Overview
🌙 Senior SOC Security Engineer – Application & Supply Chain Security
Remote (U.S. Only) | Night Shift | SOC • AppSec • Software Supply Chain Security #TS-9035
- Our client, an AWS partnered analytics organization, owns the world’s largest financial data store and runs continuous analytics on global stock data movement with the goal of being ahead of potential bad actors in the market. Highlights:
- We own the world’s largest financial store (37 petabytes and growing) and look at 155+ billion financial transactions daily— more than Twitter, Visa®, PayPal and Facebook combined.
- Leading Innovator in Machine Learning/AI, Big Data, AWS, trading algorithms
- AWS- select Partner: forging one of the biggest and most unique partnerships formed with AWS.
- Deep culture of internal upskilling
- Named 2020 #1 best place to work for US organizations with up to 5k employees.
Must Haves
Mid-Sr SOC analyst with ideally a good understanding of supply chain security
- SOC
- AppSec
- Supply chain security – can drive this security aspect ßmay consider great SOC person w/ no security supply chain but not sure . Examples of tools used in supply chain security are jFrog curation and Socket.Dev but it doesn’t have to be these.
We are expanding our 24/7 Security Operations Center and are hiring a Senior SOC Security Engineer with strong application security and software supply chain security experience. This role blends real-time incident response with proactive security engineering, focused on protecting applications, dependencies, and cloud environments at scale.
This is an excellent opportunity for a mid-to-senior SOC professional who wants to go beyond alerts and play a key role in shaping modern security practices across AppSec, DevSecOps, and software supply chain risk.
- Hours: 11:00 PM – 8:00 AM EST
- Schedule: Sunday–Thursday nights
- When scheduled for a weekend, the preceding Friday and following Monday are off
- Location: Fully remote, anywhere in the U.S.
What You’ll Do
- Monitor, detect, and respond to security incidents in a 24x7 SOC environment
- Lead investigations into software supply chain security (SSCS) threats, including:
- Compromised or malicious packages
- Backdoored libraries and third-party risks
- Design and implement security controls for third-party software dependencies and open-source components
- Perform threat hunting for emerging attack vectors
- Conduct vulnerability analysis of third-party CVEs and assess exploitability and reachability in an enterprise context
- Collaborate with engineering and DevOps teams to drive remediation and integrate security into CI/CD pipelines
- Develop detection logic, threat models, and SOC use cases focused on application and supply chain threats
- Lead incident response for identity-based attacks and application-level compromises
- Mentor junior SOC analysts and provide technical guidance during investigations
Required Experience
- Strong background in SOC operations and incident response
- Experience working with application security concepts and tooling
- Familiarity with software supply chain security risks
- Experience with SIEM and EDR tools such as:
- Splunk, Sentinel, QRadar
- CrowdStrike or similar
- Strong understanding of OWASP Top 10, secure coding practices, and remediation
- Experience working in cloud environments (AWS, Azure, or GCP)
- Ability to work independently and make decisions during off-hours
Nice to Have / Bonus Skills
- Hands-on experience with Software Composition Analysis (SCA) tools
- Exposure to artifact repositories and dependency management tools
- Familiarity with package managers (npm, PyPI, Maven, NuGet, etc.)
- Experience integrating security into DevSecOps pipelines
- Tools such as JFrog Xray, Socket.dev, or similar supply-chain security platforms
- Security certifications such as:
- CISSP, CSSLP, OSCP, GIAC, CASE
What Makes This Role Different
- Real ownership of application and supply chain security
- Opportunity to grow into a technical SOC leadership role
Who Will Succeed Here
- SOC analysts ready to operate at a senior, investigative level
- AppSec or DevSecOps engineers interested in real-time threat response
- Security professionals who enjoy deep technical analysis, not just ticket handling
- Self-starters comfortable working overnight shifts in a high-trust environment