freehire launches on Product Hunt on 26 August.

Follow →

Senior Security Operations Engineer

Open 22d

You will sit at the heart of the SOC, leading investigations from start to finish and managing the lifecycle of detections, dashboards, and automations. You'll work independently on complex security issues, deciding whether to investigate, contain, remediate, or escalate, while serving as a technical point of escalation and mentor for more junior analysts. You'll analyze, classify, and prioritize alerts from tools like Splunk, CrowdStrike, Wiz, and AWS, and conduct in-depth investigations into incidents affecting endpoints, cloud, identities, SaaS, workloads, and infrastructure. You'll build and tune cloud detection use cases, integrate and maintain log sources, and continuously improve data quality. You'll design and optimize Splunk queries, develop new detection use cases, and work to reduce noise while improving signal quality. During incidents, you'll gather evidence, reconstruct timelines, document actions, and monitor containment and remediation, turning lessons learned into sustainable improvements like runbooks and automations. You'll also build and maintain automations using Torq/SOAR, scripts, and APIs, and contribute to the design and continuous improvement of Ledger's in-house Agentic SOC, expanding its investigation workflows and correlation capabilities.

Responsibilities

  • Analyze, classify, and prioritize alerts from Splunk, CrowdStrike, Wiz, AWS, and other sources
  • Conduct in-depth investigations into incidents affecting endpoints, cloud, identities, SaaS, workloads, and infrastructure
  • Provide clear, actionable context and serve as an escalation point for less experienced analysts
  • Leverage the Agentic SOC to focus time on incidents that matter
  • Build and tune cloud detection use cases for AWS, IAM activity, EKS/Kubernetes, and container workloads
  • Use Wiz to track and prioritize cloud exposure
  • Integrate and maintain log sources and improve data quality, completeness, parsing, and normalization
  • Identify visibility blind spots and work with IT, Cloud, Infrastructure, and Engineering teams to reduce them
  • Design, write, and optimize Splunk queries and develop new detection use cases
  • Reduce noise and improve signal quality of detections
  • Lead investigations by gathering evidence, reconstructing timelines, and documenting actions taken
  • Monitor containment, remediation, and post-incident measures
  • Formalize processes including detection mechanisms, runbooks, dashboards, and automations
  • Build and maintain automations using Torq/SOAR, scripts, and APIs
  • Contribute to the design and continuous improvement of the internal Agentic SOC
  • Expand Agentic SOC capabilities with new investigation workflows and better correlation

Requirements

  • Solid and proven experience in SecOps, SOC, cloud security, incident response, or infrastructure security
  • Track record of building and improving SOC capabilities and conducting independent investigations
  • Comfortable working in cloud and SaaS environments with rapidly evolving technologies
  • Proficiency in SecOps fundamentals: triage, investigation, incident response, log analysis, and documentation
  • Strong, hands-on cloud security skills, ideally AWS, including IAM and identity activity investigation
  • Experience analyzing cloud audit logs such as CloudTrail and GuardDuty
  • Experience securing workloads, containers, and Kubernetes (EKS)
  • Comfortable with exposure/CSPM tooling, ideally Wiz
  • SIEM experience, ideally Splunk, with ability to write queries for investigation and detection
  • EDR experience, ideally CrowdStrike
  • Automation experience using Python, Bash, APIs, GitHub Actions, SOAR, or equivalent
  • Interest in or experience with AI applied to security, agent-based workflows, and SOC automation
  • Professional-level English

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available