Security Operations Engineer

Vertex

$91K — $118K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Hands-on experience in security operations, incident response and detection engineering.
  • Strong understanding of attacker tactics and MITRE ATT&CK framework.
  • Proficiency with SIEM platforms and detection query languages like KQL and SPL.
  • Familiarity with EDR/XDR platforms for investigation and containment.
  • Scripting skills, preferably in Python, PowerShell, or Bash.
  • Experience with AI tools for security applications.
  • Knowledge of at least one cloud platform's security features.
  • Excellent communication skills for diverse audiences.

Responsibilities

  • Monitor and respond to security alerts across multiple environments.
  • Lead comprehensive incident response processes from detection to recovery.
  • Develop and refine detection logic for SIEM and other platforms.
  • Automate SecOps workflows to boost response efficiency.
  • Utilize AI responsibly in security operations and maintain outputs.
  • Collaborate with teams to improve security posture and close telemetry gaps.

Benefits

  • Flexible shift schedule with 24/7 operational coverage.
  • Opportunity for cross-functional collaboration.
  • Engagement with cutting-edge security technologies.
  • Access to ongoing training and professional development.
Full Job Description
Job Description:

Vertex Inc. is looking for a Security Response Engineer role to strengthen our security monitoring, incident response, detection engineering, and SecOps automation capabilities. This role is ideal for a hands-on security practitioner who has a passion for investigating threats, responding to incidents, improving security tooling, and building operational solutions that help security teams work faster and more effectively. Given the 24/7/365 nature of the security operations function, the Security Response Engineer participates in a rotating shift schedule designed to provide continuous security analysis and incident response coverage. Within the coverage, this will require working nights, weekends, holidays, and extended hours based on the assigned coverage and operational needs.

Responsibilities

  • Monitor, triage, investigate, and respond to security alerts across endpoint, identity, network, cloud, SaaS, and application environments.


  • Lead end-to-end incident response - detection through containment, eradication, recovery, and post-incident improvement - including root-cause analysis and corrective action tracking.


  • Build, tune, and maintain detection logic across SIEM, EDR, cloud, and network platforms; conduct proactive threat hunting aligned to MITRE ATT&CK.


  • Develop and maintain SecOps tooling, scripts, API integrations, and workflow automations to improve investigation speed and response execution.


  • Apply AI responsibly in SecOps workflows, with the ability to explain, validate, test, and maintain all AI-assisted outputs.


  • Collaborate cross-functionally to close telemetry gaps, improve detection coverage, and translate incident findings into lasting security improvements.


Required Qualifications

  • Hands-on knowledge in security operations, incident response, detection engineering, or threat hunting, with demonstrated ability to lead significant investigations.


  • Strong knowledge of attacker tactics and techniques across endpoint, identity, network, cloud, and email environments, including MITRE ATT&CK mapping and IOC analysis.


  • Experience with SIEM platforms (Sentinel, Splunk, Chronicle, QRadar, or Elastic) and proficiency writing and tuning detection queries using KQL, SPL, Sigma, YARA, or equivalent.


  • Experience with EDR/XDR platforms (Defender for Endpoint, CrowdStrike, SentinelOne, Cortex XDR, or Carbon Black), including triage, investigation, and containment.


  • Scripting or automation experience using Python, PowerShell, or Bash; AI-assisted development acceptable provided the candidate can explain, validate, test, and maintain the code.


  • Practical use of AI tooling for security - such as Claude, GitHub Copilot, or OpenAI Codex - to accelerate tooling development, detection drafting, and analysis workflows.


  • Experience with at least one cloud platform (AWS, Azure, GCP, or OCI), including cloud logging, identity, and security monitoring.


  • Solid understanding of identity security, including MFA, conditional access, privileged access, token abuse, and identity-based attacks.


  • Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences.


  • Independent, self-starter, analytical, evidence-driven work style with strong attention to detail.


Preferred Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field.


  • Experience with threat intelligence, malware triage, digital forensics, or reverse engineering.


  • Experience with vulnerability management or compliance-driven SecOps (SOC 2, ISO 27001, PCI DSS, or HIPAA).


  • Familiarity with detection-as-code, Git-based workflows, CI/CD pipelines, and code review practices.


  • Relevant certifications such as GIAC (GCFA, GCIH, GCFR, GCLD, GDAT, or GEIR), OffSec (OSIR, OSTH, OSCP, or OSAI), AWS Security Specialty, Google Professional Cloud Security Engineer, Microsoft SC-200, or CompTIA CASP+.


  • Equivalent combination of education, training, and relevant professional experience accepted in lieu of a formal degree.


COMMENTS:

The above statements are intended to describe the general nature and level of work being performed by individuals in this position. Other functions may be assigned, and management retains the right to add or change the duties at any time.

Pay Transparency Statement:

US Base Salary Range: $91,200.00 - $118,600.00

Base pay offered to new hires may vary based upon factors including relevant industry and job-related skills and experience, geographic location, and business needs.* The range displayed does not encompass the full potential of the role, which allows for further growth and career progression.

In addition, as a part of our total compensation package, this role may be eligible for the Vertex Bonus Plan (VOB), a role-specific sales commission/bonus, and/or equity grants.

Learn more about Life at Vertex and connect with your recruiter for more details regarding Vertex's compensation and benefit programs.

*In no case will your pay fall below applicable local minimum wage requirements.

Similar Jobs

More Jobs at Vertex

More Information Technology Jobs

Find similar Security Operations Engineer jobs: