Intermediate SecOps Engineer
Gatineau, Province de Québec, G8R, Canada
Listed on 2026-10-06
-
IT/Tech
Cybersecurity, Network Security, Security Management & Operations
Based in Europe, the Eclipse Foundation is one of the world’s largest open source software foundations, with a proven track record of enabling community-led and industry-ready open source innovations used by millions of developers globally, earned over more than two decades.
The foundation is home to more than 400 high-impact projects and collaborations, including Open VSX, Adoptium, Jakarta EE, Eclipse IDE, and OpenHW Foundation. Supported by over 300 members globally, the Eclipse Foundation has an established international reach and reputation.
The Eclipse Foundation is seeking a skilled and proactive Intermediate Sec Ops Engineer to join our Infrastructure team. This role focuses on threat detection, incident response, security monitoring, and operational resilience across the Foundation’s infrastructure and services.
You will help improve our ability to detect, investigate, contain, and recover from security incidents. Working closely with infrastructure, release engineering, and development teams, you will maintain security visibility across systems, contribute to response playbooks, improve alert quality, and support a culture of operational security.
Salary Range50k€ - 75k€
LocationThis is a remote position. The selected candidate will work from their home office. All qualified candidates will be considered, with preference for candidates based in Canada and the European Union.
Core Responsibilities- Threat Detection and Security Monitoring:
Develop, maintain, and improve detection rules, alerts, dashboard, and monitoring workflows across infrastructure, cloud services, identity systems, endpoints, and application platforms. - Incident Response Coordination:
Participate in incident response activities, including triage, investigation, containment, remediation coordination and post-incident analysis. - Help ensure incidents are handled consistently and that lessons learned lead to concrete improvements.
- SIEM and Security Tooling Operations:
Operate and improve security monitoring tooling, including SIEM, log aggregation, alerting, vulnerability management, and related detection and response platforms. Work to reduce false positives while improving visibility into meaningful risks. - Threat Hunting and Investigation:
Proactively investigate suspicious activity, anomalous behavior, and emerging threats affecting infrastructure and services. Translate findings into improved detections, response procedures, and hardening recommendations. - Security Operations Process Improvement:
Create and maintain incident response playbooks, escalation procedure, actionable security guidance, and operational documentation to cloud operations, product development, and systems engineering teams. Help define practical security workflows that can be followed during both routine operations and active incidents. - Infrastructure Security Hardening:
Collaborate with the systems engineering team to identify and remediate security weaknesses in cloud, container, Linux, network, identity, and service configurations. - On-Call work:
Some events may require time outside of regular hours to respond appropriately. - Disaster Recovery Execution:
Actively participate in comprehensive disaster recovery planning, business continuity strategy formulation, and live simulations/exercises to validate system resilience and team readiness.
- 3–5+ years of professional experience in an active security operations, infrastructure security, incident response, or a related operational security role.
- Hands-on experience with security monitoring, alert triage, incident investigation, and response workflows.
- Experience with SIEM, log aggregation, alerting, or detection engineering tools.
- Strong understanding of Linux systems,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).