor

Albuquerque, NM · On-site

$101K - $137K/yr

Analyze system logs utilizing a variety of cybersecurity tools such as Wazuh, Elastic Stack, Splunk, Graylog * Support cybersecurity awareness and best practices across the company Required ...

Lead IT Engineer

Chicago, IL · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

Monitoring systems: e.g., Wazuh, Prometheus/Grafana/AlertManager * Asterisk/Twilio phone systems * HP managed switches/APs/RADIUS * Git/GitHub * Terraform/Ansible Leadership Experience You're a ...

Responsibilities : • Setting up Monitoring tools etc as needed. • Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. • Conduct initial ...

Network & Security Infrastructure Engineer

Columbia, MD · Hybrid

$119K - $158K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Wazuh, Crowdstrike) * Incident Response * Vulnerability Management * Elasticsearch / Kibana * Docker * Ansible * AWS networking * Google Cloud networking * Ability to obtain and maintain a security ...

next page

Showing results 1-20

Wazuh information

What are the key skills and qualifications needed to thrive as a Wazuh security analyst, and why are they important?

To thrive as a Wazuh Security Analyst, you need a solid background in cybersecurity, knowledge of intrusion detection systems, log analysis, and often a degree or certification in information security. Familiarity with the Wazuh platform, Linux systems, SIEM solutions, and scripting languages like Python or Bash is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you investigate threats and collaborate with IT teams. These skills are crucial for proactively identifying vulnerabilities, responding to incidents quickly, and maintaining robust organizational security.

What is a Wazuh engineer?

Wazuh engineers are IT professionals who specialize in deploying, configuring, and managing Wazuh, an open-source security monitoring and threat detection platform. They are responsible for setting up Wazuh to collect and analyze security data, detect vulnerabilities, and respond to security incidents. Their role often includes integrating Wazuh with other security tools, maintaining compliance, and providing support and training to other team members. Wazuh engineers play a crucial role in enhancing an organization's cybersecurity posture.

What are the typical responsibilities of a Wazuh engineer during a security incident?

A Wazuh engineer plays a crucial role during security incidents by monitoring real-time alerts, analyzing logs, and correlating events to identify potential threats. They are responsible for tuning detection rules to reduce false positives, investigating suspicious activities, and collaborating closely with IT and security teams to coordinate incident response. Additionally, Wazuh engineers often document incident findings and propose improvements to enhance the organization's security posture. This role requires a proactive approach and effective communication skills to ensure a swift and coordinated response.

What is the work of Wazuh?

A Wazuh professional is responsible for managing and maintaining the Wazuh security platform, which involves monitoring security alerts, analyzing logs, and ensuring compliance. They often work with cybersecurity tools, perform threat detection, and may require knowledge of scripting and security best practices.
More about Wazuh jobs

What cities are hiring for Wazuh jobs?

Cities with the most Wazuh job openings:

What states have the most Wazuh jobs?

States with the most job openings for Wazuh jobs include:

Infographic showing various Wazuh job openings in the United States as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 79% In-person, 7% Hybrid, and 14% Remote job distribution.

CLOUD SECURITY & SIEM ENGINEER

TECH-NET, INC

Folsom, CA • On-site

Other

Posted 3 days ago

New


Job description

CLOUD SECURITY & SIEM ENGINEER
Job Title: Cloud Security & SIEM Engineer
Location: Remote
Position Type: Full-Time / Contract-to-Hire
Work Schedule: Standard Business Hours (PST Alignment)
 
1. Role Overview
Technet is seeking a hands-on Cloud Security & SIEM Engineer to deploy, configure, and maintain the cybersecurity architecture for a critical energy-sector utility billing and data platform hosted in AWS (us-west-2).
In this role, you will lead the implementation and engineering of an enterprise high-availability (HA) Wazuh SIEM cluster deployed in a dedicated, tenant-isolated AWS management VPC. You will be responsible for telemetry pipelines across AWS-native security services, CrowdStrike Falcon EDR integration, containerized Prowler Cloud Security Posture Management (CSPM), and security monitoring for third-party middleware and data transfer tiers.
2. Technical Stack & Systems Managed
  • SIEM & Endpoint: Wazuh (HA Manager Cluster, Indexer, Dashboard, Agents, File Integrity Monitoring [FIM], Security Configuration Assessment [SCA]), CrowdStrike Falcon (Streaming API, Falcon Data Replicator / FDR).
  • AWS Native Security & Infrastructure: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS Config, AWS Systems Manager (SSM), CloudTrail, VPC Flow Logs, Route 53 Resolver logs, S3 Access Logs, EventBridge, SQS, Transit Gateway, AWS Directory Service.
  • CSPM & Compliance Automation: Containerized Prowler, CIS AWS Foundations Benchmark, SOC 2 Type II, NIST 800-53.
  • Middleware & Data Integration Tiers: GoAnywhere Managed File Transfer (MFT), Dell Boomi Middleware, Salesforce CRM API feeds, PG&E data exchanges.
  • Operating Systems & Databases: Windows Server (IIS Web Tier), Linux workloads, Amazon RDS (Microsoft SQL Server Audit Logs).
3. Key Responsibilities
  • Wazuh SIEM Implementation & Cluster Administration: Deploy, configure, and maintain a high-availability Wazuh SIEM manager cluster in a dedicated AWS management VPC. Deploy and tune Wazuh agents across Windows/IIS web nodes, Linux instances, middleware servers, and MFT nodes.
  • AWS Telemetry Pipeline Engineering: Architect and validate centralized log ingestion using AWS EventBridge, SQS, CloudTrail, VPC Flow Logs, Route 53 Resolver logs, and S3 server access logs into the SIEM correlation pipeline.
  • EDR Integration: Ingest CrowdStrike Falcon telemetry via Streaming API / FDR into Wazuh to correlate endpoint activity with cloud control plane logs without endpoint resource contention.
  • Integration Edge & MFT Security: Develop custom log parsers, decoders, and alerting rules for high-risk integration boundary systems, specifically GoAnywhere MFT, Dell Boomi, Salesforce integrations, and external PG&E utility feeds.
  • CSPM & Continuous Compliance: Deploy and automate containerized Prowler scans and AWS Config rules to deliver daily posture assessments mapped to SOC 2 Type II, CIS AWS Foundations Benchmark, and NIST 800-53 standards.
  • Vulnerability Management & Configuration Hardening: Operationalize automated recurring vulnerability scans and Security Configuration Assessments (SCA) using Wazuh and AWS Systems Manager (SSM); track and support infrastructure remediation.
  • Identity & Access Security: Assist with MFA deployment and continuous auditing across AWS Directory Service, VPN endpoints, and GoAnywhere MFT exchanges.
  • Encryption Validation: Continuously validate encryption-in-transit and encryption-at-rest across S3, EBS, and RDS SQL Server databases.
4. Required Qualifications & Technical Skills
  • Experience: 4+ years of hands-on experience in Cloud Security Engineering, SIEM Administration, or SecOps within AWS enterprise environments.
  • SIEM & Log Engineering: Deep practical expertise deploying and managing Wazuh (or ELK/OpenSearch-based security stacks), including writing custom XML decoders, rules, and managing agent fleets.
  • AWS Security Core: Strong hands-on experience with GuardDuty, Security Hub, AWS WAF, AWS Config, Systems Manager (SSM), IAM policy design, and multi-VPC networking (Transit Gateway).
  • Workload & Database Auditing: Experience configuring log feeds and auditing for Windows Server/IIS, Linux, and Amazon RDS SQL Server audit logs.
  • Integration Knowledge: Experience securing and ingesting logs from middleware and file-transfer systems (e.g., GoAnywhere MFT, Dell Boomi, API connectors).
  • Scripting: Proficiency in Python, Bash, and JSON/YAML for security automation and API integrations.
  • U.S. Data Residency Requirement: Must reside and work exclusively within the United States.
5. Preferred Qualifications & Certifications
  • AWS Certified Security – Specialty
  • AWS Certified Solutions Architect (Associate or Professional)
  • GIAC Cloud Security Automation (GCSA), GCED, or CISSP
  • Experience with utility, energy-sector, or NERC/CIP-adjacent regulated cloud environments.