Search Remote Jobs

Senior SOC Engineer

🔥 2 hours ago

🦀 Maryland – Remote

infoinfo

💵 $155k - $205k / year

⏰ Full Time

🟠 Senior

🛡️ Security Operations

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of SANS Institute

SANS Institute

201 - 500 employees

Founded 1989

🔒 Cybersecurity

📚 Education

☁️ SaaS

Cybersecurity • Education • SaaS

SANS Institute is a leading organization specializing in cybersecurity training and education, providing a wide range of hands-on courses, certifications, and degree programs aimed at enhancing the skills and expertise of cybersecurity professionals. Founded in 1989, it offers expert-led training sessions globally, alongside resources like webinars and podcasts to support ongoing learning and development in the cybersecurity field. SANS Institute is dedicated to helping individuals and organizations mitigate cyber risks through rigorous training that aligns with industry standards and best practices.

📋 Description

• Design the architecture of the agentic SOC • Define data flows through detection and response pipelines • Define agent structure, orchestration, human-in-the-loop checkpoints, and system evolution • Write, tune, and maintain detections across the internal SIEM environment • Establish a detection lifecycle of design, deploy, measure, tune, and improve • Identify alert triage, investigation, and response work suitable for agent augmentation • Build integrations, scripts, and playbooks across MSSP, EDR, SIEM, cloud infrastructure, and identity platforms • Partner with AI Engineering to build and govern the agent stack • Co-design MCP servers and tool integrations • Contribute to prompt design, evaluation harnesses, and feedback loops • Own audit trails and checkpoints for safe and accountable agent actions • Monitor agent performance, investigate failures, tune behavior, and incorporate real-world outcomes • Own vulnerability identification, prioritization, and remediation tracking • Assess and improve AWS and Azure cloud security posture • Review IAM policies, harden configurations, implement cloud-native detection, and monitor posture • Partner on identity architecture, access reviews, privilege management, and authentication standards • Conduct code reviews, threat models, and security assessments for internal applications and integrations • Evaluate technologies, integrations, and infrastructure changes for security risk • Provide pragmatic, risk-based security guidance • Support compliance activities, evidence collection, and audit engagements • Respond to security incidents • Perform other related duties as assigned

🎯 Requirements

• 7+ years in security operations, detection engineering, or security automation • First-hand experience with alert triage workflows, escalation paths, investigation patterns, and incident response lifecycle • Detection engineering experience, including writing and tuning detections, measuring efficacy, and managing false positives • Expert-level command of at least one detection query language: KQL, SPL, Lucene, Sigma, or equivalent • MITRE ATT&CK fluency • Hands-on experience with EDR and SIEM platforms in production environments • Ability to design end-to-end security operations pipelines • Systems thinking and ability to reason about data flows, dependencies, failure modes, and architectural implications • Experience designing for scale and maintainability • Exposure to threat modeling concepts applied to security infrastructure • Strong Python, including production-quality code, testing, version control, and code review discipline • Experience building integrations against REST APIs across heterogeneous security tools • Experience with SOAR platforms, security automation frameworks, or equivalent tooling • Git-based workflows and as-code mindset • Working knowledge of AWS • Curiosity about LLM-based agents and traditional automation • Willingness to learn agent frameworks, MCP, and prompt engineering • Comfort with JSON and Markdown • Calibrated skepticism about over-automation • Operator empathy • Comfort with ambiguity • Unrestricted authorization to work in the USA; visa sponsorship is not available • Preferred: experience with MSSP-managed detection and response environments • Preferred: detection-as-code experience, including CI/CD pipelines, automated testing, and content packaging • Preferred: prior SOAR playbook experience with Tines, Torq, Cortex XSOAR, Splunk SOAR, or equivalent • Preferred: incident response experience beyond Tier 1 • Preferred: cloud detection and response experience • Preferred: identity-focused detection experience with Entra, Okta, Active Directory, or similar • Preferred: hands-on LLM tooling experience • Preferred: familiarity with agentic development workflows such as CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar • Preferred: prompt injection and LLM adversarial thinking experience

🏖️ Benefits

• Competitive base salary • Bonus opportunities • 401(k) plan with company match • Medical, dental, and vision plans • Company-provided short term disability • Optional long-term disability • Supplemental life and AD&D insurance for employees and dependents • Voluntary accident insurance • Identity theft protection • Fitness and wellness programs • Company-paid employee assistance program (EAP) • Generous paid time off, including volunteer time • Professional development opportunities • SANS training opportunities • Primarily remote work environment • Tools and flexibility to thrive professionally and personally

Apply Now

Similar Jobs

🔥 22 hours ago

Valiant Solutions

201 - 500

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Tier III SOC Analyst conducting forensic investigations, detection engineering, and incident escalation. Supporting Valiant Solutions’ public-sector cybersecurity contracts through remote telework.

🕒 Yesterday

Concentric

201 - 500

🔐 Security

💼 Consulting

Program Manager overseeing embedded employees, vendors, and protective operations for Concentric, a global risk consultancy. Managing client relationships, security resources, compliance, and operational delivery.

🕒 2 days ago

Mondelēz International

10,000+ employees

💼 Consulting

📣 Marketing

📦 Logistics

Operations Analyst supporting Mondelēz International’s cyber defense operations. Assessing information security risks, testing controls, implementing security technology, and training teams.

🕒 2 days ago

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s Connected Operations IoT platform. Building security automation and supporting insider-threat investigations.

🕒 2 days ago

Motive

1001 - 5000

📦 Logistics

🏗️ Construction

🍽️ Food & Beverage

Senior Manager building Motive’s AI-first SOC across cloud, production, enterprise and connected-device environments. Leading detection, incident response, threat hunting and security automation.