We are seeking a Senior SOC Engineer to help monitor, detect, investigate, and respond to cybersecurity threats across enterprise environments. This role is responsible for strengthening security operations, improving detection capabilities, and supporting incident response efforts to protect systems, networks, and data. The ideal candidate brings deep experience in security operations, threat detection, incident investigation, and security tooling. This person is analytical, collaborative, and able to operate effectively in fast-paced environments where timely response and strong judgment are critical.
Key Responsibilities
- Monitor security events, alerts, and incidents across networks, endpoints, cloud environments, and applications.
- Investigate suspicious activity, triage alerts, and determine severity, impact, and appropriate response actions.
- Lead or support incident response activities, including containment, eradication, recovery, and post-incident analysis.
- Develop, tune, and maintain SIEM use cases, correlation rules, dashboards, and alerting logic.
- Analyze logs and telemetry from multiple security tools to identify threats, anomalies, and indicators of compromise.
- Collaborate with infrastructure, engineering, and IT teams to remediate vulnerabilities and strengthen security controls.
- Conduct threat hunting activities to proactively identify malicious behavior or hidden risks.
- Support the development and maintenance of SOC processes, playbooks, runbooks, and escalation procedures.
- Mentor junior analysts and contribute to the maturity of security operations practices.
- Recommend improvements to detection engineering, incident handling, and operational workflows.
- Prepare incident reports, metrics, and executive-ready summaries for technical and non-technical stakeholders.
- Stay current on emerging threats, attacker techniques, and cybersecurity best practices.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience.
- 5+ years of experience in a Security Operations Center, incident response, or cybersecurity operations role.
- Strong experience with SIEM platforms, log analysis, and security event investigation.
- Hands-on experience with endpoint detection and response, network security monitoring, and incident response tools.
- Strong knowledge of common attack techniques, threat actor behavior, and incident investigation methods.
- Understanding of TCP/IP, DNS, firewalls, VPNs, authentication systems, and operating system security concepts.
- Experience analyzing security data from Windows, Linux, cloud, and network environments.
- Familiarity with frameworks and standards such as MITRE ATT& CK, NIST, and cyber incident response best practices.
- Strong analytical, troubleshooting, and decision-making skills.
- Excellent written and verbal communication skills.
- Ability to work independently and collaboratively in cross-functional teams.
Preferred Qualifications
- Experience with SOAR platforms and security automation workflows.
- Knowledge of cloud security monitoring across AWS, Azure, or Google Cloud.
- Experience with threat intelligence platforms and threat hunting methodologies.
- Familiarity with malware analysis, digital forensics, or packet analysis.
- Scripting or automation experience using Python, PowerShell, or Bash.
- Experience with vulnerability management and security assessment processes.
- Relevant certifications such as CISSP, GCIA, GCIH, GCED, CySA+, or Security+.
- Experience supporting compliance-driven or highly regulated environments.