
Security Operations Engineer, Threat Hunting
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Florida.
• Act as the SOC engineer responsible for the design of SIEM and associated components, safeguarding the confidentiality, integrity, and availability of logs.
• Develop and oversee automated alert systems for prompt detection and response to security incidents.
• Manage, maintain, configure, update, and integrate security systems and infrastructure effectively.
• Ensure the upkeep of security tools and hardware, troubleshoot problems, and carry out software updates.
• Combine threat intelligence with internal data to improve detection capabilities and refine defense strategies.
• Create SIEM content including use cases, dashboards, fine-tuning for false positives, SLA/KPI reporting, and log-source configuration.
• Utilize SOAR technologies and playbooks to streamline incident-response workflows.
• Evaluate logging information-flow strategies and formulate work plans for log onboarding.
• Correlate events to meet SOC response requirements.
• Provide incident response, forensic analysis, troubleshooting, and security support that requires detailed event information.
• Assist in SOC automation projects while applying human analysis when necessary.
• Implement event and logging standards in security projects across the organization.
• Engage in threat-hunting tabletop exercises.
• Stay updated on threats, vulnerabilities, and mitigation strategies.
• Support the CISO, management team, and executive leadership.
• Assist SOC Analysts Tiers 1–3 and serve as an escalation point for complex investigations.
• Integrate advanced security operations, cybersecurity tools, intrusion detection, and secure networks with the SIEM platform.
• Perform additional duties as assigned.
• Bachelor's Degree in Computer Science or at least 4 years of experience as a Cyber Security/SOC Engineer.
• A minimum of 4 years of experience in cybersecurity or information technology practice.
• Required Information Risk, Privacy, or Security Certification (CISSP, CCSK, CCSP, PCSM), with at least 1 year of experience.
• Practical experience with IDS/IPS, firewalls, endpoint solutions, DLP, Active Directory, and application security.
• Advanced knowledge of Windows, Unix, Linux, and networking, including DNS, DHCP, and routing protocols.
• Strong comprehension of security KPIs and SLAs.
• Experience in preparing and delivering presentations to peers or senior executives.
• Proficiency in analyzing event and incident logs related to malware, vulnerabilities, exploits, and kill chain methodology.
• Ability to connect with threat intelligence platforms and SOAR solutions.
• Experience in configuring log data collection, enrichment, deployment, and integration.
• Background in operating within a SOC and incident response environment.
• Familiarity with scripting languages such as Python, PowerShell, or Bash.
• Excellent communication, project management, multitasking, organizational, and time-management skills.
• Capability to conduct tabletop exercises.
• Ability to collaborate with diverse teams and foster an enterprise-wide security culture.
• Highly organized, efficient, and a self-starter who requires minimal supervision.
• Medical insurance.
• Prescription coverage.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Options for disability insurance.
• Paid time off for vacation, illness, bereavement, family, and parental leave.
• Tax-advantaged 401(k) retirement savings plan.
• Potential for annual bonuses, commissions, and/or long-term incentive plans.
• Travel requirement of 0–10%.
OSIbeyond
It4us Cyber Security
CFA Institute
Get handpicked remote jobs straight to your inbox weekly.