Security Operations Engineer

MultiPlan

McLean (VA)

On-site

USD 130,000 - 145,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
401k
Bonus opportunity

Job summary

Claritev is seeking a Security Engineer to protect our networks, systems, and data. You will design, implement, and operate security tooling, continuously improving detections, automation, and defensive posture across IT, cloud, and applications.

You will monitor threats, respond to cybersecurity incidents, and collaborate with cross-functional teams to embed security across our infrastructure. A seasoned engineer will drive incident response and threat intelligence initiatives.

Qualifications

  • Bachelor's degree in computer science, information security, or related field, or equivalent practical experience.
  • 5+ years in cybersecurity operations, security engineering, or related role.
  • Strong understanding of networking fundamentals (TCP/IP, DNS, routing, firewalls) and operating systems (Windows, Linux).

Responsibilities

  • Monitor and improve security events across the enterprise using SIEM, EDR, and detection telemetry; triage and respond to incidents.
  • Develop and manage detection rules, correlation logic, and automated playbooks (SOAR) to improve response times.
  • Lead or support incident response efforts, including containment, eradication, and root-cause analysis.
  • Conduct threat hunting and intelligence activities; investigate threats and enrich investigations.

Skills

SIEM experience
EDR/XDR tools
Networking basics
Windows and Linux
Scripting automation
Incident response
MITRE ATT&CK
Cloud security
Communication skills
Independent work

Education

Bachelor's degree in CS/InfoSec

Tools

Splunk
QRadar
SentinelOne
CrowdStrike
Microsoft Defender

Job description

JOB SUMMARY

The Security Engineer is responsible for protecting our organization's networks, systems, and data from evolving threats. In this role, you will design, implement, and operate various security tooling and continuously improve our detections, automation, and defensive posture. The engineer will also be an escalation point for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's technology environment. The engineer works closely with IT, infrastructure, cloud, and application teams to ensure security is embedded across our infrastructure and operations.

JOB ROLES AND RESPONSIBILITIES
Security Monitoring & Detection
  • Monitor, improve, and maintain security events and alerts across the enterprise using SIEM, EDR, and detection telemetry tools; triage and respond to potential incidents in a timely manner.
  • Develop and manage detection rules, correlation logic, and automated playbooks (SOAR) to improve response times.
  • Analyze and tune security tools to reduce false positives and improve detection fidelity.
  • Design, deploy, and maintain security infrastructure, including networking, cloud tooling, endpoint protection, and email security gateways.
  • Analyze and triage security alerts to determine legitimacy, severity, and business impact.
  • Identify and implement detections for indicators of compromise (IOCs), suspicious behavior, and emerging threats.
  • Perform continuous threat monitoring and situational awareness activities.
  • Support penetration testing and red team exercises; validate and remediate identified findings.
  • Develop and document security operating procedures, runbooks, and incident response plans.
  • Stay current on emerging threats, attacker tactics/techniques/procedures (TTPs), and industry best practices (e.g., MITRE ATT&CK).
Incident Response
  • Lead or support incident response efforts, including containment, eradication, recovery, and root‑cause analysis.
  • Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.
  • Execute incident response procedures, best practices, and playbooks.
  • Document findings, actions taken, and lessons learned for post mortems.
  • Escalate significant incidents according to established procedures.
  • Perform vulnerability assessments and coordinate remediation with system and application owners.
Threat Hunting & Intelligence
  • Develop and refine detection use cases based on threat intelligence and incident trends.
  • Conduct threat hunting activities to proactively identify indicators of compromise and advanced persistent threats.
  • Utilize threat intelligence feeds and data analysis to enrich investigations.
  • Research emerging threats, vulnerabilities, and attack techniques.
Security Operations
  • Assist with security architecture reviews for new systems, applications, and cloud deployments.
  • Collaborate with compliance teams to support audits and ensure adherence to relevant frameworks (NIST, ISO 27001, SOC 2, FedRAMP, HITRUST, PCI-DSS, etc.).
  • Provide on‑call support for security incidents outside of normal business hours as needed.
  • And other duties as assigned.
REQUIREMENTS (Education, Experience, and Training)
  • Bachelor's degree in computer science, Information Security, or related field, or equivalent practical experience
  • 5+ years of experience in cybersecurity operations, security engineering, or a related role
  • Strong understanding of networking fundamentals (TCP/IP, DNS, routing, firewalls) and operating systems (Windows, Linux)
  • Hands‑on experience managing SIEM platforms (e.g., Splunk, QRadar, Sentinel) and EDR/XDR tools (e.g., CrowdStrike, SentinelOne, Defender)
  • Experience with incident response methodologies and digital forensics investigations
  • Familiarity with scripting/automation (Python, PowerShell, Bash) for security tooling and response automation
  • Knowledge of common attack techniques, malware behavior, and the MITRE ATT&CK framework
  • Understanding of cloud security concepts (AWS, Azure, or Oracle OCI)
  • Strong analytical, problem‑solving, and communication skills
  • Ability to work independently and manage competing priorities in a fast‑paced environment
Preferred Qualifications
  • Relevant certifications such as GCIH, GCIA, GSEC, GCFA, CEH, CISSP, or OSCP
  • Experience managing SIEM, SOAR, & EDR platforms and security tools
  • Familiarity with managing detection lifecycles and tuning detections
  • Experience with cloud‑native security tools (e.g. External Attack Surface Management (EASM), Continuous Threat Exposure Management (CTEM), GenAI Control Towers, Data Detection, and Secure Email Gateways (SEG))
  • Background in threat intelligence analysis
  • Prior experience in a regulated industry (finance, healthcare, government, defense)
COMPENSATION

The salary range for this position is $130k -145k. Specific offers take into account a candidate's education, experience and skills, as well as the candidate's work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

#LI-MZ1

Why Claritev?
Healthcare is complex. We help make it clearer.

At Claritev, you'll do work that matters. Together, we're helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you're looking for purpose, growth, and a team that succeeds together, you'll find it here.

What Guides Us

At Claritev, innovation, agility, and a focus on results drive our success. We embrace bold thinking, work as one team, take ownership, and strive for excellence in everything we do - creating meaningful impact for our clients, communities, and each other.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Cyber Security Analyst
Cyber Security Analyst

Clinisoltech • Huntsville (AL)

Hybrid
USD 80,000 - 90,000
Security Engineer
Security Engineer

Securiport LLC • Reston (VA)

On-site
USD 110,000 - 170,000
Security Tools Engineer
Security Tools Engineer

Total Quality Logistics • Cincinnati (OH)

On-site
USD 95,000 - 135,000
Performance bonus
Comprehensive benefits package
Health, dental, and vision coverage
+1
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Engineer
Security Engineer

Paylocity • Wayzata (MN)

Hybrid
USD 85,000 - 110,000
Senior Cybersecurity Operations Engineer
Senior Cybersecurity Operations Engineer

Terrestris Global Solutions • Washington

On-site
USD 110,000 - 140,000
Health benefits
Financial benefits
Retirement benefits
+3
Security Operations Center Analyst
Security Operations Center Analyst

Tec-Refresh, Inc. • Andover (MA)

On-site
USD 90,000 - 115,000