Job Overview

Job Overview

We are seeking an experienced Senior Security Operations Engineer to strengthen and scale our Security Operations Center (SOC) capabilities, threat detection frameworks, and incident response operations. In this role, you will be responsible for monitoring complex cloud and on-premises environments, engineering high-fidelity detection rules, and automating response playbooks to defend against sophisticated cyber threats. You will collaborate closely with Infrastructure, DevOps, and Software Engineering teams to ensure comprehensive security visibility, proactive threat hunting, and rapid containment of security incidents.

Key Responsibilities

Threat Detection & Security Automation

  • Design, build, and optimize detection engineering pipelines using SIEM, EDR, and log management platforms (e.g., Splunk, Datadog, CrowdStrike).
  • Develop and maintain automated incident response playbooks and orchestration workflows (SOAR) to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Perform proactive threat hunting using threat intelligence feeds, MITRE ATT&CK frameworks, and behavioral analysis to identify undetected malicious activity.

Incident Response & Digital Forensics

  • Serve as an escalation point for high-priority security alerts, leading end-to-end incident response, containment, and forensic investigations.
  • Conduct root-cause analysis following security events, author detailed post-mortem reports, and track long-term remediation action items.
  • Participate in on-call rotations for critical security incidents and lead tabletop exercises to test organizational readiness.

Security Monitoring & Infrastructure

  • Onboard new log sources, data feeds, and cloud services into central monitoring infrastructure, ensuring data integrity and retention compliance.
  • Audit and harden infrastructure, network perimeters, and multi-cloud environments (AWS, GCP, or Azure) against emerging vulnerabilities.
  • Define SOC operational metrics, key risk indicators (KRIs), and executive dashboards to measure security posture and operational efficiency.

Required Skills & Qualifications

Technical Skills & Expertise

  • Security Operations & Detection: Advanced expertise with SIEM solutions (Splunk, Elastic, Datadog), EDR/XDR platforms, and network detection systems.
  • Scripting & Automation: Strong proficiency in Python, Bash, or PowerShell for automating security workflows, log parsing, and API integrations.
  • Cloud & Network Security: Deep understanding of cloud architecture security (AWS/GCP/Azure), container security (Docker, Kubernetes), and network protocols (TCP/IP, DNS, TLS).
  • Frameworks & Methodologies: Applied knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, OWASP Top 10, and NIST Incident Handling guidelines.
  • Forensics & Analysis: Hands-on experience with memory forensics, log analysis, packet capture analysis (Wireshark), and malware triage.

Soft Skills & Leadership

  • Strong analytical problem-solving skills with the ability to maintain composure during critical security incidents.
  • Clear communication skills to translate complex security findings into clear actionable advice for technical and non-technical stakeholders.

Preferred Qualifications

  • Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
  • Experience: 5+ years of dedicated experience in security operations, threat detection, or incident response.
  • Certifications: Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, OSCP, or cloud security certifications (AWS Certified Security - Specialty).

Benefits & Compensation

  • Salary Range: $140,000 – $175,000 annually (commensurate with experience).
  • Comprehensive health, dental, and vision insurance coverage.
  • Flexible paid time off (PTO) and paid company holidays.
  • 401(k) retirement savings plan with company match.
  • Annual professional development stipend for security certifications, training, and conferences.
Apply Now