Enable job alerts via email!

Security Operations Engineer

Career Techniques

Dallas (TX)

On-site

USD 90,000 - 120,000

Full time

6 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in Dallas is seeking a Security Engineer to enhance their security automation and SIEM capabilities. The ideal candidate will have extensive experience with Microsoft Sentinel and a strong background in security engineering. Responsibilities include developing automation for incident response, improving detection capabilities, and collaborating with various IT teams. This role offers the opportunity to work in a dynamic environment focused on security innovation.

Qualifications

  • 3+ years in a security-related engineering role.
  • 2+ years of SIEM/SOAR Engineering Experience.

Responsibilities

  • Identification and deployment of new detections within the SIEM/SOAR platform.
  • Drive creation and implementation of SIEM content.
  • Continuous testing of SIEM/SOAR platform to identify gaps.

Skills

Automation
Security Automation
Microsoft Security Stack
Incident Response
Data Enrichment
Log Ingestion
DevOps

Education

Bachelor’s degree in Computer Science
Bachelor’s degree in Information Security

Tools

Microsoft Sentinel
Terraform
KQL
Python
PowerShell
Microsoft Power Apps
Azure Functions
Logic Apps

Job description

About the Role

This role is accountable for the architecture, engineering, and automation of in-house security platforms including the Microsoft Sentinel SIEM and associated SOAR tooling. The ideal candidate will have deep technical expertise in the Microsoft security stack and have demonstrated excellence in the development of security automation across domains such as alert triage, response, as well as other security processes such as patch and vulnerability management. They will also work extensively with various IT teams to define appropriate log ingestion, data enrichment, alerting and response actions via the SIEM/SOAR platform. They will also support the Security Operations Center (SOC) for advanced SIEM queries and analytic alerts.

Primary responsibilities in this role include:
  1. Identification of and deployment of new detections or automations within the firm's SIEM / SOAR platform.
  2. Drive creation and implementation of SIEM content (e.g., rules, alerts, dashboards, etc.).
  3. Ensure better analytics via SIEM – improve signal-to-noise ratio in SIEM content. Conduct regular assessments and tuning of Sentinel configurations to reduce false positives and enhance detection capabilities.
  4. Design and implementation of automation for alert enrichment, common detections closure, and response actions.
  5. Benchmarking of existing detections and development of a roadmap for expansion of coverage.
  6. Continuous testing of SIEM / SOAR platform to identify and remediate gaps in detection and prevention coverage.
  7. Integration with the external SOC provider to optimize the partnership and improve detection and response capabilities.
  8. Consolidation of data sources across many Microsoft tenants, systems, and companies into a single source for Security Operations procedures.
  9. Maintenance of all Security Operations tooling to ensure high availability of all log sources.
  10. Partnering with Security Analysts to enhance Security Operations procedures as well as incident response.
  11. Consolidation and automation of Security Operations Metrics from various sources.
  12. Automation of Incident Response processes and workflows.
  13. Development of and adherence to SIEM Engineering change control procedures and processes.
  14. Provide training and support to team members on SIEM functionalities.
Requirements and Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 3+ years in a security-related engineering role
  • 2+ years of SIEM/SOAR Engineering Experience
  • Deep technical understanding of Microsoft Sentinel, Log Analytics, Defender, and other Microsoft security tooling.
  • Demonstrated excellence in the area of security automation.
  • Proficiency with automation tooling (e.g., Terraform) and scripting languages (KQL, Python, PowerShell).
  • Proficiency with Microsoft Power Apps, Azure Functions, Logic Apps, and other Microsoft automation tooling.
  • Proficiency in API development with the goal of integrating security tooling.
  • Familiarity with various log ingestion methodologies into a SIEM environment.
  • Familiarity with automated development lifecycles and pipelines (DevOps).
  • Familiarity with Cisco security tooling including Meraki and Umbrella.
  • Experience in multi-tenant or MSP-like environments is a plus.
  • Possession of or ability to obtain professional certifications in information security or risk management, such as CISSP, CISM, CEH, or forensic certifications.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Operations Engineer

Gainwell Technologies

Town of Texas

Remote

USD 90.000 - 130.000

6 days ago
Be an early applicant

Security Operations Engineer

Gainwell Technologies LLC

Texas

Remote

USD 90.000 - 130.000

3 days ago
Be an early applicant

Warehouse Operations Engineer Opportunity

Serviap Logistics

Dallas

Remote

USD 80.000 - 120.000

5 days ago
Be an early applicant

Security Operations Engineer

Flexera

Remote

USD 70.000 - 120.000

21 days ago

Security Operations Engineer

TRISTAR Insurance Group

California

Remote

USD 105.000 - 105.000

30+ days ago

Security Operations Engineer

Priority Dispatch Corp.

California

Remote

USD 105.000 - 105.000

30+ days ago

Security Operations Engineer

UNIT4 NV

Maine

Remote

USD 80.000 - 100.000

30+ days ago

Infrastructure Operations Engineer II

Duck Creek Technologies

Remote

USD 100.000 - 130.000

Yesterday
Be an early applicant

Staff Security Operations Engineer, Observability & Automation Engineering

Affirm

Denver

Remote

USD 90.000 - 150.000

15 days ago