
Staff SOC Engineer – Security Telemetry, Detection Platforms
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Missouri.
• Oversee and enhance enterprise security telemetry and detection platforms, which include SIEM, EDR, SOAR, and data pipeline solutions.
• Apply secure-by-default telemetry patterns and logging standards across various operating systems, cloud environments, and network data sources.
• Design, construct, and sustain high-throughput data pipelines for log routing, enrichment, filtering, and transformation into SIEM, archiving, and other destinations.
• Develop SIEM content such as SPL searches, correlation rules, alerts, dashboards, data models, CIM mapping, and RBA where necessary.
• Establish and uphold RBAC, least-privilege models, and user provisioning across telemetry and detection platforms.
• Integrate and automate SOC tools and enterprise systems, including Tines, AWS/Azure/GCP logging, threat intelligence feeds, and ITSM systems.
• Create and maintain system design documents, reference implementations, runbooks, and technical decision records.
• Diagnose complex SIEM/EDR and pipeline issues, minimize noise, and address visibility gaps.
• Assist in incident response through focused searches, log analysis, root-cause identification, and platform expertise during high-severity incidents.
• Enhance control validation, data quality checks, parsing and field-extraction tests, content regression assessments, and platform observability.
• Assess emerging telemetry sources, detection methodologies, and vendor capabilities; develop proofs of concept.
• Support identity, access, and privilege strategies, which include API tokens, service accounts, secrets management, and SSO/SAML/OIDC.
• Convert post-incident insights into backlog items for pipeline fortification, new log sources, and content adjustments.
• Contribute to responsible logging and monitoring for AI-driven applications and platforms.
• Represent security telemetry and detection engineering for the Global Security Office in technical discussions.
• Perform additional tasks as assigned.
• Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience – Required.
• 6+ years of progressive experience in security/infrastructure engineering or SOC engineering focused on SIEM/EDR, telemetry pipelines, and detection content.
• Proven success in deploying and managing SIEM, EDR, SOAR, and data pipeline solutions at an enterprise level, including RBAC, API integrations, and platform hygiene.
• Practical experience in engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources.
• Strong technical foundation and intuitive understanding of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning to decrease ingest volume and enhance signal-to-noise ratio.
• Demonstrated ability to collaborate with security operations, architecture, infrastructure, and product teams; strong stakeholder communication and documentation skills – Required.
• Capability to map and document intricate systems and processes, including data lineage and schema/field mappings – Required.
• Knowledge of NIST frameworks, MITRE ATT&CK, and secure-by-design practices; experience with control validation and metrics/KPIs for continuous enhancement – Required.
• Experience supporting 24/7 SOC operations, including on-call participation and multi-region ingestion scenarios – Required.
• Advanced analytical and problem-solving abilities; proficiency with analysis and diagramming tools such as Lucidcharts, Visio, and Excel – Required.
• Master’s degree in Arts/Sciences (MA/MS) or professional industry certification – Preferred.
• Relevant platform certifications such as Splunk Core/Cloud, Cribl Certified Observability Engineer, or CrowdStrike CCFA/CCFR – Preferred.
• Security certifications such as CISSP, GSEC, GCDA, or Cloud+ – Preferred.
• Experience integrating security telemetry into CI/CD pipelines and applying version control, testing, and staged releases for detections and pipeline modifications – Preferred.
• Proficiency in automation and scripting languages like Python or PowerShell, and familiarity with SOAR tools such as Tines and infrastructure as code solutions like Terraform – Preferred.
• Annual bonus plan.
• Eligibility for long-term equity incentive plans for certain positions.
• Comprehensive health benefits.
• Retirement benefits.
• Additional employee benefits.
• Opportunities to gain knowledge and experience with diverse colleagues globally.
• A respectful and welcoming environment that encourages individuality and innovative thinking.
• Career potential and global opportunities.
Axians Somnitec AG
ASAAS
Motive
Kryptus SA
Get handpicked remote jobs straight to your inbox weekly.