
Security Operations Engineer
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Review and analyze MDR alerts that necessitate follow-up with customers.
• Assist in validating incidents, defining the scope, and executing remediation efforts.
• Perform log analysis and conduct security investigations.
• Aid customers in validating containment and recovery processes.
• Document findings from investigations and provide actionable recommendations.
• Support the deployment and management of Sophos MDR technologies.
• Help with onboarding endpoints, integrations, and configuration tasks.
• Resolve technical issues related to MDR platforms.
• Assess policy configurations and security controls.
• Keep technical documentation and operational runbooks updated.
• Assist in Cyber Hygiene assessments and compliance evaluations.
• Contribute to security maturity assessments.
• Evaluate customer environments for potential security enhancements.
• Offer technical recommendations that adhere to security best practices.
• Collaborate closely with Technical Account Managers (TAMs) during customer interactions.
• Coordinate with Sophos MDR teams throughout investigations.
• Provide support to DFIR personnel during escalated incidents.
• Engage in service improvement initiatives.
• Prioritize investigations, technical support inquiries, and operational tasks.
• Prepare technical reports, summaries of investigations, and operational documentation.
• Analyze security events, endpoint telemetry, cloud audit logs, network traffic, and data from security platforms.
• Validate alerts, determine root causes, and suggest remediation strategies.
• Stay informed about emerging threats, attack methodologies, and cybersecurity best practices.
• Adhere to corporate security policies, confidentiality standards, and regulatory requirements.
• Contribute to the development of operational processes and technical playbooks.
• Collaborate with Technical Account Managers, Sophos MDR personnel, internal engineering teams, and DFIR consultants during investigations and escalations.
• Promote knowledge sharing and continuous improvement within the Managed Services organization.
• A minimum of a 4-year bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
• At least 3 years of experience in security operations, cybersecurity engineering, SOC operations, incident response, or IT security.
• Knowledge of Microsoft 365, Google Workspace, endpoint security, network security technologies, log analysis, and security investigation methods.
• Strong analytical and troubleshooting abilities.
• Experience working within MSSP, MDR, or SOC environments.
• Familiarity with NIST CSF, CIS Controls, and common compliance frameworks.
• Experience with Microsoft Defender, Sophos, CrowdStrike, SentinelOne, or similar platforms.
• Professional proficiency in Spanish (both written and verbal) with the ability to communicate technical and security concepts to Spanish-speaking customers.
• Capability to effectively communicate technical and security concepts to both technical and non-technical audiences in English; proficiency in Spanish is an advantage.
• Preferred certifications include Security+, CySA+, SC-200, Sophos Engineer, or similar credentials.
• Candidates based in DFW are preferred.
• Detail-oriented and driven by processes.
• A collaborative team player.
• Competitive salary and comprehensive employee benefits package.
• Strong emphasis on learning and development.
• Opportunities for career growth.
• 6% 401K matching.
• 20 days of PTO along with 2 Floating Days.
• Paid parental leave.
• An opportunity to truly enjoy your work.
Palo Alto Networks
Pantheon Platform
Convergint
Conduent
Get handpicked remote jobs straight to your inbox weekly.