
Senior SOC Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Maryland.
• Develop the architecture for the agentic Security Operations Center (SOC)
• Outline data pathways for detection and response mechanisms
• Specify the structure of agents, orchestration processes, human-in-the-loop checkpoints, and system evolution strategies
• Create, refine, and manage detection rules within the internal Security Information and Event Management (SIEM) system
• Implement a detection lifecycle encompassing design, deployment, measurement, tuning, and enhancement
• Identify alert triage, investigative work, and response tasks suitable for agent augmentation
• Construct integrations, scripts, and playbooks across Managed Security Service Provider (MSSP), Endpoint Detection and Response (EDR), SIEM, cloud infrastructure, and identity management platforms
• Collaborate with AI Engineering to develop and oversee the agent stack
• Co-design Managed Cloud Platform (MCP) servers and tool integrations
• Contribute to prompt design, evaluation frameworks, and feedback mechanisms
• Manage audit trails and checkpoints to ensure safe and accountable actions by agents
• Monitor agent performance, investigate failures, adjust behavior, and integrate real-world outcomes
• Take ownership of vulnerability identification, prioritization, and remediation tracking
• Evaluate and enhance AWS and Azure cloud security posture
• Review Identity and Access Management (IAM) policies, strengthen configurations, implement cloud-native detection, and monitor security posture
• Collaborate on identity architecture, access reviews, privilege management, and authentication standards
• Perform code reviews, threat modeling, and security assessments for internal applications and integrations
• Assess technologies, integrations, and infrastructure changes for security risks
• Provide practical, risk-based security advice
• Assist with compliance activities, evidence gathering, and audit processes
• Respond to security incidents
• Execute other related tasks as assigned
• Over 7 years of experience in security operations, detection engineering, or security automation
• Hands-on experience with alert triage workflows, escalation paths, investigative patterns, and incident response lifecycle
• Background in detection engineering, including writing and tuning detections, measuring effectiveness, and managing false positives
• Expert-level proficiency in at least one detection query language: KQL, SPL, Lucene, Sigma, or similar
• Familiarity with MITRE ATT&CK framework
• Practical experience with EDR and SIEM platforms in live environments
• Capability to design comprehensive security operations pipelines
• Systems thinking ability to analyze data flows, dependencies, failure modes, and architectural implications
• Experience in designing for scalability and maintainability
• Knowledge of threat modeling concepts applied to security infrastructure
• Strong proficiency in Python, including production-quality code, testing practices, version control, and code review procedures
• Experience in building integrations with REST APIs across diverse security tools
• Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms, security automation frameworks, or equivalent tools
• Proficiency in Git-based workflows and an as-code mentality
• Working knowledge of AWS
• Interest in LLM-based agents and traditional automation
• Willingness to learn about agent frameworks, MCP, and prompt engineering
• Comfort with JSON and Markdown
• Critical thinking regarding over-automation
• Empathy for operators
• Ability to work comfortably in ambiguous situations
• Unrestricted authorization to work in the USA; visa sponsorship is not available
• Preferred: experience in MSSP-managed detection and response environments
• Preferred: experience with detection-as-code, including CI/CD pipelines, automated testing, and content packaging
• Preferred: prior experience with SOAR playbooks using Tines, Torq, Cortex XSOAR, Splunk SOAR, or similar
• Preferred: incident response experience beyond Tier 1
• Preferred: experience in cloud detection and response
• Preferred: identity-focused detection experience with Entra, Okta, Active Directory, or similar
• Preferred: hands-on experience with LLM tooling
• Preferred: familiarity with agentic development workflows such as CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar
• Preferred: experience with prompt injection and LLM adversarial thinking
• Competitive base salary
• Bonus opportunities
• 401(k) plan with company matching
• Medical, dental, and vision insurance options
• Short-term disability coverage provided by the company
• Optional long-term disability coverage
• Supplemental life and AD&D insurance for employees and their dependents
• Voluntary accident insurance
• Identity theft protection services
• Wellness and fitness programs
• Company-paid employee assistance program (EAP)
• Generous paid time off, including time for volunteering
• Opportunities for professional development
• SANS training opportunities
• Primarily remote work environment
• Tools and flexibility to excel both professionally and personally
Palo Alto Networks
Pantheon Platform
Convergint
Conduent
Get handpicked remote jobs straight to your inbox weekly.