Remote SOC Automation Engineer | Threat Detection & IR

Booz Allen Hamilton

North Dakota

Hybrid

USD 87,000 - 198,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Life insurance
Disability insurance
Tuition assistance
Paid leave
Professional development
Work-life programs
Dependent care

Job summary

Booz Allen Hamilton seeks a Security Operations Center Engineer to design, deploy, and maintain security operations platforms. You will build automated workflows, connect tools via APIs, and implement repeatable responses to threats across Windows and Linux environments.

You will work on incident detection, investigation, and remediation, supporting 24/7 operations and leveraging Tines, ThreatQ, and Andesite to improve threat intelligence and response workflows.

Qualifications

  • Experience designing, building, integrating, or maintaining systems that support security operations.
  • Experience developing automation using scripting languages, APIs, webhooks, or orchestration platforms.
  • Experience integrating security tools, data sources, and operational workflows.
  • Knowledge of incident response, threat detection, investigation, and remediation processes.
  • Knowledge of Windows or Linux system administration.
  • Knowledge of basic IT forensics.
  • Ability to troubleshoot complex systems and integrations.
  • Ability to support 24/7 operations through a shift or on-call schedule.

Responsibilities

  • Design, deploy, integrate, and maintain security operations platforms.
  • Develop automated workflows and playbooks to accelerate detection and response.
  • Connect security tools and data sources through APIs to enable incident workflows.
  • Support 24/7 operations through shifts or on-call coverage.
  • Turn analyst requirements into reliable, repeatable capabilities.

Skills

Security operations systems
Automation scripting
APIs and webhooks
Incident response
Windows administration
Linux administration
IT forensics
Troubleshooting complex integrations

Education

HS diploma or GED

Tools

Tines
ThreatQ
Andesite
Elastic
Splunk
Python
PowerShell
JavaScript

Job description

Booz Allen Hamilton seeks a Security Operations Center Engineer to design, deploy, and maintain security operations platforms. You will build automated workflows, connect tools via APIs, and implement repeatable responses to threats across Windows and Linux environments.

You will work on incident detection, investigation, and remediation, supporting 24/7 operations and leveraging Tines, ThreatQ, and Andesite to improve threat intelligence and response workflows.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote SOC Analyst - Threat Detection & Response
Remote SOC Analyst - Threat Detection & Response

Phase2 Technology • Columbia (MD)

On-site
USD 69,000 - 158,000
SOC Task & Integration Lead — Remote Defender
SOC Task & Integration Lead — Remote Defender

Booz Allen Hamilton • Huntsville (AL)

On-site
USD 113,000 - 257,000
Remote SOC Engineer II - Threat Detection & Incident Lead
Remote SOC Engineer II - Threat Detection & Incident Lead

CTS • United States

On-site
USD 80,000 - 85,000
Health Insurance
401(k) with company match
Paid Time Off
+6
Cybersecurity Automation Engineer - Scale Defenses
Cybersecurity Automation Engineer - Scale Defenses

Booz Allen Hamilton • McLean (VA)

Hybrid
USD 86,000 - 198,000
Senior Security Ops Engineer: Detection & IR Automation
Senior Security Ops Engineer: Detection & IR Automation

StubHub • United States

Hybrid
USD 200,000 - 250,000
Growth environment
Compensation
Flexible time off
+1
Remote Cyber Security SOC Analyst (Tier 2)
Remote Cyber Security SOC Analyst (Tier 2)

Booz Allen Hamilton • Indianapolis (IN)

On-site
USD 69,000 - 158,000
Remote Cloud SOC Analyst: Threat Hunter
Remote Cloud SOC Analyst: Threat Hunter

Booz Allen Hamilton • United States

On-site
USD 99,000 - 225,000
Cloud SOC Analyst - Threat Intel & Incident Response
Cloud SOC Analyst - Threat Intel & Incident Response

Phase2 Technology • San Antonio (TX)

On-site
USD 99,000 - 225,000
SOC Task Lead: Threat Detection & Response
SOC Task Lead: Threat Detection & Response

Phase2 Technology • Huntsville (AL)

Hybrid
USD 113,000 - 257,000
Security Operations Center Engineer
Security Operations Center Engineer

Booz Allen Hamilton • North Dakota

Hybrid
USD 87,000 - 198,000
Health benefits
Life insurance
Disability insurance
+5