Security Operations Engineer – Incident Response
Posted 6ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Operations Engineer leading incident response and forensic investigations at ProCircular. Managing critical security incidents and developing detection methodologies in a SOC environment.
Responsibilities:
- Lead incident response engagements to scope work, perform forensic investigations, contain security incidents, and provide guidance on remediation.
- Serve as the Tier III escalation point for alerts and trouble tickets escalated by Tier I and Tier II analysts that signal an incident requiring advanced review.
- Own the most complex and critical security investigations through to resolution, determining relevancy, urgency, and root cause of escalated alerts and incidents.
- Conduct host forensics, network forensics, log analysis, and malware triage to support incident response investigations.
- Collect and analyze asset data (configurations, running processes, memory, etc.) from affected systems to drive investigation and containment.
- Act as senior first responder to security event escalations via email, phone, and ticket.
- Direct and support Tier I and Tier II analysts in the remediation of critical information security incidents.
- Review and provide quality assurance on trouble tickets and investigative work produced by other team members.
- Monitor advanced security alerts and incidents within established customer Service Level Agreements.
- Craft new detection content and use cases based on threat intelligence, analyst feedback, available log data, and previous incidents.
- Tune rules, filters, and policies for detection-related security technologies to improve accuracy and visibility.
- Build parsers and field extractions to facilitate reliable content development within security data lake architectures.
- Build, implement, and maintain scripts and tools that contribute to ProCircular's security operations and incident response methodologies.
- Design, develop, and maintain security orchestration and automation workflows using industry-leading SOAR platforms.
- Manage, monitor, and maintain assigned security platforms while following and improving established procedures.
- Prepare detailed and accurate reports from analysis outcomes, and write documentation for tasks, procedures, and knowledgebase articles that support the understanding and efficiency of SOC services.
- Mentor junior engineers and analysts, and practice continual self-improvement through education, training, and certification.
- Communicate positively with clients, determine client needs, obtain clarification as required, and escalate issues and messages accordingly.
- Complete assigned projects on time and with excellent quality.
Requirements:
- Prior SOC experience with a focus on detection content development (Splunk, AlienVault, ELK, or similar).
- Strong hands-on experience in threat hunting, incident response, digital forensics, security analysis, and security engineering.
- Strong incident-handling skills across all IR phases of preparation, identification, containment, eradication, recovery, and lessons learned.
- Working knowledge of SOC and detection tooling: EDR, SOAR, SIEM, XDR, network analytics, and intrusion detection.
- Knowledge of core security devices such as firewalls, network- and host-based IDS/IPS, WAF, proxy, AV, and operating system logs, including firewall rule and policy fundamentals.
- Ability to interpret IOCs and a strong understanding of various log formats and source data for security analysis.
- Experience writing suppression and detection rules and developing and maintaining content and reporting.
- Proficiency in one or more programming/scripting languages such as Python, PowerShell, and Bash.
- Experience with Windows and Linux operating systems.
- Experience with network technologies, security and network monitoring tools, packet-capture analysis, and custom intrusion-signature development.
- Deep understanding of networking concepts and a broad range of cyber-attacks.
- Thorough understanding of the latest security principles, techniques, and protocols.
- Experience with internal and client ticketing and knowledgebase systems for incident and problem tracking (e.g., Jira, Confluence).
- Ability to drive process improvements and identify gaps.
- Strong written and oral communication, able to facilitate technical and non-technical conversations and communicate positively with clients, including via phone.
- Natural curiosity to find root cause, and the ability to remain calm under pressure.
- Able to work effectively both independently and in a team; self-motivated, goal- and detail-oriented; flexible and adaptable; able to prioritize multiple tasks and manage time efficiently.
Benefits:
- Flexible on-call coverage, including after-hours and weekends, to support incident response efforts and 24/7/365 security operations.




















