Staff SOC Engineer – Security Telemetry, Detection Platforms

Posted 16 hours ago

This is a fully remote position, open to applicants in Missouri.

📋 Description

• Oversee and enhance enterprise security telemetry and detection platforms, which include SIEM, EDR, SOAR, and data pipeline solutions.

• Apply secure-by-default telemetry patterns and logging standards across various operating systems, cloud environments, and network data sources.

• Design, construct, and sustain high-throughput data pipelines for log routing, enrichment, filtering, and transformation into SIEM, archiving, and other destinations.

• Develop SIEM content such as SPL searches, correlation rules, alerts, dashboards, data models, CIM mapping, and RBA where necessary.

• Establish and uphold RBAC, least-privilege models, and user provisioning across telemetry and detection platforms.

• Integrate and automate SOC tools and enterprise systems, including Tines, AWS/Azure/GCP logging, threat intelligence feeds, and ITSM systems.

• Create and maintain system design documents, reference implementations, runbooks, and technical decision records.

• Diagnose complex SIEM/EDR and pipeline issues, minimize noise, and address visibility gaps.

• Assist in incident response through focused searches, log analysis, root-cause identification, and platform expertise during high-severity incidents.

• Enhance control validation, data quality checks, parsing and field-extraction tests, content regression assessments, and platform observability.

• Assess emerging telemetry sources, detection methodologies, and vendor capabilities; develop proofs of concept.

• Support identity, access, and privilege strategies, which include API tokens, service accounts, secrets management, and SSO/SAML/OIDC.

• Convert post-incident insights into backlog items for pipeline fortification, new log sources, and content adjustments.

• Contribute to responsible logging and monitoring for AI-driven applications and platforms.

• Represent security telemetry and detection engineering for the Global Security Office in technical discussions.

• Perform additional tasks as assigned.


⛳️ Requirements

• Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience – Required.

• 6+ years of progressive experience in security/infrastructure engineering or SOC engineering focused on SIEM/EDR, telemetry pipelines, and detection content.

• Proven success in deploying and managing SIEM, EDR, SOAR, and data pipeline solutions at an enterprise level, including RBAC, API integrations, and platform hygiene.

• Practical experience in engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources.

• Strong technical foundation and intuitive understanding of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning to decrease ingest volume and enhance signal-to-noise ratio.

• Demonstrated ability to collaborate with security operations, architecture, infrastructure, and product teams; strong stakeholder communication and documentation skills – Required.

• Capability to map and document intricate systems and processes, including data lineage and schema/field mappings – Required.

• Knowledge of NIST frameworks, MITRE ATT&CK, and secure-by-design practices; experience with control validation and metrics/KPIs for continuous enhancement – Required.

• Experience supporting 24/7 SOC operations, including on-call participation and multi-region ingestion scenarios – Required.

• Advanced analytical and problem-solving abilities; proficiency with analysis and diagramming tools such as Lucidcharts, Visio, and Excel – Required.

• Master’s degree in Arts/Sciences (MA/MS) or professional industry certification – Preferred.

• Relevant platform certifications such as Splunk Core/Cloud, Cribl Certified Observability Engineer, or CrowdStrike CCFA/CCFR – Preferred.

• Security certifications such as CISSP, GSEC, GCDA, or Cloud+ – Preferred.

• Experience integrating security telemetry into CI/CD pipelines and applying version control, testing, and staged releases for detections and pipeline modifications – Preferred.

• Proficiency in automation and scripting languages like Python or PowerShell, and familiarity with SOAR tools such as Tines and infrastructure as code solutions like Terraform – Preferred.


🏝️ Benefits

• Annual bonus plan.

• Eligibility for long-term equity incentive plans for certain positions.

• Comprehensive health benefits.

• Retirement benefits.

• Additional employee benefits.

• Opportunities to gain knowledge and experience with diverse colleagues globally.

• A respectful and welcoming environment that encourages individuality and innovative thinking.

• Career potential and global opportunities.

People also viewed

Axians Somnitec AG11 hours ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
ASAAS12 hours ago

Mid-Level SOC Analyst – Evening Shift

BR flagBrazil OnlyFull-timeSecurity Operations
ApplyView job
Motive12 hours ago

Senior Manager, Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$140k – $200k/year
ApplyView job
Kryptus SA18 hours ago

Security/SecOps Analyst – SIEM/Sentinel

BR flagBrazil OnlyFull-timeSecurity Operations
ApplyView job
Axians Somnitec AG20 hours ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
Axians20 hours ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers