Security Operations Engineer
Team: Cybersecurity
Location: Remote, US
Commitment: Full-time
Workplace Type: remote
Salary:
SIEM Implementation & Detection Engineering
- Serve as the primary implementer for the new SIEM solution, configuring data ingestion and tuning the platform for optimal performance.
- Own the security observability platform on Grafana (Loki/LogQL, Prometheus/PromQL, Grafana Alerting; OTel for collection), including onboarding sources, parsing, enrichment, and alert routing.
- Own the "Content Engineering" lifecycle: Write, test, and tune detection rules and queries (LogQL, PromQL, SPL, KQL, SQL, etc.) to identify malicious activity with low false-positive rates.
- Partner with the Engineering team to ensure the new observability platform captures the right security telemetry and logs.
- Serve as the primary operator for security monitoring and initial incident triage, participating in the on-call rotation.
Telemetry Engineering & Observability (Security)
- Define logging standards and required security telemetry for product and infrastructure.
- Own log onboarding, parsing, enrichment, normalization, retention, and cost controls.
- Build dashboards and SLOs for security telemetry health (coverage, latency, drop rate).
Incident Response & Process Development
- Develop and maintain the library of Incident Response documents, including Triage Books, Runbooks, and Playbooks for future on-call rotation.
- Act as the primary technical liaison for our MDR provider (Sophos), ensuring they have the context needed to monitor effectively.
- Lead deeper analysis and threat hunting investigations for complex alerts escalated by the MDR or internal teams.
- Own alert routing and incident tracking integration (PagerDuty + Jira/Slack), including severity model, escalation paths, and reporting.
- Lead incident coordination, write post-incident reviews, and drive corrective actions with Engineering.
- Own phishing detection/response workflows and playbooks (user reports, triage, containment).
Operational Health & Optimization
- Continuously evaluate the efficacy of alerts and automations; refine logic to reduce alert fatigue.
- Assist in defining log schemas to ensure data is parsed correctly for both security and engineering use cases.
- Evaluate and implement AI-assisted tools to streamline query generation and dashboard creation.
- Own the integration and correlation between MDR alerts and internal SIEM/incident tracking.
- Implement least-privilege access to security telemetry and ensure logging pipelines avoid sensitive data leakage.
WHAT YOU'LL BRING:
- 5-7 years of total experience in Information Security or Security Operations.
- Proven experience transitioning from a "consumer" of alerts (Analyst) to a "builder" of detections (Engineer).
- Demonstrated experience working with SIEM/observability platforms (Grafana/Loki preferred; Splunk/Elastic/Sentinel/Datadog acceptable), specifically in creating dashboards, reports, and writing complex queries.
- Experience working with Managed Detection and Response (MDR) providers or MSSPs is highly preferred.
- Background in partnering with DevOps or Engineering teams on logging or observability initiatives is a plus.
- Bachelor’s degree in Computer Science, Information Security, or a related field or equivalent work experience.
- Industry certifications such as GCIH, GCIA, GCED, GMON, Security+, CySA+ or related are highly desirable.
YOUR TECHNICAL TOOLKIT:
- Query Languages: Strong proficiency in query languages (e.g., LogQL, PromQL, KQL, SPL, SQL) to interrogate data and build dashboards.
- Detection Logic: Ability to translate threat intelligence and MITRE ATT&CK techniques into actionable detection rules.
- Response Frameworks: Deep understanding of the Incident Response Lifecycle (NIST or SANS) and experience writing clear, executable runbooks.
- Light Scripting: Familiarity with Python or similar scripting languages for automation or API integration is beneficial (though not a primary coding role).
WHAT SETS YOU APART:
- Operator-to-Builder Mindset: The ability to understand the "pain" of a bad alert and the drive to engineer a better solution.
- Cross-Functional Collaboration: Ability to work effectively with Engineering teams to align on data formatting and ingestion without friction.
- Autonomy: Capable of prioritizing work and driving the SIEM implementation forward with minimal oversight.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
