Staff Security Operations Engineer
Core
Lead the response to critical cyber incidents, define detection strategies, and build/evolve the SecOps architecture including SIEM, SOAR, and an in-house Agentic SOC.
Role type
Staff Security Operations Engineer (Individual Contributor)
Builds
SIEM architecture (Splunk), SOAR workflows (Torq), log/data pipelines, and the internal Agentic SOC for alert enrichment and automation.
Domain
Cybersecurity, Cloud Security, Incident Response, Web3/Digital Assets
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Incident response & forensics, Threat hunting, SIEM architecture, SOAR automation, Cloud security (AWS, EKS, Kubernetes), Python scripting, Technical leadership
Preferred skills
Splunk expertise, Wiz (CSPM/CNAPP), CrowdStrike EDR, OSINT/CTI methodologies, AI applied to security operations
Technologies
Splunk, Torq, Wiz, AWS, EKS, Kubernetes, CrowdStrike, Python, Bash, GitHub Actions
Responsibilities
Coordinate complex CSIRT incidents and conduct end-to-end investigations; Define detection strategy and lead proactive threat hunting; Design and optimize SIEM/SOAR architecture and log pipelines; Mentor senior and junior engineers; Establish standards, playbooks, and methodologies for the team.
Seniority
Staff, expert IC with strategic influence and architectural ownership