1

Wazuh Jobs (NOW HIRING)

Infrastructure Security Engineer

Palo Alto, CA · Hybrid

$168K/yr

SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...

Infrastructure Security Engineer

Palo Alto, CA · On-site

$168K/yr

SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...

Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...

Infrastructure Security Engineer

Austin, TX · Hybrid

$141K/yr

SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...

Security Analyst

Mountain View, CA · On-site +1

$90K - $120K/yr

Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...

Infrastructure Security Engineer

Washington, DC · Hybrid

$162K/yr

SIEM platforms such as Wazuh) * Experience in building custom cloud security tools or integrations * Interest in leveraging AI for cloud security monitoring and automation * Contributions to open ...

Security Analyst

Mountain View, CA · On-site

$100 - $125/hr

Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...

Monitor security alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems. * Conduct initial triage and investigation of potential security incidents. * Analyze logs ...

Infrastructure Engineer

Bentonville, AR · Hybrid

$94K - $123K/yr

Using monitoring and analysis tools such as Datadog and Wazuh IDS to collect and analyze system performance metrics for capacity planning, proactive response, and troubleshooting. * The application ...

Site Reliability Engineer

Camden, NJ · On-site

$150 - $200/hr

Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...

Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...

Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh. * Strong analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience ...

Site Reliability Engineer

Camden, NJ · On-site

$57.50 - $76.50/hr

Operate and improve our observability stack (Datadog, Wazuh, Prometheus, Grafana) - dashboards, alert quality, SLOs, and reducing time-to-detection for market-impacting issues * Run and maintain ...

Showing results 41-60

Wazuh information

What is a Wazuh engineer?

Wazuh engineers are IT professionals who specialize in deploying, configuring, and managing Wazuh, an open-source security monitoring and threat detection platform. They are responsible for setting up Wazuh to collect and analyze security data, detect vulnerabilities, and respond to security incidents. Their role often includes integrating Wazuh with other security tools, maintaining compliance, and providing support and training to other team members. Wazuh engineers play a crucial role in enhancing an organization's cybersecurity posture.

What are the typical responsibilities of a Wazuh engineer during a security incident?

A Wazuh engineer plays a crucial role during security incidents by monitoring real-time alerts, analyzing logs, and correlating events to identify potential threats. They are responsible for tuning detection rules to reduce false positives, investigating suspicious activities, and collaborating closely with IT and security teams to coordinate incident response. Additionally, Wazuh engineers often document incident findings and propose improvements to enhance the organization's security posture. This role requires a proactive approach and effective communication skills to ensure a swift and coordinated response.

What are the key skills and qualifications needed to thrive as a Wazuh security analyst, and why are they important?

To thrive as a Wazuh Security Analyst, you need a solid background in cybersecurity, knowledge of intrusion detection systems, log analysis, and often a degree or certification in information security. Familiarity with the Wazuh platform, Linux systems, SIEM solutions, and scripting languages like Python or Bash is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you investigate threats and collaborate with IT teams. These skills are crucial for proactively identifying vulnerabilities, responding to incidents quickly, and maintaining robust organizational security.

What is the work of Wazuh?

A Wazuh security analyst or engineer is responsible for monitoring, analyzing, and responding to security alerts using the Wazuh platform. They configure and maintain security tools, perform threat detection, and ensure compliance with security policies, often working with SIEM systems and security best practices.
More about Wazuh jobs

What cities are hiring for Wazuh jobs?

Cities with the most Wazuh job openings:

What states have the most Wazuh jobs?

States with the most job openings for Wazuh jobs include:

What job categories do people searching Wazuh jobs look for?

The top searched job categories for Wazuh jobs are:

Infographic showing various Wazuh job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 63% In-person, 11% Hybrid, and 26% Remote job distribution.

Incident Response Manager

Fortuna Cysec Inc

Atlanta, GA • On-site

Full-time

Re-posted 8 days ago


Job description

Description:

Company Overview


Fortuna Cysec delivers unified cybersecurity operations through TheFense platform—our integrated MDR, SIEM, EDR, and response ecosystem designed for regulated industries, nonprofits, healthcare, education, and mission-driven organizations. Our global SOC/NOC operates 24×7×365, providing real-time visibility, rapid containment, and deep technical expertise across diverse customer environments.

We are expanding our Incident Response leadership team with a hands-on technical manager who thrives in fast-moving investigations and can guide customers through their most critical security events.


 Role Summary

The Cybersecurity Incident Response Manager leads and directly participates in high-severity investigations across Fortuna Cysec’s customer base. This role blends technical depth, operational leadership, and customer-facing communication. You will serve as the senior escalation point for complex incidents, drive containment and remediation, and strengthen TheFense platform’s detection and response capabilities.


Requirements:

Lead and Execute Incident Response

· Command all phases of incident response—triage, investigation, containment, eradication, and recovery—while performing hands-on technical analysis. 

· Analyze EDR telemetry, SIEM alerts, network logs, cloud audit logs, and identity events across Microsoft, AWS, and hybrid environments. 

· Execute containment actions including endpoint isolation, identity disablement, MFA resets, OAuth token revocation, and firewall/network segmentation changes.

· Conduct forensic acquisition and analysis using Velociraptor, KAPE, FTK, EnCase, and Volatility.

· Reverse-engineer or sandbox suspicious binaries/scripts to determine behavior and impact.

· Lead hypothesis-driven threat hunts mapped to MITRE ATT&CK using TheFense’s unified telemetry.

Strengthen IR Operations

· Oversee daily IR operations across global SOC/NOC teams, ensuring SLA adherence and seamless follow-the-sun handoffs.

· Review and enhance IR playbooks, runbooks, and automated response actions within TheFense.

· Ensure high-quality incident documentation, evidence handling, and customer-ready reporting.

· Conduct root-cause analysis and deliver technically detailed post-incident reviews.

· Partner with engineering to refine detection logic, reduce false positives, and improve automation.

Engage Directly with Customers

· Serve as the technical authority during active breaches, guiding CISOs, IT directors, and executive stakeholders.

· Deliver clear, concise briefings that include attack path analysis, forensic findings, and prioritized remediation steps.

· Support customer teams with hands-on remediation across identity, cloud, endpoint, and email ecosystems.

· Provide strategic recommendations aligned with NIST, CIS Controls, and Fortuna Cysec best practices.

Advance Threat Intelligence and Detection

· Translate emerging threat intelligence into new detection rules, response playbooks, and threat-hunting queries.

· Validate detection logic through lab testing, simulated attacks, and historical telemetry review.

· Identify detection gaps and collaborate with TI teams to enrich investigations with IOCs and adversary behavior patterns.

Build Team and Platform Maturity

· Mentor analysts across global SOC/NOC teams in IR, forensics, cloud investigations, and threat hunting.

· Develop internal tooling and automation using Python or PowerShell.

· Participate in tabletop exercises, purple-team engagements, and breach simulations.

· Contribute to the evolution of TheFense platform by evaluating new telemetry sources and response capabilities.

Required Qualifications

  • 5–10+      years of hands-on experience in incident response, threat hunting, SOC      operations, or digital forensics.
  • Deep      technical expertise with EDR platforms (Microsoft Defender, SentinelOne,      CrowdStrike, Carbon Black).
  • Strong      SIEM experience with log parsing, correlation, and custom detection      creation (Wazuh, Microsoft Sentinel, Elastic, Splunk).
  • Strong      Windows Servers, Office 365 & Azure EntraID / Intune Experience
  • Hands-on      experience with cloud IR in Azure, AWS, and hybrid environments.
  • Proficiency      with forensic tools (Velociraptor, KAPE, FTK, EnCase) and memory analysis      frameworks (Volatility).
  • Strong      understanding of identity security (Entra ID, Okta), email security (M365,      Proofpoint), and SaaS compromise patterns.
  • Familiarity      with MITRE ATT&CK, NIST 800-61, CIS Controls, ISO 27035.
  • Ability      to communicate complex technical findings to both technical and executive      audiences.
  • Relevant      certifications: GCIA, GCFA, GCIH, GNFA, CISSP, or equivalent experience.

Preferred Qualifications

  • Experience      in an MDR, MSSP, or IR consulting environment.
  • Scripting/automation      skills in Python or PowerShell.
  • Experience      with malware analysis, cloud forensics, or identity compromise      investigations.
  • Experience      supporting regulated industries (HIPAA, FERPA, PCI-DSS, SOX, CJIS) and      mission-driven organizations.


Fortuna Cysec is an equal opportunity employer. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, pregnancy, age, sexual orientation, transgender status, gender identity, disability, alienage or citizenship status, marital status or partnership status, genetic information, veteran status or any other characteristic protected under applicable law.