Security Engineer - II (SOC)
Core
Hands-on Security Engineer in a 24x7 Security Operations Center (SOC) responsible for monitoring, triaging, and responding to security alerts across the technology environment.
Role type
Mid-level hands-on IC Security Engineer (SOC)
Builds
Automated response workflows using AI agents and SOAR platforms; detection rules and use cases aligned to MITRE ATT&CK.
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Alert triage and incident response, SIEM/EDR tuning, SOAR playbook development, cloud security (AWS/GCP/Azure), vulnerability management, scripting (Python/Bash), security metrics reporting (MTTD/MTTR), compliance frameworks (NIST/ISO/SOC2)
Preferred skills
AI agents/LLM-based automation for security, MITRE ATT&CK framework expertise, industry certifications (CISSP/GCIA/GCIH/GSEC/CEH)
Technologies
SIEM, EDR, IDS/IPS, vulnerability scanners, SOAR platforms, AI agents, Python, Bash, AWS, GCP, Azure
Responsibilities
Triage, investigate, and respond to security alerts from SIEM, EDR, cloud, network, and identity sources; tune detections to reduce false positives; build and maintain automated response workflows; track and report SOC metrics; support vulnerability management and remediation; collaborate with engineering teams to improve telemetry and detection coverage; mentor junior engineers.
Seniority
Mid-level, hands-on IC
