
Security Engineer
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Assist SOC Management in establishing tactical and operational objectives, along with creating policies and procedures for the detection, assessment, reporting, and response to security incidents.
• Design and optimize detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
• Act as customer-facing escalation support for issues and security incidents that have been escalated from Tier 1 and Tier 2 SOC Analysts.
• Provide first-responder incident response advisory support for clients encountering incidents within 11:11 Systems' software and systems.
• Take ownership of the timeliness and accuracy of critical incident identification, advisement, and reporting both internally and to clients.
• Lead and promote process improvement initiatives aimed at enhancing operational objectives, driving efficiencies, and improving KPIs.
• Propel the implementation and continuous enhancement of technologies, capabilities, frameworks, and methodologies.
• Develop and sustain customer-facing security stacks, including SIEM, EDR, SOAR, WAF, and vulnerability scanning.
• Architect technical enhancements to existing processes.
• Diagnose network connectivity and infrastructure issues impacting the Security Operations Team.
• Provide guidance on and assist in developing SOC analyst training programs, as well as offering cross-functional training.
• Monitor emerging threats, risks, and exploits, translating that knowledge into updated SIEM detection rulesets.
• Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.
• Participate in an after-hours on-call rotation.
• Adhere to 11:11 Systems' Code of Business Ethics and Company Values, including responsible data handling and compliance training.
• 5+ years of experience in information security, including a minimum of 3 years in information technology.
• At least 3 years of experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools, with a focus on Azure Sentinel, Cortex XDR, and Tenable.
• Analyst-level experience in the telecommunications and/or enterprise cybersecurity sector.
• 1+ years of experience in Python scripting or development.
• 1+ years of experience in Linux administration and troubleshooting.
• Strong comprehension of TCP/UDP/IP networking, packet analysis, and networking protocols.
• Experience in enterprise security architecture, detection, and response.
• Advanced understanding of industry-standard incident response practices and SOC operations.
• Experience in building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
• Familiarity with Kubernetes.
• Experience with Palo Alto products, such as Cortex XDR, Panorama, and next-generation firewalls.
• Experience with ThreatX or similar WAF platforms.
• Active certifications like Security+, CySA+, CASP+, CISSP, and/or GCIH.
• Working knowledge of security frameworks such as ISO, NIST, and CIS.
• Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
• Current knowledge of attacker tactics, techniques, and procedures.
• Excellent communication, problem-solving, and interpersonal skills for customer-facing and team interactions.
• Must be a US Citizen and legally authorized to work in the US without visa sponsorship.
• Ability to satisfactorily perform each essential function.
• 24/7 monitoring, support, and escalation for customers.
• Participation in on-call rotation for after-hours support.
• Required compliance training.
• Reasonable accommodation for qualified individuals with disabilities.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.