
Security Engineer
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Assist SOC Management in establishing tactical and operational objectives and formulating policies and procedures for detecting, assessing, reporting, and responding to security incidents.
• Create and refine detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
• Act as customer-facing escalation support for issues and security incidents that have been escalated from Tier 1 and Tier 2 SOC Analysts.
• Provide first-responder incident-response advisory support for clients facing security incidents within the scope of 11:11 Systems' software and systems.
• Ensure the timeliness and accuracy of critical incident identification, advisement, and reporting both internally and to customers.
• Lead and support initiatives for process improvement to enhance operational goals, drive efficiencies, and improve key performance indicators (KPIs).
• Champion the implementation and ongoing enhancement of new technologies, capabilities, frameworks, and methodologies.
• Develop and maintain customer-facing security stacks, including SIEM, EDR, SOAR, WAF, and vulnerability scanning, while architecting technical enhancements.
• Troubleshoot network connectivity and infrastructure issues impacting the Security Operations Team.
• Provide guidance on and assist in the development of SOC analyst training programs, along with cross-functional training.
• Monitor emerging threats, risks, and exploits, translating that knowledge into updated SIEM detection rulesets.
• Support service delivery through pre-production reviews for newly onboarded SIEM and EDR customers.
• Participate in an on-call rotation for after-hours support.
• Operate in accordance with 11:11 Systems' Code of Business Ethics and Company Values, including responsible data handling and completion of required compliance training.
• Over 5 years of experience in information security, with a minimum of 3 years in information technology.
• At least 3 years of experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools, specifically Azure Sentinel, Cortex XDR, and Tenable.
• Analyst-level experience in the telecommunications and/or enterprise cybersecurity sectors.
• Minimum of 1 year of experience in Python scripting or development.
• At least 1 year of experience in Linux administration and troubleshooting.
• Strong knowledge of TCP/UDP/IP networking, packet analysis, and networking protocols.
• Experience with enterprise security architecture, detection, and response.
• Deep understanding of standard incident response practices and SOC operations.
• Experience creating Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
• Familiarity with Kubernetes.
• Experience with Palo Alto products, including Cortex XDR, Panorama, and next-generation firewalls.
• Experience with ThreatX or similar WAF platforms.
• Possession of active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
• Working knowledge of security frameworks such as ISO, NIST, and CIS.
• Understanding of Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
• Up-to-date knowledge of attacker tactics, techniques, and procedures.
• Excellent communication, problem-solving, and interpersonal skills for both customer and team interactions.
• Must be a US Citizen and legally authorized to work in the US without the need for visa sponsorship.
• Ability to satisfactorily perform each essential function.
• 24/7 monitoring, support, and escalation for customers.
• On-call rotation for after-hours support.
• Required compliance training.
• Reasonable accommodations for qualified individuals with disabilities.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.