SOC Engineer
The SOC Engineer will build detection and response capabilities, including SIEM log pipelines, ATT&CK-mapped detections, alert investigation, automation, and runbooks. The role requires 3–5 years of SOC or detection-engineering experience plus strong cloud, identity, scripting, and SIEM expertise.
About the job
Responsibilities
Detection Engineering
- Design, write, and tune detections mapped to MITRE ATT&CK techniques.
- Track and reduce false positives while expanding coverage of prioritized techniques.
Log Pipeline Engineering
- Onboard, parse, and normalize log sources into the SIEM.
- Bring tier-1 sources online and maintain reliable pipelines as new sources are added.
- Work with cloud and identity logs, including CloudTrail, GuardDuty, Kubernetes audit logs, and Okta.
Incident Triage and Response
- Investigate alerts end-to-end.
- Escalate with clear severity reasoning, complete timelines, and actionable context.
- Own the triage process through to a clear disposition.
Automation
- Script enrichment, response actions, and repetitive SOC tasks in Python or Go.
- Automate recurring manual work to systematically reduce toil.
Runbooks and Documentation
- Write triage runbooks for all high- and critical-severity alert types.
- Keep runbooks current as detections and infrastructure evolve.
SOC Foundation
- Build the monitoring capability needed to inform an in-house versus hybrid SOC decision.
- Establish scalable architecture, coverage, and processes.
Requirements
- 3–5 years of experience in detection engineering, SOC engineering, or blue-team roles.
- Hands-on experience building detections in a modern SIEM such as RunReveal, Panther, Elastic, Splunk, Sentinel, or similar.
- Deep familiarity with cloud and identity log sources, including CloudTrail, GuardDuty, Kubernetes audit logs, and Okta or other identity-provider logs.
- Proficiency in Python or Go scripting and automation.
- Experience mapping detections to MITRE ATT&CK.
- English proficiency at B2 or higher.
Nice-to-Haves
- Experience with detections-as-code managed in Git and deployed through CI/CD.
- EDR experience with SentinelOne or CrowdStrike.
- Incident-response experience beyond triage.
- CNAPP exposure, such as Wiz, and cloud-security fundamentals.
- Certifications such as GCIA, GCDA, GCIH, or BTL2.
- Experience building monitoring from scratch at a SaaS company or technology startup.
Compensation and Benefits
- Competitive salary and equity in a high-growth startup.
- Healthcare, dental, and vision coverage.
- Ownership and autonomy over projects.
Skills
Mitre Att&Ck, SIEM, Cloudtrail, Guardduty, Kubernetes, Okta, Python, Go, Runreveal, Panther, Elastic, Splunk, Microsoft Sentinel, Git, CI/CD
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.