Senior SOC Engineer

atSANS InstituteRemoteUS flagMarylandFull-timeSecurity OperationsSenior$155k – $205k/year

Posted 1 day ago

This is a fully remote position, open to applicants in Maryland.

📋 Description

• Develop the architecture for the agentic Security Operations Center (SOC)

• Outline data pathways for detection and response mechanisms

• Specify the structure of agents, orchestration processes, human-in-the-loop checkpoints, and system evolution strategies

• Create, refine, and manage detection rules within the internal Security Information and Event Management (SIEM) system

• Implement a detection lifecycle encompassing design, deployment, measurement, tuning, and enhancement

• Identify alert triage, investigative work, and response tasks suitable for agent augmentation

• Construct integrations, scripts, and playbooks across Managed Security Service Provider (MSSP), Endpoint Detection and Response (EDR), SIEM, cloud infrastructure, and identity management platforms

• Collaborate with AI Engineering to develop and oversee the agent stack

• Co-design Managed Cloud Platform (MCP) servers and tool integrations

• Contribute to prompt design, evaluation frameworks, and feedback mechanisms

• Manage audit trails and checkpoints to ensure safe and accountable actions by agents

• Monitor agent performance, investigate failures, adjust behavior, and integrate real-world outcomes

• Take ownership of vulnerability identification, prioritization, and remediation tracking

• Evaluate and enhance AWS and Azure cloud security posture

• Review Identity and Access Management (IAM) policies, strengthen configurations, implement cloud-native detection, and monitor security posture

• Collaborate on identity architecture, access reviews, privilege management, and authentication standards

• Perform code reviews, threat modeling, and security assessments for internal applications and integrations

• Assess technologies, integrations, and infrastructure changes for security risks

• Provide practical, risk-based security advice

• Assist with compliance activities, evidence gathering, and audit processes

• Respond to security incidents

• Execute other related tasks as assigned


⛳️ Requirements

• Over 7 years of experience in security operations, detection engineering, or security automation

• Hands-on experience with alert triage workflows, escalation paths, investigative patterns, and incident response lifecycle

• Background in detection engineering, including writing and tuning detections, measuring effectiveness, and managing false positives

• Expert-level proficiency in at least one detection query language: KQL, SPL, Lucene, Sigma, or similar

• Familiarity with MITRE ATT&CK framework

• Practical experience with EDR and SIEM platforms in live environments

• Capability to design comprehensive security operations pipelines

• Systems thinking ability to analyze data flows, dependencies, failure modes, and architectural implications

• Experience in designing for scalability and maintainability

• Knowledge of threat modeling concepts applied to security infrastructure

• Strong proficiency in Python, including production-quality code, testing practices, version control, and code review procedures

• Experience in building integrations with REST APIs across diverse security tools

• Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms, security automation frameworks, or equivalent tools

• Proficiency in Git-based workflows and an as-code mentality

• Working knowledge of AWS

• Interest in LLM-based agents and traditional automation

• Willingness to learn about agent frameworks, MCP, and prompt engineering

• Comfort with JSON and Markdown

• Critical thinking regarding over-automation

• Empathy for operators

• Ability to work comfortably in ambiguous situations

• Unrestricted authorization to work in the USA; visa sponsorship is not available

• Preferred: experience in MSSP-managed detection and response environments

• Preferred: experience with detection-as-code, including CI/CD pipelines, automated testing, and content packaging

• Preferred: prior experience with SOAR playbooks using Tines, Torq, Cortex XSOAR, Splunk SOAR, or similar

• Preferred: incident response experience beyond Tier 1

• Preferred: experience in cloud detection and response

• Preferred: identity-focused detection experience with Entra, Okta, Active Directory, or similar

• Preferred: hands-on experience with LLM tooling

• Preferred: familiarity with agentic development workflows such as CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar

• Preferred: experience with prompt injection and LLM adversarial thinking


🏝️ Benefits

• Competitive base salary

• Bonus opportunities

• 401(k) plan with company matching

• Medical, dental, and vision insurance options

• Short-term disability coverage provided by the company

• Optional long-term disability coverage

• Supplemental life and AD&D insurance for employees and their dependents

• Voluntary accident insurance

• Identity theft protection services

• Wellness and fitness programs

• Company-paid employee assistance program (EAP)

• Generous paid time off, including time for volunteering

• Opportunities for professional development

• SANS training opportunities

• Primarily remote work environment

• Tools and flexibility to excel both professionally and personally

People also viewed

Palo Alto Networks17 hours ago

Senior MSIAM SOC Engineer – Unit 42

US flagNorth Carolina OnlyFull-timeSecurity Operations$134.6k – $217.8k/year
ApplyView job
Pantheon Platform18 hours ago

Staff Security Engineer – Security Operations

IE flagIreland OnlyFull-timeSecurity Operations
ApplyView job
Convergint20 hours ago

Security Operations Center Architect

US flagUnited States OnlyFull-timeSecurity Operations$98k – $140k/year
ApplyView job
Conduent21 hours ago

Cyber Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations$76.1k – $98.8k/year
ApplyView job
Tokio Marine HCC21 hours ago

Security Operations Engineer

US flagUnited States OnlyFull-timeSecurity Operations$104.3k – $157.9k/year
ApplyView job
EPI Company1 day ago

Security Operations Engineer

FR flagFrance, +2 more countriesFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers