Security Operations Specialist

UNC Charlotte

Full-Time
Closes on Saturday, October 24, 2026

Job Description

The Security Operations Specialist is a highly technical, action-oriented role focused on defending the University’s digital infrastructure from active threats. This position will lead the initiative to integrate AI within the University's security toolset. Instead of relying on passive compliance checklists, this position leverages cutting-edge artificial intelligence, machine learning, and automated orchestration to enable proactive threat hunting, accelerate real-time threat containment, and lower alert fatigue.

Security Operations Support
  • Contribute to continuous improvement of the security information and event management (SIEM) system, developing processes and procedures for monitoring, alerting, detection, and response functions for on-premise, cloud-based, and, as appropriate, third-party systems and services.
  • Review system logs and real-time alerts to identify trends, investigate abnormalities, and report exceptions.
  • Tune and create analytic detection policies for detecting and monitoring anomalous and malicious activity across the University Information Technology ecosystem.
  • Contribute to continuous improvement in Security Operations tasks and functions.
  • Support vulnerability management operations for the University and affiliates.
  • Create and maintain data dashboards and reports based on various systems of record to help the University IT community identify vulnerabilities, enabling them to focus their efforts to mitigate IT security risks across our environment.
Proactive Defense & AI-Augmented SOC Support
  • Threat Hunting: Deploy machine learning models and AI-driven behavior analytics to actively hunt for hidden threat actors.
  • SOC Augmentation: Design and maintain AI-assisted agents to triage alerts and automate response, reducing alert fatigue and response time.
  • Dynamic Optimization: Continuously build, tune, and refine policies across the Security tools to accurately catch modern, fast-moving attacker techniques.
Engineering Offensive & Defensive Tooling
  • Automated Defense: Assist Security Engineers to optimize and maintain Security Orchestration, Automation, and Response (SOAR) systems.
  • Adversarial Simulation: Develop and automate scripts and AI attack simulations to test existing defenses.
Incident Response
  • Perform the role of an incident response team member in the event of a successful attack to support technical response actions, incident mitigation, and recovery activities.
  • Participate in investigations of security incidents and provide resolutions based on alerts and events provided by security dashboards ranging from a Security Information and Event Management (SIEM) system to vulnerability scans or penetration testing assessments.
  • Contribute to procedures for proactive and reactive Incident Response to be used University-wide.
UNC Charlotte
Security Operations Specialist - 176837