Security Engineer

AccruePartners

Charlotte (NC)

On-site

USD 110,000 - 140,000

Full time

8 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AccruePartners is seeking a senior cybersecurity professional to own and advance the organization’s SIEM and security operations environment. You will develop detection content, automate responses with SOAR, and serve as a senior escalation resource for complex incidents.

You will lead tuning across identity, endpoint, cloud and network telemetry, while mentoring Tier 1/2 analysts and coordinating with a 24/7 SOC team.

Qualifications

  • 4+ years in cybersecurity with meaningful Security Operations or Incident Response exposure.
  • 2+ years hands-on experience with an enterprise SIEM platform.
  • Strong experience developing and tuning SIEM analytics rules, alerts, and detection content.
  • Experience operating as a senior engineer, Tier 3 escalation resource, or advanced SOC analyst.
  • Practical experience designing or maintaining SOAR playbooks.
  • Strong understanding of incident response, investigations, evidence collection, and documentation.
  • Automation scripting with PowerShell or Python.
  • Experience integrating endpoint, identity, email, and network telemetry into a SIEM.
  • Knowledge of MITRE ATT&CK framework and common threat techniques.
  • Microsoft Sentinel exposure is valuable; familiarity with other security tools is beneficial.

Responsibilities

  • Own the day-to-day management, health, tuning, and advancement of the organization's SIEM platform.
  • Develop, tune, and maintain detection rules across identity, endpoint, cloud, network, and other telemetry.
  • Serve as a senior escalation resource for complex or high-severity cybersecurity incidents.
  • Conduct technical investigations, root-cause analysis, and forensic review as needed.
  • Design and build SOAR playbooks that automate repetitive response activities.
  • Develop automation workflows using PowerShell or Python.
  • Evaluate and onboard new log sources, integrations, data connectors, and threat intelligence feeds.
  • Partner with identity, endpoint, infrastructure, and network teams to maintain security visibility.
  • Review alerts to improve detection quality and reduce false positives.

Skills

SIEM analytics
Incident response
SOAR playbooks
PowerShell/Python scripting
Threat detection
Mentorship

Education

Security certifications preferred

Tools

Microsoft Sentinel
SentinelOne
Proofpoint
Red Canary

Job description

THE TEAM YOU WILL BE JOINING
  • Established enterprise organization continuing to invest in and expand its Information Security function
  • Growing security team that is creating clearer specialization across Security Engineering, Security Operations, and Governance, Risk & Compliance
  • Collaborative environment working alongside internal security engineers and a dedicated 24/7 Security Operations team
  • Opportunity to join a team that is actively modernizing its security operations capabilities, detection strategy, and automation
  • Highly visible role with direct impact on how the organization detects, investigates, and responds to cybersecurity threats
What They Offer You
  • Direct-hire opportunity with a growing Information Security organization
  • Ability to take meaningful ownership of the organization's SIEM and security operations environment
  • Opportunity to build and improve detection content rather than simply monitor alerts
  • Significant exposure to security automation, orchestration, incident response, and threat detection
  • Ability to influence the future direction of the organization's security technology stack
  • Opportunity to serve as a senior technical resource while partnering with a broader 24/7 SOC operation
What You Will Do
  • Own the day-to-day management, health, tuning, and advancement of the organization's SIEM platform
  • Develop, tune, and maintain detection rules across identity, endpoint, cloud, network, and other security telemetry
  • Serve as a senior escalation resource for complex or high-severity cybersecurity incidents
  • Conduct technical investigations, root-cause analysis, and forensic review as needed
  • Design and build SOAR playbooks that automate repetitive response activities and improve detection and response times
  • Develop automation and enrichment workflows using tools such as PowerShell, Python, or similar scripting languages
  • Evaluate and onboard new log sources, integrations, data connectors, and threat intelligence feeds
  • Partner with identity, endpoint, infrastructure, and network teams to maintain appropriate security visibility
  • Review security alerts and identify opportunities to improve detection quality, reduce false positives, and strengthen response processes
  • Maintain documentation for detection logic, incident response procedures, automation, and security operations workflows
  • Provide technical guidance and mentorship to Tier 1 and Tier 2 security analysts
  • Participate in incident response activities and an on-call rotation when required
BACKGROUND PROFILE
  • 4+ years of cybersecurity experience with meaningful Security Operations or Incident Response exposure
  • 2+ years of hands-on experience working with an enterprise SIEM platform
  • Strong experience developing and tuning SIEM analytics rules, alerts, and detection content
  • Experience operating as a senior engineer, Tier 3 escalation resource, or advanced SOC analyst
  • Practical experience designing or maintaining SOAR playbooks
  • Strong understanding of incident response, investigations, evidence collection, and documentation
  • Scripting and automation experience using PowerShell, Python, or similar technologies
  • Experience integrating technologies such as endpoint security, identity, email security, and network telemetry into a SIEM
  • Working understanding of the MITRE ATT&CK framework and common threat tactics and techniques
  • Microsoft security ecosystem experience is valuable; the current environment includes Microsoft Sentinel
  • Exposure to tools such as SentinelOne, Red Canary, Proofpoint, or comparable security technologies is beneficial
  • Relevant cybersecurity certification such as Security+, CySA+, GCIH, GCIA, or comparable certification preferred
LOCATION
  • Fort Mill, SC
  • Onsite

Open

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
IT Security Engineer
IT Security Engineer

Pike Corporation • Fort Mill (SC)

On-site
USD 120,000 - 180,000
Manager
Manager

Apexcare Talent Solutions • Berkeley (CA)

On-site
USD 140,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+4
Information Security Analyst
Information Security Analyst

Cisive Inc. • Maryland

On-site
USD 90,000 - 130,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

EXOS • Indianapolis (IN)

On-site
USD 100,000 - 140,000
SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

PowerGrid Services, LLC • Hartselle (AL), Northern (KY)

Hybrid
USD 80,000 - 110,000