SOC Engineer

Quzara LLC

United States

Remote

USD 120,000 - 150,000

Full time

43 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Quzara LLC seeks a hands-on SOC Engineer to onboard customers into our managed security services and maintain their security tooling and telemetry. You will work with customers and internal teams to integrate data sources, configure Microsoft security services, automate workflows, and resolve issues in federal and regulated environments.

The role requires 5+ years in IT infrastructure or security, 3+ years with Microsoft Azure, and 2+ years with Microsoft Sentinel or another enterprise SIEM.

Qualifications

  • Bachelor's degree preferred or equivalent experience.
  • 5+ years in IT infrastructure, cloud, or security engineering, including 3+ years hands-on with Microsoft Azure.
  • 2+ years with Microsoft Sentinel or a comparable enterprise SIEM with data-source onboarding.
  • Strong working knowledge of the Microsoft security stack (Sentinel, Defender XDR, Entra ID, Azure Monitor / Log Analytics) and multi-tenant access.
  • Hands-on experience onboarding data sources (identity, endpoints, firewalls, SaaS, Syslog/CEF, API) from Azure, AWS, and Google Workspace.
  • Experience across multiple SIEM platforms (Microsoft Sentinel, Splunk, SentinelOne, IBM QRadar).
  • Proficiency in KQL and scripting (PowerShell or Python).
  • Strong written and customer-facing communication skills.
  • AZ-500 or SC-200 certification (current).
  • Preferred: MSSP/MDR experience; GCC/GCC High environments; CrowdStrike or SentinelOne experience.

Responsibilities

  • Lead onboarding of new customers from discovery through configuration and handoff.
  • Configure and integrate Microsoft security services (Sentinel, Defender XDR, Entra ID) with customer environments.
  • Onboard and validate security telemetry from identity, endpoints, networks, SaaS, and multi-cloud sources (Azure, AWS, Google Workspace).
  • Integrate and troubleshoot log sources across SIEMs (Microsoft Sentinel, Splunk, SentinelOne, IBM QRadar).
  • Troubleshoot ingestion and integration issues across cloud, identity, network, Windows, and Linux layers.
  • Build automation and scripts to make onboarding and operations repeatable.
  • Support customers under FedRAMP, CMMC, and NIST frameworks.
  • Produce clear technical documentation and resolve onboarding blockers with stakeholders.

Education

Bachelor's degree or equivalent experience

Tools

Microsoft Sentinel
Defender XDR
Entra ID
Azure Monitor / Log Analytics
PowerShell
Python
KQL
Splunk
IBM QRadar

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

FULL TIME Professional Remote, US

Salary Range: $120,000.00 To $150,000.00 Annually

Job Title:SOC Engineer

Pay Type: SALARIED EXEMPT

Location:Remote (Must Work East Coast Hours)

Summary of Position Role/Responsibilities

Quzara is seeking a hands-on SOC Engineer to onboard customers into our managed security services and keep their security tooling and telemetry running reliably. The SOC Engineer works with customers and internal teams to integrate data sources, configure Microsoft security services, automate workflows, and resolve technical issues in federal and regulated environments.

Essential Functions of the Job
  • Lead technical onboarding of new customers, from discovery and requirements through configuration, validation, and handoff.
  • Configure and integrate Microsoft security services, including Microsoft Sentinel, Defender XDR, and Entra ID, with customer environments.
  • Onboard and validate security telemetry from identity, endpoint, network, SaaS, and multi-cloud sources, including Azure, AWS, and Google Workspace.
  • Integrate and troubleshoot log sources across multiple SIEM platforms, including Microsoft Sentinel, Splunk, SentinelOne, and IBM QRadar.
  • Troubleshoot ingestion and integration issues across cloud, identity, network, Windows, and Linux layers.
  • Build automation and scripts that make onboarding and operations repeatable.
  • Support customers operating under federal and regulated requirements, including FedRAMP, CMMC, and NIST frameworks.
  • Produce clear technical documentation and work directly with customer stakeholders to resolve onboarding blockers.
Marginal Functions of the Job
  • Other duties as assigned
Normal Work Schedule

This full-time role runs Monday to Friday, 8:30 AM–5:30 PM and requires flexibility to work remotely or on-site (if applicable per client RTO policies). On occasion additional hours may be necessary.

Education, Training, and Experience
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience.
  • 5+ years in IT infrastructure, cloud, or security engineering, including 3+ years hands-on with Microsoft Azure.
  • 2+ years with Microsoft Sentinel or a comparable enterprise SIEM, including data-source onboarding.
  • Strong working knowledge of the Microsoft security stack (Sentinel, Defender XDR, Entra ID, Azure Monitor / Log Analytics) and multi-tenant delegated access (Azure Lighthouse, GDAP).
  • Hands-on experience onboarding a wide range of data sources (identity providers, endpoints, firewalls and network devices, SaaS applications, Syslog/CEF, API, and agent-based integrations) from Azure, AWS, and Google Workspace / Google Cloud.
  • Experience working across multiple SIEM platforms, such as Microsoft Sentinel, Splunk, SentinelOne, IBM QRadar, or similar.
  • Proficiency in KQL and scripting (PowerShell or Python), with solid troubleshooting skills across Windows, Linux, networking, and identity.
  • Strong written and customer-facing communication skills.
  • At least one current certification required: AZ-500 or SC-200.
  • Preferred: prior MSSP, MDR, or security consulting experience; experience supporting federal or defense-industrial-base customers, including GCC and GCC High environments; and experience with EDR/XDR platforms such as CrowdStrike or SentinelOne.
Preferred Certifications
  • Ideal: SC-100 (Microsoft Cybersecurity Architect Expert).
  • Microsoft: AZ-104 (Azure Administrator), AZ-305 (Azure Solutions Architect Expert), SC-300 (Identity and Access Administrator), SC-401 (Information Security Administrator), MS-102 (Microsoft 365 Administrator).
  • Cloud security: AWS Certified Security – Specialty, Google Professional Cloud Security Engineer.
  • SIEM / EDR: Splunk Enterprise Security Certified Admin, IBM QRadar SIEM, SentinelOne, or CrowdStrike Falcon (CCFA) certifications, or equivalent.
  • General security: CISSP, CCSP, CompTIA Security+ or CySA+, GIAC (GCDA, GCIH, or GCED).
EEO Statement

The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Customer Onboarding Engineer (Security & Comp
Customer Onboarding Engineer (Security & Comp

Quzara LLC • United States

Remote
USD 105,000 - 145,000
SOC Engineer
SOC Engineer

Constellation GovCloud • McLean (VA)

On-site
USD 120,000 - 170,000
On-site gym
Medical, dental, and vision insurance
FSA and EAP
+2
SOC Engineer
SOC Engineer

Merlin Group • McLean (VA)

On-site
USD 120,000 - 150,000
On-site gym & wellness benefits
401(k) with employer match
SOC Engineer
SOC Engineer

CGC • McLean (VA), Northern (KY)

Hybrid
USD 120,000 - 160,000
On-site gym and health insurance
401(k) with employer match
Unlimited PTO
SOC Engineer
SOC Engineer

Merlin International Inc • McLean (VA)

On-site
USD 110,000 - 140,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
SOC Engineer
SOC Engineer

Amentum • Ellicott City (MD)

On-site
USD 145,000 - 190,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+6
SOC Engineer
SOC Engineer

Bayview Fund Management, LLC • Coral Gables (FL)

On-site
USD 160,000 - 180,000
Remote role
Bonus eligibility
SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
Security Operations Center Technical SME
Security Operations Center Technical SME

Athletes Global Corporation • United States

On-site
USD 160,000 - 177,000
Health insurance
Health savings account