Security Engineer

Posted 2hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Engineer operating 11:11 Systems’ global SOC. Building SIEM/SOAR detections, supporting incident response, and improving customer security operations.

Responsibilities:

  • Support SOC Management in setting tactical and operational goals and developing policies and procedures for security event detection, assessment, reporting, and response
  • Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms
  • Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts
  • Provide first-responder incident response advisory support for clients within the scope of 11:11 Systems' software and systems
  • Own the timeliness and accuracy of critical incident identification, advisement, and reporting internally and to customers
  • Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs
  • Drive implementation and continuous improvement of technologies, capabilities, frameworks, and methodologies
  • Develop and maintain customer-facing security stacks including SIEM, EDR, SOAR, WAF, and vulnerability scanning, and architect technical improvements
  • Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team
  • Advise on and help build SOC analyst training programs and provide cross-functional training
  • Monitor emerging threats, risks, and exploits and translate knowledge into updated SIEM detection rulesets
  • Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers
  • Participate in an on-call rotation for after-hours support
  • Work in alignment with 11:11 Systems' Code of Business Ethics and Company Values, including responsible data handling and required compliance training

Requirements:

  • 5+ years in information security, including 3+ years in information technology
  • 3+ years' experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools, with focus on Azure Sentinel, Cortex XDR, and Tenable
  • Analyst-level experience in the telecom and/or enterprise cybersecurity industry
  • 1+ years' experience with Python scripting or development
  • 1+ years' experience with Linux administration and troubleshooting
  • Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols
  • Experience with enterprise security architecture, detection, and response
  • Mature understanding of industry-standard incident response practices and SOC operations
  • Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development
  • Experience with Kubernetes
  • Experience with Palo Alto products, including Cortex XDR, Panorama, and next-generation firewalls
  • Experience with ThreatX or similar WAF platforms
  • Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH
  • Working knowledge of security frameworks such as ISO, NIST, and CIS
  • Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK
  • Up-to-date knowledge of attacker tactics, techniques, and procedures
  • Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work
  • Must be a US Citizen and legally eligible to work in the US without visa sponsorship
  • Ability to perform each essential function satisfactorily; reasonable accommodation may be made for qualified individuals with disabilities