Security Operations Engineer (Incident Response)

ProCircular

$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of SOC experience with a focus on detection content development (e.g., Splunk, AlienVault, ELK).
  • Hands-on experience in threat hunting and digital forensics.
  • Expertise in all phases of incident response including recovery and lessons learned.
  • Proficient with EDR, SOAR, SIEM, and intrusion detection tools.
  • Familiarity with various log formats and source data analysis for security incidents.
  • Experience in crafting suppression and detection rules.
  • Knowledge in scripting languages such as Python and PowerShell.

Responsibilities

  • Lead complex incident response engagements and forensic investigations.
  • Act as primary escalation point for Tier I and II analysts.
  • Conduct detailed analysis to determine the root causes of security events.
  • Develop and maintain automated workflows for incident response processes.
  • Design security detection content based on threat intelligence and previous incidents.
  • Mentor and support junior analysts and engineers in their tasks.
  • Ensure compliance with customer service level agreements related to incident management.

Benefits

  • Flexible on-call support for after-hours incident response.
  • Opportunities for professional development and certification.
  • A collaborative team environment focused on growth and support.
  • Access to cutting-edge security technologies and tools.
  • Potential for schedule flexibility upon supervisor approval.
Full Job Description
Position Summary
This position serves as a senior technical authority for response operations on the most critical and complex events, spanning both advanced (Tier III) security operations and incident response engineering. On the operations side, this role leads immediate containment, investigation, and management of remediation actions for critical incidents, acting as the primary escalation point for Tier I and Tier II analysts and driving the most difficult investigations through to resolution. It also turns the knowledge gained throughout each response into stronger defenses, developing and tuning threat detection content across tools to identify anomalous, suspicious, and malicious behavior within security data lake architectures.

On the engineering side, this person works with a team to develop and maintain automated workflows that orchestrate incident response actions and optimize security operations for our clients across all phases of the incident response lifecycle. The role requires deep, cross-product expertise and close collaboration with SOC leadership, service delivery, and clients to provide ongoing communication of status and timely, decisive response to tickets and events. An individual must be able to perform each essential job function satisfactorily. The requirements listed below represent the knowledge, skill, and/or ability required.

Essential Job Functions (including but are not limited to the following)
  • Lead incident response engagements to scope work, perform forensic investigations, contain security incidents, and provide guidance on remediation.
  • Serve as the Tier III escalation point for alerts and trouble tickets escalated by Tier I and Tier II analysts that signal an incident requiring advanced review.
  • Own the most complex and critical security investigations through to resolution, determining relevancy, urgency, and root cause of escalated alerts and incidents.
  • Conduct host forensics, network forensics, log analysis, and malware triage to support incident response investigations.
  • Collect and analyze asset data (configurations, running processes, memory, etc.) from affected systems to drive investigation and containment.
  • Act as senior first responder to security event escalations via email, phone, and ticket.
  • Direct and support Tier I and Tier II analysts in the remediation of critical information security incidents.
  • Review and provide quality assurance on trouble tickets and investigative work produced by other team members.
  • Monitor advanced security alerts and incidents within established customer Service Level Agreements.
  • Craft new detection content and use cases based on threat intelligence, analyst feedback, available log data, and previous incidents.
  • Tune rules, filters, and policies for detection-related security technologies to improve accuracy and visibility.
  • Build parsers and field extractions to facilitate reliable content development within security data lake architectures.
  • Build, implement, and maintain scripts and tools that contribute to ProCircular's security operations and incident response methodologies.
  • Design, develop, and maintain security orchestration and automation workflows using industry-leading SOAR platforms.
  • Manage, monitor, and maintain assigned security platforms while following and improving established procedures.
  • Prepare detailed and accurate reports from analysis outcomes, and write documentation for tasks, procedures, and knowledgebase articles that support the understanding and efficiency of SOC services.
  • Mentor junior engineers and analysts, and practice continual self-improvement through education, training, and certification.
  • Communicate positively with clients, determine client needs, obtain clarification as required, and escalate issues and messages accordingly.
  • Complete assigned projects on time and with excellent quality.
  • Provide flexible on-call coverage, including after-hours and weekends, to support incident response efforts and 24/7/365 security operations.
  • Operate with integrity and accountability, uphold the values of ProCircular, and abide by the Company handbook.
  • Perform additional responsibilities as necessary.


Position Requirements
The requirements listed below are representative of the knowledge skills and abilities required. Employees who do not have the requirements for a job at the time of hire will not be considered for the position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Required Skills and Experience:
  • Prior SOC experience with a focus on detection content development (Splunk, AlienVault, ELK, or similar).
  • Strong hands-on experience in threat hunting, incident response, digital forensics, security analysis, and security engineering.
  • Strong incident-handling skills across all IR phases of preparation, identification, containment, eradication, recovery, and lessons learned.
  • Working knowledge of SOC and detection tooling: EDR, SOAR, SIEM, XDR, network analytics, and intrusion detection.
  • Knowledge of core security devices such as firewalls, network- and host-based IDS/IPS, WAF, proxy, AV, and operating system logs, including firewall rule and policy fundamentals.
  • Ability to interpret IOCs and a strong understanding of various log formats and source data for security analysis.
  • Experience writing suppression and detection rules and developing and maintaining content and reporting.
  • Proficiency in one or more programming/scripting languages such as Python, PowerShell, and Bash.
  • Experience with Windows and Linux operating systems.
  • Experience with network technologies, security and network monitoring tools, packet-capture analysis, and custom intrusion-signature development.
  • Deep understanding of networking concepts and a broad range of cyber-attacks.
  • Thorough understanding of the latest security principles, techniques, and protocols.
  • Experience with internal and client ticketing and knowledgebase systems for incident and problem tracking (e.g., Jira, Confluence).
  • Ability to drive process improvements and identify gaps.
  • Strong written and oral communication, able to facilitate technical and non-technical conversations and communicate positively with clients, including via phone.
  • Natural curiosity to find root cause, and the ability to remain calm under pressure.
  • Able to work effectively both independently and in a team; self-motivated, goal- and detail-oriented; flexible and adaptable; able to prioritize multiple tasks and manage time efficiently.


Desired Skills and Experience:
  • Prior experience with Git/GitHub and CI/CD pipelines.
  • Knowledge of Active Directory environments and Windows Active Directory domains.
  • Working knowledge of virtualization platforms such as VMware and Hyper-V.
  • Prior experience with container-based technologies such as Docker and Kubernetes.
  • Knowledge of penetration-testing methodologies.
  • Knowledge of network security architecture concepts such as topology, protocols, components, and defense-in-depth.
  • Knowledge of vulnerability information sources (alerts, advisories, errata, and bulletins).
  • Understanding of server-grade applications such as DBMS/SQL, Exchange, DNS, SMTP, IIS, Apache, SharePoint,
  • Active Directory, identity management, vulnerability/patch management, and LDAP.
  • Broad knowledge of attack techniques and defenses such as buffer overflows, DoS, reconnaissance and scanning, session hijacking and cache poisoning, password attacks, web application attacks, and worms / bots / botnets.
  • Awareness of emerging attack vectors, including cloud computing and mobile platforms.
  • Prior consulting experience.


Desired Education:
  • Associate's degree or higher in Computer Science, Information Security or equivalent experience.
  • Additionally, at least 3 years' experience performing SOC analysis and/or incident response, including at least 6-months of experience supporting a security platform in a content development role.
  • Security certifications a plus. (ex. CISSP, GCFA, GCIA, GCIH, GMON, etc.)


Language Requirements:

The primary language of ProCircular is English. Excellent communication skills are required, defined as the ability to:
  • Actively listen for total comprehension.
  • Ask questions that enhance the understanding of a certain topic.
  • Relay information and/or instruction in a descriptive and understandable fashion in both written and verbal format.


Reasoning Ability Requirements:
High-functioning reasoning abilities are necessary to meet deadlines, prioritize company and customer needs, and work in a collaborative team environment.

Physical Requirements:
Occasional lifting up to 40 lbs. may be necessary from time to time. Must be able to sit for long periods of time, view a computer monitor, and type frequently/constantly (up to 8 hours a day).

Travel Requirements:
A valid driver's license is required for occasional travel.

Schedule Expectations:
Our normal hours of operation are from Monday through Friday, from 8:00 am to 5:00 pm. Central Time.
Full-Time: Full-Time employees are defined legally as working at least 30 hours per week. However, full-time positions at ProCircular require at least 40 hours. This position requires 40 hours worked within a regular workweek. Occasionally, time over 40 hours may be necessary to meet the requirements of the position. If performance expectations are met, employees may flex his or her schedule, subject to preapproval of one's direct supervisor.

Supervision Requirements:
This position does not have supervisory responsibilities.

Performance Expectations
All teammates are evaluated at least annually on their performance based on the essential job functions in this job description, along with ProCircular's Core Values:

It’s about people
People define every part of our business. Growth potential is based on the abilities and personalities of the people involved. Technology solutions are a part of the equation, but it’s the people in an organization that define its true security. We work hardest when we’re supporting one another. We take care of each other; we take care of our families, and in doing so we take better care of our customers.

Fear is the mind killer
We don’t let fear define the need for our services and we don’t present a problem without discussing realistic response or mitigation options. There’s more than enough to worry about in life and plenty of people telling us to be afraid. We’re solutions people, not fear mongers.

Strong opinions lightly held
Opinions are important - they coalesce facts, reason, experience, and judgment into actionable points of view. We present our opinions with logic and reason rather than emotions, offering several alternatives to each challenge and the supporting data. The rejection of an idea is not a rejection of the individual or their merit. Everyone has a voice and a chance to speak, regardless of title, station or seniority.

Quality over speed, speed over cost
Every organization must consciously balance quality, speed, and cost. We will always put the quality of our work first. We make great efforts to move quickly, but never at the expense of quality. While we strive to keep our services affordable, we never choose an inexpensive alternative that will adversely impact quality or speed.

Cool heads, warm hearts
We keep a cool head and help others do the same, especially in a crisis. We approach adversity with patience, logic, and understanding. Mistakes happen; we don’t hide, ignore, condemn, or fear them. Mistakes are opportunities to exemplify honesty, accountability, professionalism, tolerance, and grace. Instead of pointing a finger, we use humor, empathy, and fun when it matters most.

R-E-S-P-E-C-T
We treat each other how we hope to be treated. We don’t yell; we aren’t condescending, and we always try to understand the other person’s perspective, before reacting to it. We keep it light and we listen. We extend this principle to our customers, and we understand that talking down to them is the easiest way to send them to a competitor.

Tomorrow just happened
Life is what happens when we’re busy making other plans. We work hard on today but we’re always thinking about the future. We take extra time to make sure we’re learning and looking ahead. No matter what your discipline or area of expertise, you’re adding your capabilities to the long-term plan for the organization and its clients.

Similar Jobs

More Jobs at ProCircular

More Information Technology Jobs

Find similar Security Operations Engineer (Incident Response) jobs: