Manager

Torsap Thai Kitchen

Berkeley (CA)

On-site

USD 140,000 - 175,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
PTO
Company holidays
401(k) match
Development stipend

Job summary

Torsap Thai Kitchen is seeking a Senior Security Operations Engineer to strengthen the SOC, threat detection, and incident response across cloud and on‑prem environments. You will design detection rules, automate response playbooks, and collaborate with Infrastructure, DevOps, and Software teams to improve security visibility.

The ideal candidate has 5+ years in security operations, strong expertise with SIEM/EDR, cloud security, and threat hunting, plus hands-on incident handling and forensics

Qualifications

  • Advanced SIEM/EDR/XDR experience.
  • Proficient in Python/Bash/PowerShell for automation.
  • Strong cloud security knowledge (AWS/GCP/Azure).
  • Experience with MITRE ATT&CK, Kill Chain, NIST incident handling.

Responsibilities

  • Design, build, and optimize detection pipelines using SIEM/EDR/logs.
  • Develop automated incident response playbooks (SOAR).
  • Lead proactive threat hunting and forensics investigations.

Skills

SIEM
EDR/XDR
Python
Automation
Cloud security
Threat hunting
Forensics
Team collaboration

Education

Bachelor's degree in Cybersecurity/CS/IT

Tools

Splunk
Elastic
Datadog
CrowdStrike
Wireshark
Docker
Kubernetes

Job description

Job Overview

We are seeking an experienced Senior Security Operations Engineer to strengthen and scale our Security Operations Center (SOC) capabilities, threat detection frameworks, and incident response operations. In this role, you will be responsible for monitoring complex cloud and on-premises environments, engineering high-fidelity detection rules, and automating response playbooks to defend against sophisticated cyber threats. You will collaborate closely with Infrastructure, DevOps, and Software Engineering teams to ensure comprehensive security visibility, proactive threat hunting, and rapid containment of security incidents.

Key Responsibilities

Threat Detection & Security Automation

  • Design, build, and optimize detection engineering pipelines using SIEM, EDR, and log management platforms (e.g., Splunk, Datadog, CrowdStrike).
  • Develop and maintain automated incident response playbooks and orchestration workflows (SOAR) to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
  • Perform proactive threat hunting using threat intelligence feeds, MITRE ATT&CK frameworks, and behavioral analysis to identify undetected malicious activity.

Incident Response & Digital Forensics

  • Serve as an escalation point for high-priority security alerts, leading end-to-end incident response, containment, and forensic investigations.
  • Conduct root-cause analysis following security events, author detailed post-mortem reports, and track long-term remediation action items.
  • Participate in on-call rotations for critical security incidents and lead tabletop exercises to test organizational readiness.

Security Monitoring & Infrastructure

  • Onboard new log sources, data feeds, and cloud services into central monitoring infrastructure, ensuring data integrity and retention compliance.
  • Audit and harden infrastructure, network perimeters, and multi-cloud environments (AWS, GCP, or Azure) against emerging vulnerabilities.
  • Define SOC operational metrics, key risk indicators (KRIs), and executive dashboards to measure security posture and operational efficiency.
Required Skills & Qualifications

Technical Skills & Expertise

  • Security Operations & Detection: Advanced expertise with SIEM solutions (Splunk, Elastic, Datadog), EDR/XDR platforms, and network detection systems.
  • Scripting & Automation: Strong proficiency in Python, Bash, or PowerShell for automating security workflows, log parsing, and API integrations.
  • Cloud & Network Security: Deep understanding of cloud architecture security (AWS/GCP/Azure), container security (Docker, Kubernetes), and network protocols (TCP/IP, DNS, TLS).
  • Frameworks & Methodologies: Applied knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, OWASP Top 10, and NIST Incident Handling guidelines.
  • Forensics & Analysis: Hands‑on experience with memory forensics, log analysis, packet capture analysis (Wireshark), and malware triage.

Soft Skills & Leadership

  • Strong analytical problem‑solving skills with the ability to maintain composure during critical security incidents.
  • Clear communication skills to translate complex security findings into clear actionable advice for technical and non-technical stakeholders.
Preferred Qualifications
  • Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
  • Experience: 5+ years of dedicated experience in security operations, threat detection, or incident response.
  • Certifications: Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA), CISSP, OSCP, or cloud security certifications (AWS Certified Security - Specialty).
Benefits & Compensation
  • Salary Range: $140,000 - $175,000 annually (commensurate with experience).
  • Comprehensive health, dental, and vision insurance coverage.
  • Flexible paid time off (PTO) and paid company holidays.
  • 401(k) retirement savings plan with company match.
  • Annual professional development stipend for security certifications, training, and conferences.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Security Operations
Senior Manager, Security Operations

gomotive • United States

Remote
USD 140,000 - 200,000
Medical, dental, vision coverage
401(k) contributions
Disability & life insurance
+1
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

On-site
USD 110,000 - 150,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

On-site
USD 120,000 - 180,000
Security Operations Center (SOC) Analyst / Engineer
Security Operations Center (SOC) Analyst / Engineer

Zoho • United States

On-site
USD 110,000 - 160,000
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Cyber Security Analyst
Cyber Security Analyst

Clinisoltech • Huntsville (AL)

Hybrid
USD 80,000 - 90,000
Staff Security Analyst
Staff Security Analyst

turing • United States

Remote
USD 198,000 - 242,000
Salary $220,000
Senior IC track