
SNOC Engineer III
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Enhance continuous improvement within SNOC operations by refining monitoring, response workflows, automation, and operational efficiency.
• Act as the primary escalation point for intricate incidents, delivering advanced technical analysis and resolution assistance.
• Create and uphold runbooks, incident response procedures, investigation guides, and knowledge base documentation.
• Identify and assess risks, vulnerabilities, and suspicious activities across network, system, endpoint, identity, and cloud environments.
• Enhance detection logic, fine-tune alerts, and contribute to SIEM analytics rules and automation workflows.
• Mentor junior SNOC engineers during investigations, troubleshooting, and incident response efforts.
• Assist compliance initiatives through precise documentation for audits and reporting purposes.
• Validate and test incident response procedures, disaster recovery plans, and operational readiness exercises.
• Direct high-severity incident investigations and lead containment, eradication, and recovery initiatives.
• Conduct advanced threat analysis utilizing SIEM, EDR, identity protection, and network telemetry platforms.
• Investigate intricate alerts across endpoint, identity, email, cloud, and network platforms.
• Develop detection capabilities, threat hunting queries, alert enrichment logic, and automated response playbooks.
• Collaborate with engineering, infrastructure, and client teams on remediation and long-term risk mitigation strategies.
• Support the onboarding and integration of telemetry from new platforms and technologies.
• Document investigations, incidents, and operational actions in ticketing and case management systems.
• Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred (or equivalent experience).
• Preferred certifications: GIAC (GCIH, GCIA, GCFA).
• Preferred certifications: CompTIA CySA+ or CASP+.
• Preferred certification: Microsoft Certified: Azure Security Engineer Associate.
• Preferred certification: AWS Certified Specialty.
• Preferred certification: Cisco CCNP or equivalent.
• Advanced knowledge of operations, incident investigation, and threat detection methodologies.
• Experience with SIEM and monitoring platforms such as Microsoft Sentinel, Wazuh, SentinelOne, or similar technologies.
• Strong understanding of networking fundamentals, endpoint protection, identity protection, and cloud environments (Azure, AWS, or similar).
• Experience in performing advanced log analysis, threat hunting, and alert triage across various telemetry sources.
• Ability to troubleshoot complex issues and provide leadership during high-severity operational events.
• Strong written and verbal communication skills for internal documentation and client-facing discussions.
• Experience in enhancing monitoring through detection engineering, alert tuning, and automation.
• Familiarity with frameworks, compliance standards, and operational best practices.
• Certification, training, and professional development opportunities.
• Medical, Dental & Vision Coverage.
• Life Insurance.
• 401(k) with company match.
• "You Pick a Day" paid holiday.
• FSA & HSA options.
• Pet Insurance.
• Collaborative, uplifting environment where achievements are celebrated.
Green Energy Venture AG
Abacus Group
EXP
Get handpicked remote jobs straight to your inbox weekly.