1

Wazuh Jobs (NOW HIRING)

General knowledge of SIEMs, including Wazuh/ELK Stack * Experience with vulnerability scanning tools such as Qualys * Experience maintaining endpoint detection and response (EDR) systems * Experience ...

$88K - $121K/yr

Familiarity with technologies such as Wazuh, Snort, TheHive, Cortex, HashiCorp Vault, HashiCorp Boundary, Tailscale, Authentik, Keycloak, and related security platforms is valuable. * Experience with ...

Showing results 21-40

Wazuh information

What is a Wazuh engineer?

Wazuh engineers are IT professionals who specialize in deploying, configuring, and managing Wazuh, an open-source security monitoring and threat detection platform. They are responsible for setting up Wazuh to collect and analyze security data, detect vulnerabilities, and respond to security incidents. Their role often includes integrating Wazuh with other security tools, maintaining compliance, and providing support and training to other team members. Wazuh engineers play a crucial role in enhancing an organization's cybersecurity posture.

What are the typical responsibilities of a Wazuh engineer during a security incident?

A Wazuh engineer plays a crucial role during security incidents by monitoring real-time alerts, analyzing logs, and correlating events to identify potential threats. They are responsible for tuning detection rules to reduce false positives, investigating suspicious activities, and collaborating closely with IT and security teams to coordinate incident response. Additionally, Wazuh engineers often document incident findings and propose improvements to enhance the organization's security posture. This role requires a proactive approach and effective communication skills to ensure a swift and coordinated response.

What are the key skills and qualifications needed to thrive as a Wazuh security analyst, and why are they important?

To thrive as a Wazuh Security Analyst, you need a solid background in cybersecurity, knowledge of intrusion detection systems, log analysis, and often a degree or certification in information security. Familiarity with the Wazuh platform, Linux systems, SIEM solutions, and scripting languages like Python or Bash is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you investigate threats and collaborate with IT teams. These skills are crucial for proactively identifying vulnerabilities, responding to incidents quickly, and maintaining robust organizational security.

What is the work of Wazuh?

A Wazuh security analyst or engineer is responsible for monitoring, analyzing, and responding to security alerts using the Wazuh platform. They configure and maintain security tools, perform threat detection, and ensure compliance with security policies, often working with SIEM systems and security best practices.
More about Wazuh jobs

What cities are hiring for Wazuh jobs?

Cities with the most Wazuh job openings:

What states have the most Wazuh jobs?

States with the most job openings for Wazuh jobs include:

What job categories do people searching Wazuh jobs look for?

The top searched job categories for Wazuh jobs are:

Infographic showing various Wazuh job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 63% In-person, 11% Hybrid, and 26% Remote job distribution.

Cyber Defense Incident Responder (CDIR) - Colorado Springs, Colorado

Davidson Technologies, Inc.

Colorado Springs, CO • On-site

$75K - $110K/yr

Full-time

Posted 6 days ago


Job description

Davidson has distinguished itself in the aerospace and missile defense industry with an outstanding reputation for excellence. Specifically, we're recognized for hiring noted experts, experienced engineers and scientists dedicated to designing and delivering advanced, intelligent technology solutions in defense of our Nation.
Davidson is seeking a Cyber Defense Incident Responder (CDIR) in Colorado Springs, Colorado.
As a CDIR Operator, the successful candidate will utilize the Cyber Security Manager (CSM) toolkit to monitor network logs and message traffic between all elements on the GMD Communication Network (GCN) and elevate alerts via proper channels/protocols. The contingent position(s) are in Fort Greely, Alaska (FGA), and/or Schriever SFB, Colorado (SSFB) and is a permanent position, rotating schedules may be required (no differential pay for shift work, no housing, or cars offered).
Job Responsibilities:
  • Monitor all mission network traffic
  • Provide 24-hours a day, 7-days a week, 365 days a year (24/7/365) capability to detect network attacks to GMD network communications. CDIR operators will be expected to work any/all shifts. Standard operations are on 10-hour shifts but may switch to 8-hour or 12-hour schedule based on team availability, mission requirements, or Prime directives.
  • Support Information Assurance/Computer Network Defense Analysts for monitoring and analysis.
  • Support monitoring of systems, servers, infrastructure, and software, to include firewalls, proxy servers, and intrusion detection systems.
  • Review system and firewall logs and IDS alerts using approved tools and in accordance with operating procedures.
  • Participate, when needed, with the incident response team in a technical hands-on role to support investigation, response, resolution identification, and root cause analysis.
  • Recommend and implement additional controls to prevent future incidents.
  • Support other teams by responding to requests for more information and assisting with specific projects.
  • Provide inputs to the respective operations work schedule.
  • Provide weekly status reports.
  • Attend daily/weekly/monthly support meetings, as requested.
  • Complete required CSM training, system familiarization, safety and security at the designated facility

Job Requirements:
  • DOD 8140 Compliance Certification for (531) Cyber Defense Incident Responder:
    • CBROPS or FITSP-O or GISF or CCSP or CEH or Cloud+ or GCED or PenTest+ or Security+ or GSEC
  • Ability to read, understand and execute defined engineering procedures

Desired Competencies:
  • CySA+ or CFR or GCFA or GCIA or GDSA or GCIH or GICSP or CCE
  • Familiarity with cyber network defense tools (i.e., Splunk, WAZUH, etc.)
  • Knowledge of DOD Communication Network Architectures and Network Operations Center (NOC) documentation and processes

Clearance:
  • Must be a U.S. citizen
  • Must already possess a Secret Clearance and the ability to obtain Top-Secret if required