Security Operations Specialist
UNC Charlotte
Full-Time
Closes on Saturday, October 24, 2026
Job Description
Security Operations Support
- Contribute to continuous improvement of the security information and event management (SIEM) system, developing processes and procedures for monitoring, alerting, detection, and response functions for on-premise, cloud-based, and, as appropriate, third-party systems and services.
- Review system logs and real-time alerts to identify trends, investigate abnormalities, and report exceptions.
- Tune and create analytic detection policies for detecting and monitoring anomalous and malicious activity across the University Information Technology ecosystem.
- Contribute to continuous improvement in Security Operations tasks and functions.
- Support vulnerability management operations for the University and affiliates.
- Create and maintain data dashboards and reports based on various systems of record to help the University IT community identify vulnerabilities, enabling them to focus their efforts to mitigate IT security risks across our environment.
- Threat Hunting: Deploy machine learning models and AI-driven behavior analytics to actively hunt for hidden threat actors.
- SOC Augmentation: Design and maintain AI-assisted agents to triage alerts and automate response, reducing alert fatigue and response time.
- Dynamic Optimization: Continuously build, tune, and refine policies across the Security tools to accurately catch modern, fast-moving attacker techniques.
- Automated Defense: Assist Security Engineers to optimize and maintain Security Orchestration, Automation, and Response (SOAR) systems.
- Adversarial Simulation: Develop and automate scripts and AI attack simulations to test existing defenses.
- Perform the role of an incident response team member in the event of a successful attack to support technical response actions, incident mitigation, and recovery activities.
- Participate in investigations of security incidents and provide resolutions based on alerts and events provided by security dashboards ranging from a Security Information and Event Management (SIEM) system to vulnerability scans or penetration testing assessments.
- Contribute to procedures for proactive and reactive Incident Response to be used University-wide.