Engineer, Security

11:11 Systems

United States

On-site

USD 120,000 - 160,000

Full time

19 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

11:11 Systems is seeking an experienced Security Engineer to join our Security Operations team. You will support, build, and refine the systems and processes powering our global SOC, delivering 24/7 monitoring, support, and escalation for customers.

Responsibilities include developing detection rules, serving as escalation point, incident response advisory, and driving improvements across SIEM/EDR/SOAR stacks. Requires 5+ years in info security and strong Azure Sentinel/Cortex XDR experience.

Qualifications

  • 5+ years in information security, including 3+ years in information technology.
  • 3+ years' experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools (focus on Azure Sentinel, Cortex XDR, and Tenable).
  • Analyst-level experience in the telecom and/or enterprise cybersecurity industry.
  • 1+ years' experience with Python scripting or development.
  • 1+ years' experience with Linux administration and troubleshooting.
  • Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.
  • Experience with enterprise security architecture, detection, and response.
  • Mature understanding of industry-standard incident response practices and SOC operations.
  • Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
  • Experience with Kubernetes.
  • Experience with Palo Alto products (Cortex XDR, Panorama, next-gen firewalls).
  • Experience with ThreatX or similar WAF platforms.
  • Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
  • Working knowledge of security frameworks (ISO, NIST, CIS, etc.).
  • Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
  • Up-to-date knowledge of attacker tactics, techniques, and procedures.
  • Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work.
  • Must be a US Citizen and legally eligible to work in the US without visa sponsorship.

Responsibilities

  • Support SOC management in setting goals and developing policies for timely detection and response.
  • Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
  • Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts.
  • Provide first responder incident response advisory support for clients within 11:11 Systems' scope.
  • Own the timeliness and accuracy of critical incident identification, advisement, and reporting.
  • Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs.
  • Drive implementation and continuous improvement of new technologies, capabilities, frameworks, and methodologies.
  • Develop and maintain customer-facing security stacks (SIEM, EDR, SOAR, WAF, vulnerability scanning) and architect improvements.
  • Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team.
  • Advise on and help build SOC analyst training programs; provide cross-functional training as needed.
  • Stay current on emerging threats, risks, and exploits, and translate into updated SIEM detection rulesets.
  • Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.
  • Participate in an on-call rotation for after-hours support.
  • Work in alignment with 11:11's Code of Business Ethics and Company Values, including responsible data handling and training.

Skills

Python scripting
Linux administration
SOC operations
Incident response
Networking fundamentals
KQL
Communication

Education

Security Certifications (Security+, CySA+, CASP+, CISSP, GCIH)

Tools

Azure Sentinel
Cortex XDR
Tenable
Kubernetes
Palo Alto Cortex XDR
Panorama
ThreatX

Job description

The Role

11:11 Systems is looking for an experienced Security Engineer to join our Security Operations team. In this role, you'll support, build, and refine the systems and processes that power our global Security Operations Center (SOC), delivering 24/7 monitoring, support, and escalation for our customers.


You'll also serve as an escalation point for the SOC team and play a key role in reviewing high-severity customer incidents, including participation in an on-call rotation. We're looking for someone with a strong Security Engineering background, prior analyst experience in the telecom and/or enterprise cybersecurity industry, a knack for driving system and process efficiency, and a proactive mindset toward continuous improvement.


Responsibilities


  • Support SOC Management in setting tactical and operational goals, and in developing policies and procedures for timely detection, assessment, reporting, and response to security events.

  • Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.

  • Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts.

  • Provide \"first responder\" incident response advisory support for clients experiencing security incidents, within the scope of 11:11 Systems' software and systems (not a Digital Forensics and Incident Response role).

  • Own the timeliness and accuracy of critical incident identification, advisement, and reporting, both internally and to customers.

  • Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs.

  • Drive implementation and continuous improvement of new technologies, capabilities, frameworks, and methodologies.

  • Develop and maintain customer-facing security stacks (SIEM, EDR, SOAR, WAF, vulnerability scanning) and architect technical improvements to existing processes.

  • Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team.

  • Advise on and help build SOC analyst training programs; provide cross-functional training as needed.

  • Stay current on emerging threats, risks, and exploits, and translate that knowledge into updated SIEM detection rulesets.

  • Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.

  • Participate in an on-call rotation for after-hours support.

  • Work in alignment with 11:11's Code of Business Ethics and Company Values, including responsible data handling and completion of required compliance training.


Qualifications


  • 5+ years in information security, including 3+ years in information technology.

  • 3+ years' experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools (focus on Azure Sentinel, Cortex XDR, and Tenable).

  • Analyst-level experience in the telecom and/or enterprise cybersecurity industry.

  • 1+ years' experience with Python scripting or development.

  • 1+ years' experience with Linux administration and troubleshooting.

  • Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.

  • Experience with enterprise security architecture, detection, and response.

  • Mature understanding of industry-standard incident response practices and SOC operations.

  • Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.

  • Experience with Kubernetes.

  • Experience with Palo Alto products (Cortex XDR, Panorama, next-gen firewalls).

  • Experience with ThreatX or similar WAF platforms.

  • Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.

  • Working knowledge of security frameworks (ISO, NIST, CIS, etc.).

  • Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.

  • Up-to-date knowledge of attacker tactics, techniques, and procedures.

  • Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work.

  • Must be a US Citizen and legally eligible to work in the US without visa sponsorship.


To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Senior SOC Engineer
Senior SOC Engineer

TRG • Westlake (OH)

Hybrid
USD 110,000 - 160,000
Security Engineer II
Security Engineer II

The CORE Institute • Phoenix (AZ)

On-site
USD 110,000 - 160,000
Senior SOC Engineer
Senior SOC Engineer

Inversion6 • Westlake (OH)

Hybrid
USD 110,000 - 150,000
Network Security Analyst – Level 1
Network Security Analyst – Level 1

Jobtailor • Austin (TX)

On-site
USD 95,000 - 130,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000