We are seeking a
Security Operations Platform Engineer for our
First Quality Enterprises, LLC company, working remotely The Information Security team is actively seeking a platform engineer to join our SOC operations to support the design, implementation, management, and optimization of our SIEM/SOAR platform. This role ensures effective log ingestion, threat detection, alert tuning, reporting, automation, and overall platform health to enhance the organization's security monitoring and incident response capabilities.
Primary responsibilities include:- Platform Management
- Configure and maintain SIEM/SOAR platform
- Monitor platform performance, availability, and data health
- Review and maintain upgrades, integrations, and ongoing optimization
- Manage role/scope-based access controls and data retention policies
- Data Ingestion & Integration
- Onboard and normalize log sources (firewalls, endpoints, servers, cloud, SaaS, identity providers, etc.)
- Build integrations via scripting for custom data onboarding utilizing APIs
- Troubleshoot ingestion issues and ensure log integrity and completeness
- Review and maintain parsing rules and data mappings
- Optimize data pipelines for performance and cost efficiency
- SOC Operations Support
- Develop, tune, and maintain detection rules logic, and alerting thresholds to improve fidelity and reduce false positives
- Collaborate with SOC analysts during active investigations to provide platform support, log extraction, and forensic data retrieval
- Vendor management and escalation support
- Reporting & Dashboards
- Build and maintain dashboards for SOC operations, compliance, and executive reporting
- Develop and maintain scheduled and ad-hoc reports for stakeholders
- Develop KPIs and metrics for security posture and incident trends
- Continuous Improvement
- Evaluate new log sources and security integrations
- Recommend enhancements to improve visibility and coverage
- Stay current on platform updates and best practices
- Evaluate existing integrations and data to improve parsing, data normalization, and data reduction
The ideal candidate should possess the following:- Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
- 3+ years of experience managing a SIEM platform
- Knowledge of network protocols, firewalls, IDS/IPS, EDR, cloud security logs
- Understanding of data normalization standards (CEF, LEEF, JSON, etc.)
- Experience with SIEM query languages
- Experience with scripting (Python, PowerShell, or similar) for automation
- Working knowledge of MITRE ATT&CK, threat intelligence, and incident response processes
- Preferred: 3+ years managing SOAR platform
- Preferred: Experience developing automation, and response playbooks
- Preferred: Familiarity with Azure, AWS, or GCP log configurations
- Preferred: Experience supporting compliance frameworks (NIST, ISO 27001, SOX, HIPAA, etc.)
- Preferred: Security+, CySA+, CASP+, GCIA, GCIH, CISSP or equivalent
- Analytical and problem-solving skills
- Strong troubleshooting and log analysis capabilities
- Ability to translate security requirements into technical solutions
- Strong communication skills for technical and executive audiences
- Ability to work both independently and collaboratively in a fast-paced SOC environment
Travel up to 5 days per yearWhat We Offer YouWe believe that by continuously improving the quality of our benefits, we can help to raise the quality of life for our team members and their families. At First Quality you will receive:
- Competitive base salary and bonus opportunities
- Paid time off (three-week minimum)
- Medical, dental and vision starting day one
- 401(k) with employer match
- Paid parental leave
- Child and family care assistance (dependent care FSA with employer match up to $2500)
- Bundle of joy benefit (years' worth of free diapers to all team members with a new baby)
- Tuition assistance
- Wellness program with savings of up to $4,000 per year on insurance premiums
- ...and more!