Staff SOC Engineer — Telemetry & Detection Platforms

RGA

Missouri

Hybrid

USD 127,000 - 189,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Annual bonus plan
Health benefits
Retirement benefits

Job summary

RGA is seeking a Staff SOC Engineer to design, implement, and optimize security telemetry and detection platforms across hybrid environments. You will build and maintain data pipelines, SIEM content, and RBAC controls while collaborating with security operations, architecture, and product teams.

The role emphasizes secure-by-design data collection, scalable controls, and measurable outcomes to advance SOC maturity and support regulatory compliance.

Qualifications

  • 6+ years of progressive experience in security/infrastructure engineering or SOC engineering focused on SIEM/EDR, telemetry pipelines, and detection content
  • Demonstrated success deploying and operating SIEM, EDR, SOAR, and data pipeline solutions at enterprise scale, including RBAC, API integrations, and platform hygiene
  • Hands‑on experience engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources
  • Strong technical background and tacit understanding of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning to reduce ingest volume and improve signal to noise

Responsibilities

  • Administer and engineer improvements to enterprise security telemetry and detection platforms- including SIEM, EDR, SOAR, and data pipeline solutions - ensuring reliability, performance, and cost efficiency
  • Implement secure by default telemetry patterns and logging standards across operating systems, cloud, and network data sources
  • Design, build, and maintain data pipelines (Routes, Pipelines, Packs) for secure, cost managed, and high throughput log routing, enrichment, filtering, and transformation into SIEM, archive, and other destinations
  • Engineer SIEM content (SPL searches, correlation rules, alerts, dashboards, data models, CIM mapping, RBA where applicable) with an emphasis on signal quality, performance, and SLO/KPI driven cost control
  • Define and maintain role-based access controls (RBAC), least privilege models, and user provisioning across telemetry and detection platforms to enable auditable operations
  • Contribute to integration and automation across SOC tooling and enterprise systems (e.g., Tines, cloud native logging in AWS/Azure/GCP, threat intel feeds, ticketing/ITSM) to streamline detection, enrichment, and response workflows
  • Author and maintain explicit documentation - including system design documents, reference implementations, runbooks, and technical decision records capturing rationale, architecture, and operational procedures
  • Apply tacit understanding of SIEM/EDR behavior, data schemas, and pipeline constraints to troubleshoot complex issues, reduce noise, and close visibility gaps
  • Participate in incident response by developing targeted searches, conducting log analysis, identifying root causes, and providing platform/tooling expertise during high severity events
  • Implement and continuously improve control validation (data quality checks, parsing/field extraction tests, content regression tests) and observability (health monitors, capacity, latency, backlog, and error metrics)
  • Evaluate emerging telemetry sources, detection approaches, and vendor capabilities; build proofs of concept to assess fit, security posture, and operational impact
  • Support identity, access, and privilege strategies within SOC platforms (API tokens, service accounts, secrets management, SSO/SAML/OIDC) aligned to enterprise guardrails
  • Collaborate in post incident reviews and resilience improvements, translating findings into backlog items for pipeline hardening, new log sources, or content tuning
  • Contribute to responsible logging and monitoring for AI enabled applications and platforms (e.g., model/service telemetry, prompt/audit logs), integrating risks and controls into detection strategy
  • Serve as the security telemetry and detection engineering representative for Global Security Office in technical forums, ensuring platform considerations are aligned with enterprise strategies and governance
  • Perform other duties as assigned

Skills

Security engineering
SIEM
EDR
SOAR
RBAC
Cloud and on-prem
Data pipelines

Education

Bachelor's degree in arts/sciences (BA/BS) or equivalent experience
Master's degree in Arts/Sciences (MA/MS) or professional certification preferred

Tools

Tines
Terraform
Python
PowerShell

Job description

RGA is seeking a Staff SOC Engineer to design, implement, and optimize security telemetry and detection platforms across hybrid environments. You will build and maintain data pipelines, SIEM content, and RBAC controls while collaborating with security operations, architecture, and product teams.

The role emphasizes secure-by-design data collection, scalable controls, and measurable outcomes to advance SOC maturity and support regulatory compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Engineer: Telemetry & Detection Platforms
Senior SOC Engineer: Telemetry & Detection Platforms

Reinsurance Group of America, Incorporated • Missouri

On-site
USD 127,000 - 189,000
Staff SOC Engineer - Security Telemetry & Detection Platforms
Staff SOC Engineer - Security Telemetry & Detection Platforms

RGA • Missouri

Hybrid
USD 127,000 - 189,000
Annual bonus plan
Health benefits
Retirement benefits
Staff SOC Engineer - Security Telemetry & Detection Platforms
Staff SOC Engineer - Security Telemetry & Detection Platforms

Reinsurance Group of America, Incorporated • Missouri

On-site
USD 127,000 - 189,000
Cybersecurity Engineering Team Lead: SOC & Telemetry
Cybersecurity Engineering Team Lead: SOC & Telemetry

DGS Office of External Affairs • Tallahassee (FL)

On-site
USD 120,000 - 170,000
Senior SOC Detection Engineer — Build Global Detections
Senior SOC Detection Engineer — Build Global Detections

Embedded Shishya • United States

Remote
USD 120,000 - 180,000
Private health insurance
Sports benefits
Mental Health Program
+6
SOC Security Engineer: Detection & Response
SOC Security Engineer: Detection & Response

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Hybrid SOC Manager — Lead 24/7 Security Ops
Hybrid SOC Manager — Lead 24/7 Security Ops

RADICL • Colorado

Hybrid
USD 120,000 - 180,000
Health insurance
401(k) plan
Paid time off
+1
Senior SOC Engineer - SIEM, Detection & Automation
Senior SOC Engineer - SIEM, Detection & Automation

Amentum • Columbia (AL)

On-site
USD 145,000 - 190,000
Health, dental, vision insurance
Paid time off & holidays
401(k) matching
+5