Security Engineer

Beazley plc

Northern (KY)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary and bonus
Flexible working arrangements
Parental leave – 3 months
Employee insurance premiums covered
401k contribution matching
Career training and conferences

Job summary

Beazley Security is seeking a SOC Operations Engineer to manage and optimise Beazley Group’s EDR/NDR platforms, bridging engineering with SOC operations. You will own the platforms, coordinate upgrades, improve alert fidelity, and assist SOC teams with investigations and containment.

The role requires 3+ years in security operations or related fields, experience with EDR/NDR, and strong collaboration across SOC, infra, and vendors. Flexible working arrangements offered.

Qualifications

  • Minimum 3 years’ experience in security operations, cyber engineering, or platform management.
  • Hands‑on experience administering and optimising leading NDR and EDR platforms.
  • Strong understanding of endpoint telemetry, network analytics, and SOC workflows.
  • Experience planning and performing platform upgrades, integrations, and lifecycle management.
  • Familiarity with MITRE ATT&CK and threat‑hunting principles.
  • Ability to collaborate effectively with SOC analysts, infrastructure teams, and vendors.
  • Excellent documentation, analytical, and communication skills.
  • Experience working within hybrid SOC models (internal + managed service).
  • Exposure to Identity Threat Detection & Response (ITDR) solutions.

Responsibilities

  • Act as the technical owner for SOC systems and operations, ensuring full operational coverage and integration across the enterprise estate.
  • Maintain the physical and virtual infrastructure (appliances, sensors, collectors), planning upgrades, hardware refreshes, and configuration changes as required.
  • Oversee policy, sensor deployment, and version control across all EDR/NDR agents and connectors.
  • Validate data flow and health between endpoints, appliances, and the central XDR platform leveraged by the SOC.
  • Coordinate with the SOC, vendors, and IT infrastructure teams to schedule upgrades, patching, and feature enablement.
  • Tune detection logic, behavioural models, and response policies to reduce false positives and improve threat visibility.
  • Implement target NDR model optimisation, device tagging, and subnet labelling enhancements to support faster investigations.
  • Maintain EDR platform configuration baselines and analytics dashboards.
  • Support integration and data quality within the Beazley Security XDR platform to ensure reliable event correlation.
  • Document all configuration changes, tuning decisions, and engineering work in line with IT Security change management processes.
  • Collaborate closely with the Beazley Security SOC, ensuring they have the right visibility, alert quality, and context to perform effective first-line detection and triage.
  • Serve as part of the escalation group for security cases from the centralized SOC, assisting with containment and isolation activities during incidents where necessary.
  • Provide subject‑matter expertise on EDR and NDR telemetry sources during investigations and post‑incident reviews.
  • Contribute to root‑cause analysis and recommend platform‑level improvements following any potential incidents.
  • Partner with the Threat Intelligence team and MDR organization to proactively hunt for malicious activity and validate emerging TTPs within Beazley’s environment.
  • Feed newly identified patterns back into SOC detection content and threat models.
  • Produce operational and executive reporting across all managed detection platforms.
  • Participate in recurring technical optimisation sessions and quarterly business reviews with vendors.
  • Track detection efficacy, platform uptime, and configuration drift metrics as part of the IT Security KPI set.
  • Continuously assess opportunities for automation, enrichment, and process improvement.

Skills

Security operations
Cyber engineering
Platform management
Endpoint telemetry
Network analytics
SOC workflows
Documentation
Hybrid SOC

Education

CySA+
GCIA
Security certifications

Tools

SQL
PowerShell
Python

Job description

Beazley Security is a global cybersecurity firm committed to helping clients enable advanced cyber defenses that reduce risk with quantifiable results. We’re comprised of top talent from private industry, government, intelligence, and law enforcement who are specialists in threat detection, incident response, digital forensics, offensive security, risk management, and cyber resilience. As a subsidiary of a specialty insurance giant, Beazley Insurance, we’ve been at the forefront of cyber insurance management and breach response activities for business clients in the US, UK, and Europe since 2017. As Beazley Security, the company will have an expanded scope, leveraging nearly two decades of cyber incident experience, a strong services division, and a business strategy focused on growth, to realize our goals and deliver benefits to clients.

As a company, we are committed to upholding our core values of Belonging, Integrity, Service, Accountability, and Curiosity. We believe these values are essential to creating a strong and inclusive workplace culture, as well as to deliver world-class cybersecurity solutions to our clients worldwide. As Beazley Security, these values will continue to thrive, with an extra emphasis on expansion of our capabilities and capacity in helping solve unique client challenges.

Summary:

The SOC Operations Engineer is responsible for the operational management, optimisation, and lifecycle maintenance of Beazley Group’s core Endpoint Detection and Response (EDR) and Network Detection and Response (NDR) platforms. Working within the IT Security function and in close collaboration with the Beazley Security MDR SOC, this role ensures this detection technologies remain effective, resilient, and optimally tuned to support rapid threat detection and response. The position bridges engineering with supporting day to day SOC operations. The individual in this role will be responsible for owning the platforms, coordinating upgrades and enhancements, improving alert fidelity, and assisting the SOC teams with advanced investigations, containment support, and continuous improvement.

Responsibilities:
  • Act as the technical owner for SOC systems and operations, ensuring full operational coverage and integration across the enterprise estate.
  • Maintain the physical and virtual infrastructure (appliances, sensors, collectors), planning upgrades, hardware refreshes, and configuration changes as required.
  • Oversee policy, sensor deployment, and version control across all EDR/NDR agents and connectors.
  • Validate data flow and health between endpoints, appliances, and the central XDR platform leveraged by the SOC.
  • Coordinate with the SOC, vendors, and IT infrastructure teams to schedule upgrades, patching, and feature enablement.
  • Tune detection logic, behavioural models, and response policies to reduce false positives and improve threat visibility.
  • Implement target NDR model optimisation, device tagging, and subnet labelling enhancements to support faster investigations.
  • Maintain EDR platform configuration baselines and analytics dashboards.
  • Support integration and data quality within the Beazley Security XDR platform to ensure reliable event correlation.
  • Document all configuration changes, tuning decisions, and engineering work in line with IT Security change management processes.
  • Collaborate closely with the Beazley Security SOC, ensuring they have the right visibility, alert quality, and context to perform effective first-line detection and triage.
  • Serve as part of the escalation group for security cases from the centralized SOC, assisting with containment and isolation activities during incidents where necessary.
  • Provide subject‑matter expertise on EDR and NDR telemetry sources during investigations and post‑incident reviews.
  • Contribute to root‑cause analysis and recommend platform‑level improvements following any potential incidents.
  • Partner with the Threat Intelligence team and MDR organization to proactively hunt for malicious activity and validate emerging TTPs within Beazley’s environment.
  • Feed newly identified patterns back into SOC detection content and threat models.
  • Produce operational and executive reporting across all managed detection platforms.
  • Participate in recurring technical optimisation sessions and quarterly business reviews with vendors.
  • Track detection efficacy, platform uptime, and configuration drift metrics as part of the IT Security KPI set.
  • Continuously assess opportunities for automation, enrichment, and process improvement.
Key Interfaces:
  • Internal: Head of IT Security, SOC Manager, Incident Response, Infrastructure, Cloud, and Networking teams.
  • External: Beazley Security MDR SOC
Qualifications:
  • Minimum 3 years’ experience in security operations, cyber engineering, or platform management .
  • Hands‑on experience administering and optimising leading NDR and EDR platforms
  • Strong understanding of endpoint telemetry, network analytics, and SOC workflows.
  • Experience planning and performing platform upgrades, integrations, and lifecycle management.
  • Familiarity with MITRE ATT&CK and threat‑hunting principles.
  • Ability to collaborate effectively with SOC analysts, infrastructure teams, and vendors.
  • Excellent documentation, analytical, and communication skills.
  • Experience working within hybrid SOC models (internal + managed service).
  • Exposure to Identity Threat Detection & Response (ITDR) solutions
  • Certifications such as CySA+ , GCIA , or equivalent.
  • Scripting or query language capability (SQL, PowerShell, Python).
Personal Attributes
  • Highly organised and proactive, with strong ownership of assigned technologies.
  • Analytical thinker who thrives on improving systems and processes.
  • Collaborative and approachable, able to bridge operations, engineering, and intelligence teams.
  • Calm under pressure, with a methodical and disciplined approach to incident support.
Beazley Security offers:
  • Competitive salary and bonus.
  • Flexible working arrangements.
  • Generous leave policies including 3 months paid parental.
  • 100% of employee‑only insurance premiums covered (healthcare, dental and vision).
  • Up to 5% matched 401k contribution.
  • Opportunities for career advancement and ongoing training.
  • Participation in industry conferences and events.

Beazley Security is an equal opportunity employer. We embrace diversity and are committed to creating an inclusive environment for all employees

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Beazley Security • United States

Hybrid
USD 110,000 - 150,000
Flexible working
Parental leave (3 months)
Health insurance
+2
SOC Operations Engineer – EDR & NDR Platforms
SOC Operations Engineer – EDR & NDR Platforms

Beazley Security • United States

On-site
USD 80,000 - 100,000
Competitive salary
Flexible working arrangements
Generous leave policies
+4
SOC Operations Engineer: EDR/NDR Platform Lead
SOC Operations Engineer: EDR/NDR Platform Lead

Beazley plc • Northern (KY)

Hybrid
USD 90,000 - 130,000
Competitive salary and bonus
Flexible working arrangements
Parental leave – 3 months
+3
SOC Ops Engineer: EDR/NDR Platform Lead
SOC Ops Engineer: EDR/NDR Platform Lead

Beazley Security • United States

Hybrid
USD 110,000 - 150,000
Flexible working
Parental leave (3 months)
Health insurance
+2
Senior Cybersecurity Consultant, Blue Team Lead
Senior Cybersecurity Consultant, Blue Team Lead

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
SOC Manager (Hands-On) - Remote (USA)
SOC Manager (Hands-On) - Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 110,000 - 140,000
Health, dental, and vision insurance
401(k) with employer contribution
Flexible vacation policy
+1
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Security Operations Engineer
Security Operations Engineer

Yellow Card • Tulsa (OK)

On-site
USD 120,000 - 160,000
SOC 3 Analyst
SOC 3 Analyst

LogicalisUS • Beachwood (OH)

On-site
USD 78,000 - 100,000