Job SummaryThe Security Operations Engineer III is a senior individual contributor within the Allvue Information Security team responsible for strengthening detection, response, and security automation capabilities. The role combines hands-on management of endpoint detection and response, SIEM and SOAR, email security, and secure remote access technologies. The engineer will develop and tune detections, investigate security and insider events, conduct threat hunting, build automated response workflows, manage integrations and log ingestion, support incident response and the on-call rotation, and assist with the production of operational reporting and metrics.
ResponsibilitiesDetection, Investigation and Response - Develop, tune, test, and maintain detections across EDR, SIEM, email security, and secure remote access technologies.
- Independently triage and investigate security alerts, incidents, and insider events; coordinate response actions and document findings.
- Conduct threat hunts using threat intelligence and recognized threat frameworks and participate in the incident-response on-call rotation, and coordinate with the MDR provider (Rapid7) when required.
Security Platform Engineering - Administer, maintain, and optimise CrowdStrike, Rapid7 SIEM and SOAR,Mimecast, and Prisma GlobalProtect security capabilities
- Manage security-platform integrations and log ingestion, monitor data health, and resolve collection or connectivity issues.
- Evaluate, test and document platform changes, configurations, playbooks, and operational procedures.
- Identify platform and detection gaps and implement improvements that strengthen operational reliability and security coverage
Automation, Reporting and Continuous Improvement - Build and maintain SOAR workflows and security automations using PowerShell, Python, and APIs.
- Produce operational reporting and metrics covering detection, investigation, response, platform health, and automation outcomes.
- Translate investigation findings, incident lessons, and detection gaps into improvements to security coverage and response processes.
- Apply emerging AI capabilities, including LLM-based tools, where appropriate to improve security or technical workflows while recognizing associated security risks and limitations.
Requirements- Demonstrated ability to operate independently across security operations, detection engineering, incident response, threat hunting, and security-platform engineering.
- Demonstrated ability to evaluate complex security issues, determine appropriate courses of action, and implement practical solutions.
- Demonstrated ability to collaborate effectively with internal stakeholders and external security service providers.
Technical & System Proficiency - Advanced hands-on proficiency with EDR and SIEM/SOAR technologies, including CrowdStrike and Rapid7.
- Working-to-advanced proficiency with Mimecast and Prisma GlobalProtect.
- Proficiency in PowerShell and Python for security automation and workflow development.
- Working knowledge of Windows, Linux, and macOS
- Working knowledge of APIs, security integrations, and log-ingestion processes.
- Working knowledge of recognized threat frameworks and their application to detection, investigation, and response.
- Working knowledge of LLMs, agentic AI, broader AI capabilities and limitations, and security risks associated with AI systems.
AI Skills and Experience - Working knowledge of large language models, agentic AI, and broader AI capabilities and limitations.
- Understanding of how LLMs and AI systems can be exploited or misused from a security perspective.
- A demonstrated track record of using LLMs or other AI capabilities in security or technical workflows.
Experience - Minimum 5 years of relevant professional experience.
- Demonstrated hands-on experience in security operations, detection engineering, threat hunting, incident response, and security investigation
- Relevant professional security certifications are preferred but not required.
Language Skills - Ability to communicate technical security information clearly in written and verbal form to technical and non-technical stakeholders.
Education/Certifications- Bachelor's degree in computer science, Information Security, Engineering, or a related field preferred, or equivalent relevant work experience.
What We Offer- Health Coverage options along with other voluntary benefits
- Enterprise Udemy membership with access to thousands of personal and professional development courses
- 401K with Company match up to 4% or Employee Pension plan
- Competitive pay and year-end bonus potential
- Flexible PTO
- Charitable Donation matching, along with Volunteer and Voting PTO
- Numerous team building activities to promote collaboration in a fun and fast-paced work environment