IT Security Engineer
Overview
The SOC Engineer is the technical lead for the organization's SIEM platform and serves as the SOC's Tier 3 escalation resource. This role owns the design, tuning, and continuous advancement of detection content, drives SOAR playbook creation and adherence, and provides deep investigative expertise for the most complex security incidents. The ideal candidate combines strong hands-on SIEM engineering and query-language skills with the judgment and leadership to mentor Tier 1/2 analysts and shape the SOC's detection strategy.
Key Responsibilities
- Own and advance the organization's SIEM platform, including analytics/correlation rules, dashboards, data connectors, ingestion/cost management, and the overall detection roadmap.
- Lead detection engineering efforts: design, build, tune, and validate analytics rules across identity, endpoint, cloud, and network telemetry.
- Serve as the SOC's Tier 3 escalation point, performing deep technical investigation, root-cause analysis, and forensic collection on the most complex or high-severity incidents.
- Design, build, and maintain SOAR playbooks and drive consistent analyst adherence to documented playbook procedures.
- Build automation and enrichment pipelines (including AI-assisted triage where applicable) to reduce manual effort and improve mean time to detect/respond.
- Mentor and provide technical guidance to Tier 1/2 SOC analysts, including reviewing investigations and coaching on playbook execution.
- Evaluate, onboard, and tune new log sources, data connectors, and threat intelligence feeds to expand detection coverage.
- Partner with IAM, endpoint, and network security teams to ensure detection coverage keeps pace with control and infrastructure changes.
- Track and report on detection engineering and SOC performance metrics (e.g., MTTD, MTTR, playbook adherence, false-positive rates).
- Maintain thorough documentation of detection logic, playbooks, and incident response procedures.
- Participate in on-call rotation and respond to security incidents after hours when necessary.
Minimum Requirements
- 4+ years of experience in cybersecurity, including at least 2 years of hands-on experience with an enterprise SIEM platform and its query language(s).
- Demonstrated experience leading or serving as a senior/Tier 3 resource within a SOC or incident response function.
- Strong hands-on experience building and tuning SIEM analytics rules and detection content.
- Experience designing and maintaining SOAR playbooks or equivalent security orchestration/automation tooling.
- Solid incident response and forensics experience, including investigation, evidence handling, and documentation.
- Proficiency with scripting/automation (PowerShell, Python, or similar).
- Experience integrating security tooling (EDR, email security, identity, network) into a SIEM for detection and correlation.
- At least one relevant security certification (e.g., GCIA, GCIH, CySA+, Security+, or vendor-specific SIEM certifications).
- Strong understanding of the MITRE ATT&CK framework and common adversary tactics, techniques, and procedures.
- Able to respond to security incidents after hours when necessary.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
- Experience with SIEM dashboard/reporting development and executive/board-level reporting on security metrics.
- Experience with AI/LLM-assisted alert enrichment or triage pipelines.
- Familiarity with common enterprise security stack components (EDR, secure web gateway/CASB, identity providers, email security) and how they integrate into detection workflows.
- Familiarity with SOC 2, risk assessments, and other GRC functions.
- Advanced certifications (e.g., GCFA, GCTI, OSCP, CISSP) are a plus.
- Excellent problem-solving skills and the ability to lead through ambiguity under pressure.
- Strong communication skills, with the ability to convey technical findings to both technical and non-technical stakeholders.
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
While performing the duties of this job, the employee is regularly required to talk or hear. The employee is frequently required to stand; walk; use hands to fingers, handle, and feel; and reach with hands and arms, and operate objects, tools or controls; reach with hands and arms.
.
Work Environment:
While performing the duties of this job, the employee is not substantially exposed to adverse environmental conditions (such as in typical office or administrative work). The employee may be subject to one or more of the following atmospheric conditions that affect the respiratory system of the skin: fumes, odors, dust, mists, gases, or poor ventilation.
Competencies:
Excellent oral and written communication skills to effectively interact with internal customers and department staff.
Self-Motivated
Team-Oriented
Customer Oriented
Must be able to follow Company safety rules and all other Company policies.
Pike Enterprises, LLC is an Equal Opportunity Employer
EOE/Minorities/Females/Vet/Disabled
NOTE: This job description is not intended to be all-inclusive. Employee may perform other related duties as requested to meet the ongoing needs of the organization.