
Security Operations Platform Engineer
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Florida, +3 more states.
• Configure and oversee the SIEM/SOAR platform.
• Monitor the performance, availability, and data integrity of the platform.
• Review and manage upgrades, integrations, and continuous optimization.
• Administer role- and scope-based access controls along with data retention policies.
• Onboard and standardize log sources, including firewalls, endpoints, servers, cloud services, SaaS, identity providers, etc.
• Create integrations through scripting for custom data onboarding using APIs.
• Troubleshoot ingestion issues to ensure the integrity and completeness of log data.
• Review and manage parsing rules and data mappings.
• Optimize data pipelines for both performance and cost-effectiveness.
• Develop, refine, and maintain detection rule logic and alert thresholds to enhance fidelity and reduce false positives.
• Collaborate with SOC analysts during active investigations to provide platform support, log extraction, and forensic data retrieval.
• Construct and maintain dashboards for SOC operations, compliance, and executive reporting.
• Develop and sustain scheduled and ad-hoc reports for stakeholders.
• Create KPIs and metrics to assess security posture and incident trends.
• Assess new log sources and security integrations.
• Suggest enhancements to increase visibility and coverage.
• Stay updated on platform improvements and industry best practices.
• Review existing integrations and data to enhance parsing, normalization, and data reduction.
• Bachelor’s degree in Cybersecurity, Information Technology, or a related field (or equivalent experience).
• Over 3 years of experience managing a SIEM platform.
• Proficient in network protocols, firewalls, IDS/IPS, EDR, and cloud security logs.
• Familiar with data normalization standards (CEF, LEEF, JSON, etc.).
• Experience with SIEM query languages.
• Proficient in scripting (Python, PowerShell, or similar) for automation purposes.
• Working knowledge of MITRE ATT&CK, threat intelligence, and incident response protocols.
• Preferred: Over 3 years of experience managing a SOAR platform.
• Preferred: Experience in developing automation and response playbooks.
• Preferred: Familiarity with log configurations for Azure, AWS, or GCP.
• Preferred: Experience supporting compliance frameworks (NIST, ISO 27001, SOX, HIPAA, etc.).
• Preferred: Security+, CySA+, CASP+, GCIA, GCIH, CISSP or equivalent certifications.
• Strong analytical and problem-solving capabilities.
• Excellent troubleshooting and log analysis skills.
• Ability to translate security requirements into practical technical solutions.
• Strong communication skills suitable for both technical and executive audiences.
• Capability to work independently and collaboratively within a fast-paced SOC environment.
• Willingness to travel up to 5 days per year.
• Competitive base salary along with bonus opportunities.
• Paid time off with a minimum of three weeks.
• Medical, dental, and vision coverage starting on day one.
• 401(k) plan with employer matching.
• Paid parental leave.
• Child and family care assistance (dependent care FSA with employer match up to $2500).
• Bundle of joy benefit, offering a year's worth of free diapers to all team members with a new baby.
• Tuition assistance program.
• Wellness program providing savings of up to $4,000 annually on insurance premiums.
• ...and more!
Agility Technologies Inc
American College of Education
First Due
Faire
Get handpicked remote jobs straight to your inbox weekly.