Cyber Security Engineer II
Summary
The Senior SOC Engineer will manage the threat detection ecosystem by engineering SIEM correlation rules, building automated SOAR playbooks, and leading proactive threat hunting. The role focuses on enhancing security operations through cloud monitoring, incident response, and technical leadership.
Job Summary
We are looking for a Sr. SOC Engineer with 3-5 years of experience to serve as the senior resource for our threat detection ecosystem. You will be responsible for the end-to-end lifecycle of our security operations infrastructure, from engineering high-fidelity correlation rules in the SIEM to orchestrating automated response playbooks in SOAR. Your goal is to move the SOC beyond reactive alerting by building a proactive, intelligence-driven defense posture that can identify and neutralize sophisticated adversaries in real-time.
Key Responsibilities & Business Impact
1. Detection Engineering & Framework Alignment
- Correlation Logic: Design, build, and maintain advanced detection rules within the SIEM/XDR environment that correlate disparate data sources (Identity, Network, Cloud, and Endpoint).
- MITRE Integration: Map all detection capabilities to the MITRE ATT&CK Framework to identify visibility gaps and ensure comprehensive coverage against modern TTPs (Tactics, Techniques, and Procedures).
- Logic Tuning: Conduct continuous "noise reduction" by fine-tuning alerting logic and suppression lists to maximize the signal-to-noise ratio for frontline analysts.
2. Security Orchestration & Lifecycle Management
- SOAR Architecting: Develop and maintain automated response playbooks (SOAR) to standardize incident handling, from automated enrichment and evidence collection to one-click containment.
- Tooling Ecosystem: Manage the health and integration of the SOC tech stack, ensuring seamless data ingestion from cloud providers (AWS/Azure/GCP) and SaaS applications into central monitoring hubs.
- Continuous Improvement: Regularly audit log sources for "telemetry health," ensuring that critical security logs are being ingested correctly and meet compliance retention requirements.
3. Advanced Hunting & Incident Leadership
- Proactive Hunting: Lead hypothesis-based threat hunting engagements, utilizing EDR and SIEM data to find "silent" lateral movement or credential harvesting that automated tools might miss.
- SME Escalation: Act as the Tier 2 escalation point for high-priority security incidents, performing deep-dive forensic analysis and providing technical leadership during the containment and recovery phases.
- Root Cause Analysis: Lead post-incident reviews to identify systemic weaknesses and implement automated technical controls to prevent recurrence.
Required Qualifications
Technical Experience
- Experience: 3-5 years of hands-on experience in a Security Operations Center (SOC) or Security Engineering role.
- SIEM/XDR Mastery: Deep technical proficiency with platforms such as Splunk ES, Microsoft Sentinel, Google Chronicle, or Palo Alto Cortex XDR.
- Cloud Security: Solid understanding of monitoring cloud-native environments (log types like CloudTrail, VPC Flow Logs, and GuardDuty).
- Querying & Scripting: Expert-level proficiency in query languages (KQL, SPL, or Lucene) and scripting languages (primarily Python or PowerShell) for automation and data manipulation.
Soft Skills & Education
- Education: Bachelor’s degree in Cybersecurity, Computer Science, or a related technical field.
- Analytical Mindset: Ability to synthesize complex, fragmented data points into a cohesive narrative of an attack.
- Collaboration: Strong ability to document complex workflows and lead technical training sessions for junior SOC analysts.
Certifications (Highly Desired)
- SOC & Detection: GIAC Certified Detection Analyst (GCDA), GIAC Certified Intrusion Analyst (GCIA). GCIH (GIAC Certified Incident Handler)
- Vendor Specific: Microsoft SC-200, Splunk Core Certified Advanced Power User, or AWS Certified Security - Specialty.
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- LinkedIn Profile optional
- Website optional