Billings, MTremote

Salary
$120,000–$150,000from the description
Posted
Jul 13, 2026
Location
Billings, MT
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual-contributor role responsible for owning a SIEM platform (Sumo Logic preferred) and the broader security operations function at a healthcare benefits company. Day-to-day work spans log source architecture, detection engineering mapped to MITRE ATT&CK, alert triage, threat hunting across AWS/cloud/endpoint/identity environments, and leading the full incident response lifecycle. Suits an experienced security engineer comfortable working independently in a HIPAA-regulated, compliance-driven setting.

Senior level · 7+ years · Remote · Full-time

Must have (11)
Sumo LogicAWS CloudTrailAWS GuardDutyAWS Security HubMITRE ATT&CKCrowdStrikeZscalerPowerShell, Python or Shell ScriptingLinuxWindowsMicrosoft 365

“or” means any one of them counts — you don't need all of them.

Posted 7 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 490 people nationally plausibly meet what this posting asks for (information security analysts). range 100–740

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Zscaler3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Linux65%PowerShell51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The JD requires a Bachelor's degree 'or equivalent work experience,' so no formal degree is hard-gated.

A cyber-specific certification (GCIH, GCFA, CISSP, or a relevant SIEM/vendor cert) is listed as required; no single cert is named as the exclusive gate.

Sumo Logic is 'strongly preferred' within the required SIEM section — it is listed under Required Skills with that qualifier, so it is treated as a hard gate on SIEM expertise with Sumo Logic as the named platform.

CrowdStrike and Zscaler appear in the required section as parenthetical examples ('e.g.') of EDR and network security platforms respectively; they are captured as hard gates with the understanding that equivalent platforms in those categories would likely be accepted.

PowerShell, Python, and Bash are listed together as interchangeable scripting options in the required section; PowerShell is the primary name with Python and Bash as alternatives.

The role is fully remote ('Remote first work environment') with no stated geographic restriction.

The 7-year total IT experience minimum includes a sub-requirement of at least 4 years specifically in security engineering, SOC, or incident response.

Tabletop exercise experience and healthcare industry experience are listed under Preferred Skills/Experience.

This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗