
Security Engineer
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States.
• Assist SOC Management in establishing tactical and operational objectives while creating policies and procedures for the detection, assessment, reporting, and response to security events.
• Create and refine detection rules, correlation logic, and automation workflows within SIEM and SOAR platforms.
• Act as customer-facing escalation support for issues and security incidents referred by Tier 1 and Tier 2 SOC Analysts.
• Deliver first-responder incident response advisory support for clients relevant to 11:11 Systems' software and systems.
• Ensure the timely and accurate identification, advisement, and reporting of critical incidents both internally and to clients.
• Lead and aid in initiatives aimed at process improvement to enhance operational objectives, drive efficiencies, and elevate KPIs.
• Spearhead the implementation and ongoing enhancement of technologies, capabilities, frameworks, and methodologies.
• Develop and sustain customer-facing security solutions including SIEM, EDR, SOAR, WAF, and vulnerability scanning, while architecting technical enhancements.
• Diagnose network connectivity and infrastructure problems impacting the Security Operations Team.
• Provide guidance on and assist in the development of SOC analyst training programs, as well as cross-functional training.
• Monitor emerging threats, risks, and exploits, translating insights into updated SIEM detection rulesets.
• Support service delivery through pre-production assessments for newly onboarded SIEM and EDR clients.
• Participate in an on-call rotation for after-hours assistance.
• Operate in accordance with 11:11 Systems' Code of Business Ethics and Company Values, including responsible data management and necessary compliance training.
• A minimum of 5 years in information security, including over 3 years in information technology.
• At least 3 years of experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools, particularly with Azure Sentinel, Cortex XDR, and Tenable.
• Analyst-level experience in the telecommunications and/or enterprise cybersecurity sectors.
• Over 1 year of experience in Python scripting or development.
• More than 1 year of experience with Linux administration and troubleshooting.
• A solid understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.
• Experience with enterprise security architecture, detection, and response mechanisms.
• A mature understanding of industry-standard incident response practices and SOC operations.
• Experience in constructing Azure Sentinel use cases, analytical rules, and workbooks, including KQL query development.
• Familiarity with Kubernetes.
• Experience with Palo Alto products, such as Cortex XDR, Panorama, and next-generation firewalls.
• Experience with ThreatX or similar WAF platforms.
• Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
• Working knowledge of security frameworks like ISO, NIST, and CIS.
• Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
• Current knowledge of attacker tactics, techniques, and procedures.
• Strong communication, problem-solving, and interpersonal skills for both customer and team interactions.
• Must be a U.S. citizen and legally authorized to work in the U.S. without the need for visa sponsorship.
• Ability to satisfactorily perform each essential function; reasonable accommodations may be made for qualified individuals with disabilities.
• Comprehensive health, dental, and vision insurance.
• Competitive salary and performance-based incentives.
• Opportunities for professional development and training.
• Flexible work arrangements and a supportive work environment.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.