Staff SOC Engineer – Security Telemetry, Detection Platforms

🔥 6 minutes ago

🏰 Missouri – Remote

infoinfo

💵 $126.7k - $188.8k / year

⏰ Full Time

🔴 Lead

🛡️ Security Operations

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Reinsurance Group of America, Incorporated

Reinsurance Group of America, Incorporated

1001 - 5000 employees

Founded 1973

💼 Consulting

📦 Logistics

🛡️ Insurance

Consulting • Logistics • Insurance

Reinsurance Group of America, Incorporated (RGA) is a leading global reinsurance company that focuses exclusively on life and health reinsurance solutions. With a strong commitment to providing innovative products and services, RGA helps its clients manage risk and enhance their insurance portfolios through its expertise in underwriting, claims management, and financial solutions. The company operates in multiple global markets, leveraging its extensive data and analytics capabilities to offer tailored solutions that meet the unique needs of the life and health insurance sectors.

📋 Description

• Administer and engineer improvements to enterprise security telemetry and detection platforms, including SIEM, EDR, SOAR, and data pipeline solutions • Implement secure-by-default telemetry patterns and logging standards across operating systems, cloud, and network data sources • Design, build, and maintain high-throughput data pipelines for log routing, enrichment, filtering, and transformation into SIEM, archive, and other destinations • Engineer SIEM content including SPL searches, correlation rules, alerts, dashboards, data models, CIM mapping, and RBA where applicable • Define and maintain RBAC, least-privilege models, and user provisioning across telemetry and detection platforms • Integrate and automate SOC tooling and enterprise systems, including Tines, AWS/Azure/GCP logging, threat intelligence feeds, and ITSM systems • Author and maintain system design documents, reference implementations, runbooks, and technical decision records • Troubleshoot complex SIEM/EDR and pipeline issues, reduce noise, and close visibility gaps • Support incident response through targeted searches, log analysis, root-cause identification, and platform expertise during high-severity events • Improve control validation, data quality checks, parsing and field-extraction tests, content regression tests, and platform observability • Evaluate emerging telemetry sources, detection approaches, and vendor capabilities; build proofs of concept • Support identity, access, and privilege strategies, including API tokens, service accounts, secrets management, SSO/SAML/OIDC • Translate post-incident findings into backlog items for pipeline hardening, new log sources, and content tuning • Contribute to responsible logging and monitoring for AI-enabled applications and platforms • Represent security telemetry and detection engineering for the Global Security Office in technical forums • Perform other duties as assigned

🎯 Requirements

• Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience – Required • 6+ years of progressive experience in security/infrastructure engineering or SOC engineering focused on SIEM/EDR, telemetry pipelines, and detection content • Demonstrated success deploying and operating SIEM, EDR, SOAR, and data pipeline solutions at enterprise scale, including RBAC, API integrations, and platform hygiene • Hands-on experience engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources • Strong technical background and tacit understanding of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning to reduce ingest volume and improve signal to noise • Proven ability to collaborate across security operations, architecture, infrastructure, and product teams; strong stakeholder communication and documentation skills – Required • Ability to map and document complex systems and processes, including data lineage and schema/field mappings – Required • Familiarity with NIST frameworks, MITRE ATT&CK, and secure by design practices; experience with control validation and metrics/KPIs for continuous improvement – Required • Experience supporting 24/7 SOC operations, including on call participation and multi region ingestion scenarios – Required • Advanced analytical and problem-solving skills; competency with analysis and diagramming tools such as Lucidcharts, Visio, and Excel – Required • Master’s degree in Arts/Sciences (MA/MS) or professional industry certification – Preferred • Relevant platform certifications such as Splunk Core/Cloud, Cribl Certified Observability Engineer, or CrowdStrike CCFA/CCFR – Preferred • Security certifications such as CISSP, GSEC, GCDA, or Cloud+ – Preferred • Experience integrating security telemetry into CI/CD pipelines and applying version control, testing, and staged releases for detections and pipeline changes – Preferred • Proficiency in automation and scripting such as Python or PowerShell, and experience with SOAR such as Tines and infrastructure as code such as Terraform – Preferred

🏖️ Benefits

• Annual bonus plan • Long-term equity incentive plan eligibility for some positions • Health benefits • Retirement benefits • Other employee benefits • Knowledge and experience with diverse colleagues around the world • Respectful, welcoming environment that fosters individuality and pioneering thought • Career potential and global opportunities

Apply Now

Similar Jobs

🕒 2 days ago

Thrive

1001 - 5000

🔒 Cybersecurity

💼 Consulting

Director leading Thrive’s Security Operations Center for cloud, cybersecurity, networking, disaster recovery, and managed services. Overseeing SOC operations, incident response, threat monitoring, and analyst teams.

🕒 6 days ago

1Password

501 - 1000

🔒 Cybersecurity

☁️ SaaS

⚡ Productivity

Staff Security Engineer leading high-severity incident response at 1Password, a cybersecurity company. Building AI-assisted automation, threat hunting, insider risk, and readiness programs.

🕒 September 14

MRO

1001 - 5000

🏥 Healthcare

☁️ SaaS

📋 Compliance

Director leading MRO’s information security operations and cybersecurity program execution. Managing security teams, KPIs, vulnerability remediation, monitoring, and incident response.

🕒 September 9

Stripe

1001 - 5000

💳 Fintech

🛍️ eCommerce

🤝 B2B

Stripe Security Incident Response Manager investigating fraud and abuse across its financial infrastructure platform. Leading incident response, mitigation, automation, and cross-functional security improvements.

🕒 September 2

Backblaze

201 - 500

🛍️ eCommerce

🏢 Enterprise

Director of Security Operations leading Backblaze’s cybersecurity monitoring, incident response, and vulnerability programs. Driving AI-assisted defenses, automation, and operational resilience across cloud and distributed environments.