Security Operations Engineer II (Employer of Record)
Core
Operate and tune enterprise security tools, build automation playbooks, and respond to security incidents to protect operations.
Role type
Security Operations Engineer II (SOC)
Builds
Automation playbooks, detection rules, and security configurations for a global finance company
Domain
Information Security / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM/SOAR operations, EDR/IDS/IPS monitoring, Python/PowerShell scripting, CI/CD and Infrastructure-as-Code, MITRE ATT&CK framework, incident response, WAF/proxy management, log analysis, change management
Preferred skills
GSEC/GCIA/GCED/AZ-500/SC-200/SC-100/Network+/CCNA certifications, Zero Trust architecture, detection engineering (KQL/SPL), vulnerability management
Technologies
SIEM, SOAR, EDR, WAF, Proxy, Python, PowerShell, Git, CI/CD, JSON, YAML, KQL, SPL
Responsibilities
Operate and tune enterprise security tools (EDR, SIEM/SOAR, WAF/proxy), build automation and playbooks, author and tune detection rules, maintain health dashboards and metrics, conduct knowledge transfers, administer URL/SSL/identity policies, analyze block events, provide on-call support, report on incidents and outages, detect and respond to security incidents
Seniority
Mid-level, hands-on IC