Security Operations Engineer
Core
Design, implement, and maintain high-fidelity security detections, correlation rules, alerts, and response workflows to identify attacks, misuse, and data loss events across the company's environment.
Role type
Senior Security Operations Engineer (Detection Engineering)
Builds
High-signal detections for credential misuse, privilege abuse, lateral movement, endpoint compromise, cloud/SaaS misuse, and insider risk; automated response workflows.
Domain
Cybersecurity, Security Operations, SIEM Engineering
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM engineering (Splunk), incident response lifecycle, networking, systems, cloud security, Python scripting, API integration, threat intelligence (MITRE ATT&CK), detection logic design, automation workflow development
Preferred skills
SOAR platforms (Tines, XSOAR), IDS/IPS/EDR/UTM technologies, cloud-native monitoring (AWS Config, CloudTrail), secure coding principles, security certifications (GCIH, AWS Security Specialty)
Technologies
Splunk, Python, AWS, Tines, XSOAR, MITRE ATT&CK
Responsibilities
Design and maintain detections across identity, endpoint, network, cloud, and SaaS domains; correlate signals to identify attacker behavior; support incident triage, investigation, and containment; develop enrichment and automation workflows; tune alerts to reduce false positives; create playbooks and operational guidance; mature the security operations model.
Seniority
Senior, hands-on IC