SOC Security Engineer: Detection & Response

11:11 Systems

United States

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

11:11 Systems is seeking an experienced Security Engineer to join our Security Operations team. You will support, build, and refine the systems and processes powering our global SOC, delivering 24/7 monitoring, support, and escalation for customers.

Responsibilities include developing detection rules, serving as escalation point, incident response advisory, and driving improvements across SIEM/EDR/SOAR stacks. Requires 5+ years in info security and strong Azure Sentinel/Cortex XDR experience.

Qualifications

  • 5+ years in information security, including 3+ years in information technology.
  • 3+ years' experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools (focus on Azure Sentinel, Cortex XDR, and Tenable).
  • Analyst-level experience in the telecom and/or enterprise cybersecurity industry.
  • 1+ years' experience with Python scripting or development.
  • 1+ years' experience with Linux administration and troubleshooting.
  • Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.
  • Experience with enterprise security architecture, detection, and response.
  • Mature understanding of industry-standard incident response practices and SOC operations.
  • Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
  • Experience with Kubernetes.
  • Experience with Palo Alto products (Cortex XDR, Panorama, next-gen firewalls).
  • Experience with ThreatX or similar WAF platforms.
  • Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
  • Working knowledge of security frameworks (ISO, NIST, CIS, etc.).
  • Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
  • Up-to-date knowledge of attacker tactics, techniques, and procedures.
  • Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work.
  • Must be a US Citizen and legally eligible to work in the US without visa sponsorship.

Responsibilities

  • Support SOC management in setting goals and developing policies for timely detection and response.
  • Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
  • Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts.
  • Provide first responder incident response advisory support for clients within 11:11 Systems' scope.
  • Own the timeliness and accuracy of critical incident identification, advisement, and reporting.
  • Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs.
  • Drive implementation and continuous improvement of new technologies, capabilities, frameworks, and methodologies.
  • Develop and maintain customer-facing security stacks (SIEM, EDR, SOAR, WAF, vulnerability scanning) and architect improvements.
  • Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team.
  • Advise on and help build SOC analyst training programs; provide cross-functional training as needed.
  • Stay current on emerging threats, risks, and exploits, and translate into updated SIEM detection rulesets.
  • Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.
  • Participate in an on-call rotation for after-hours support.
  • Work in alignment with 11:11's Code of Business Ethics and Company Values, including responsible data handling and training.

Skills

Python scripting
Linux administration
SOC operations
Incident response
Networking fundamentals
KQL
Communication

Education

Security Certifications (Security+, CySA+, CASP+, CISSP, GCIH)

Tools

Azure Sentinel
Cortex XDR
Tenable
Kubernetes
Palo Alto Cortex XDR
Panorama
ThreatX

Job description

11:11 Systems is seeking an experienced Security Engineer to join our Security Operations team. You will support, build, and refine the systems and processes powering our global SOC, delivering 24/7 monitoring, support, and escalation for customers.

Responsibilities include developing detection rules, serving as escalation point, incident response advisory, and driving improvements across SIEM/EDR/SOAR stacks. Requires 5+ years in info security and strong Azure Sentinel/Cortex XDR experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Security Engineer - SIEM/IR & Automation
Senior SOC Security Engineer - SIEM/IR & Automation

Socket.dev • United States

Remote
USD 120,000 - 180,000
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
SOC Security Engineer - Threat Detection & Response
SOC Security Engineer - Threat Detection & Response

Access Search, Inc. • Tinley Park (IL)

On-site
USD 100,000 - 140,000
SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Senior SOC Analyst: Threat Detection & Incident Response
Senior SOC Analyst: Threat Detection & Incident Response

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Security Engineer II — SOC & Threat Intel Lead
Security Engineer II — SOC & Threat Intel Lead

Socket.dev • Phoenix (AZ)

On-site
USD 110,000 - 150,000
Remote SOC Engineer II - Threat Detection & Incident Lead
Remote SOC Engineer II - Threat Detection & Incident Lead

CTS • United States

On-site
USD 80,000 - 85,000
Health Insurance
401(k) with company match
Paid Time Off
+6
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000