Security Engineer

Jobtailor

Town of Montana (WI)

On-site

USD 85,000 - 125,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Wisconsin is seeking a security engineer to build and enhance SOC workflows, SIEM log ingestion, and AI-assisted detection capabilities. You will develop Python automations, tune detection logic, and support incident response across cloud environments.

The role emphasizes collaboration with security, cloud, IT, and engineering teams to improve visibility, reduce risk, and strengthen security operations. A foundational AWS certification and hands-on SIEM experience are preferred.

Qualifications

  • 2-3 years of experience in cybersecurity, SOC operations, security engineering, cloud security, detection engineering, or incident response.
  • Working knowledge of AWS services, cloud security fundamentals, logging, monitoring, IAM, and basic cloud architecture.
  • AWS entry-level certification required at minimum, such as AWS Certified Cloud Practitioner.
  • Hands-on proficiency with Python for scripting, automation, data processing, security tooling, or workflow development.
  • Experience working with SIEM platforms, including log ingestion, parsing, alerting, dashboards, and detection logic.
  • Experience building, maintaining, or troubleshooting log flows from applications, infrastructure, AWS services, endpoint tools, or security platforms into a SIEM.
  • Strong understanding of SOC workflows, alert triage, investigation, escalation, and incident response processes.
  • Ability to help develop, tune, and improve detections based on logs, threat behavior, and operational needs.
  • Familiarity with agentic concepts, agentic frameworks, AI-assisted workflows, autonomous or semi-autonomous agents, and practical security operations use cases.
  • Nice to have: hands-on exposure to LLMs, AI agents, agentic workflows, or AI-assisted security operations
  • Nice to have: experience with Sigma, SPL, KQL, SQL, YARA, or similar detection/query languages
  • Nice to have: familiarity with Terraform, CloudFormation, CDK, or similar tools

Responsibilities

  • Build, maintain, and improve security workflows, integrations, detection processes, and operational tooling within an agentic SOC
  • Work with automation, AI-assisted workflows, and agent-based capabilities supporting alert triage, investigation, enrichment, and response
  • Design, configure, maintain, and troubleshoot SIEM log ingestion flows from AWS, applications, infrastructure, endpoint tools, and security platforms
  • Create, tune, and maintain detection rules, alert logic, dashboards, playbooks, and investigation workflows
  • Develop Python scripts and automations for alert enrichment, data processing, reporting, workflow improvement, and security operations support
  • Support cloud security logging, monitoring, IAM reviews, and cloud detection use cases
  • Review, analyze, and correlate security alerts and logs to identify suspicious activity and support investigations
  • Assist with security event investigations, escalation, containment, remediation, and post-incident improvements
  • Improve SOC processes, playbooks, detection coverage, documentation, and response workflows
  • Partner with security, cloud, IT, and engineering teams to improve visibility, reduce risk, and strengthen security operations

Skills

Python
SIEM
Cloud Security
Detection Engineering
Incident Response
Log Ingestion

Education

AWS Certified Cloud Practitioner

Tools

AWS
Terraform
CloudFormation
CDK
Sigma
SPL
KQL
SQL
YARA

Job description

  • Build, maintain, and improve security workflows, integrations, detection processes, and operational tooling within an agentic SOC
  • Work with automation, AI-assisted workflows, and agent-based capabilities supporting alert triage, investigation, enrichment, and response
  • Design, configure, maintain, and troubleshoot SIEM log ingestion flows from AWS, applications, infrastructure, endpoint tools, and security platforms
  • Create, tune, and maintain detection rules, alert logic, dashboards, playbooks, and investigation workflows
  • Develop Python scripts and automations for alert enrichment, data processing, reporting, workflow improvement, and security operations support
  • Support cloud security logging, monitoring, IAM reviews, and cloud detection use cases
  • Review, analyze, and correlate security alerts and logs to identify suspicious activity and support investigations
  • Assist with security event investigations, escalation, containment, remediation, and post-incident improvements
  • Improve SOC processes, playbooks, detection coverage, documentation, and response workflows
  • Partner with security, cloud, IT, and engineering teams to improve visibility, reduce risk, and strengthen security operations
Requirements
  • 2-3 years of experience in cybersecurity, SOC operations, security engineering, cloud security, detection engineering, or incident response
  • Working knowledge of AWS services, cloud security fundamentals, logging, monitoring, IAM, and basic cloud architecture
  • AWS entry-level certification required at minimum, such as AWS Certified Cloud Practitioner
  • Hands-on proficiency with Python for scripting, automation, data processing, security tooling, or workflow development
  • Experience working with SIEM platforms, including log ingestion, parsing, alerting, dashboards, and detection logic
  • Experience building, maintaining, or troubleshooting log flows from applications, infrastructure, AWS services, endpoint tools, or security platforms into a SIEM
  • Strong understanding of SOC workflows, alert triage, investigation, escalation, and incident response processes
  • Ability to help develop, tune, and improve detections based on logs, threat behavior, and operational needs
  • Familiarity with agentic concepts, agentic frameworks, AI-assisted workflows, autonomous or semi-autonomous agents, and practical security operations use cases
  • Nice to have: hands-on exposure to LLMs, AI agents, agentic workflows, or AI-assisted security operations
  • Nice to have: experience with Sigma, SPL, KQL, SQL, YARA, or similar detection/query languages
  • Nice to have: familiarity with Terraform, CloudFormation, CDK, or similar tools
Core Competencies

Demonstrates expertise in cybersecurity operations, focusing on SOC workflows, cloud security, and detection engineering. Proficient in Python scripting for automation and data processing, with hands-on experience in SIEM platforms and AWS services.

Highest-signal resume keywords
  • Cybersecurity Experience
  • Python Scripting Proficiency
  • SIEM Platform Expertise
  • AWS Services Knowledge
  • SOC Workflow Understanding
Hard Skills
  • Python
  • SIEM
  • Cloud Security
  • Detection Engineering
  • Incident Response
  • Log Ingestion
  • Alert Triage
  • Automation
  • Data Processing
  • Threat Detection
Soft Skills
  • Collaboration
  • Problem-Solving
  • Analytical Thinking
Certifications & Qualifications
  • AWS Certified Cloud Practitioner
Industry Keywords
  • SOC Operations
  • Security Engineering
  • Cloud Architecture
  • IAM
  • AI-Assisted Workflows
Tools & Technologies
  • AWS
  • Terraform
  • CloudFormation
  • CDK
  • Sigma
  • SPL
  • KQL
  • SQL
  • YARA
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Detection and platform engineer
Detection and platform engineer

Tixy Services LLC • Town of Texas (WI), Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Actus Consulting Group • Plano (TX)

On-site
USD 120,000 - 180,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
SOC Engineer
SOC Engineer

Tenex • Sarasota (FL), Scottsdale (AZ), Kansas City (MO)

On-site
USD 90,000 - 140,000
Senior Software Engineer
Senior Software Engineer

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 260,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000