Senior SOC Engineer - Agentic

SANS Institute

• $155K — $205K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in security operations, detection engineering, or security automation with the ability to lead independently.
  • Experience with well-run SOC functions including alert triage and incident response.
  • Expertise in detection engineering including writing, tuning detections and managing false positives.
  • Fluency in MITRE ATT&CK for operational use.
  • Hands-on experience with EDR and SIEM in production environments.
  • Strong proficiency in Python and integration with REST APIs.

Responsibilities

  • Design and build the architecture for the agentic SOC focusing on automation and AI agent integration.
  • Own detection engineering by writing and maintaining detections like code across the SIEM.
  • Translate SOC operations into automated workflows and build necessary integrations.
  • Monitor and improve agent performance, incorporating feedback into the system.
  • Manage vulnerability identification, mitigation, and remediation tracking programs across the environment.
  • Evaluate cloud security posture and implement enhancements.

Benefits

  • Competitive base salary and bonus opportunities.
  • Comprehensive health benefits including medical, dental, and vision plans.
  • Generous paid time off including volunteer time.
  • 401(k) plan with company match and financial benefits programs.
  • Learning and development access through SANS training opportunities.
Full Job Description
What You'll Achieve at SANS

We are seeking a Senior SOC Engineer - Agentic to join our Security team. This role is a dual-focus security engineering role. On one side, this engineer owns the design and buildout of our agentic SOC - building the detection engineering, automation, and AI agent infrastructure that allows a lean security team to operate at the scope of a much larger one.

On the other, they serve as a hands-on security engineer across the full breadth of the program: vulnerability management, cloud security, identity and access management, application security, architecture reviews, and compliance support.

Initially the role will split roughly evenly between these two tracks. As the Agentic SOC matures and AI agents absorb more of the operational workload, the balance will shift - but the security engineering work never goes away. This is a role for someone who wants to do real security engineering today while building the systems that redefine what security engineering looks like tomorrow.

As a Senior SOC Engineer - Agentic, you will:
  • Agentic SOC Buildout
    • Design the architecture of the agentic SOC. Define how data flows through the detection and response pipeline, how agents are structured and orchestrated, where human-in-the-loop checkpoints belong, and how the overall system evolves as we expand agent autonomy.
    • Build and own detection engineering. Write, tune, and maintain detections across our internal SIEM environment. Treat detection content as code - version-controlled, peer-reviewed, tested, measured. Establish the lifecycle of design 1 deploy 1 measure 1 tune 1 improve.
    • Translate SOC operations into automation. Identify the alert triage, investigation, and response work that is ripe for agent augmentation, and define what good looks like for each workflow before it gets handed to an agent.
    • Build automations and integrations across our stack. Connect our MSSP, EDR, SIEM, cloud infrastructure, and identity platforms through integrations, scripts, and playbooks - both deterministic automation where that is the right tool, and agent-driven workflows where it is not.
    • Partner with AI Engineering to build and govern the agent stack. Co-design the MCP servers and tool integrations that let agents work with security systems. Contribute to prompt design, evaluation harnesses, and feedback loops - and own the audit trails and checkpoints that keep agent actions safe and accountable.
    • Operate and improve. Monitor agent performance, investigate failures, tune behavior, and feed real-world outcomes back into the system. The job does not end when something ships.
  • Security Engineering
    • Vulnerability management. Own the vulnerability identification, prioritization, and remediation tracking program. Work with engineering and infrastructure teams to drive risk reduction across the environment.
    • Cloud security. Assess and improve cloud security posture across AWS and Azure - identity and access management (IAM) policy review, configuration hardening, cloud-native detection, and ongoing posture monitoring.
    • Identity and access management. Partner with IT and engineering on identity architecture, access reviews, privilege management, and authentication standards.
    • Application security. Conduct code reviews, threat models, and security assessments for internal applications and integrations. Partner with development teams to shift security left.
    • Security architecture reviews. Evaluate new technologies, integrations, and infrastructure changes for security risk. Provide pragmatic, risk-based guidance.
    • Compliance and audit support. Support security compliance activities, evidence collection, and audit engagements as needed.
  • Respond to incidents. When something real happens, you are part of the response. The agents help; they do not replace you.
  • Perform other related duties as assigned.


What We're Looking For

Every SANS employee brings something unique. For this role, we're looking for candidates with:
  • 7+ years in security operations, detection engineering, or security automation, with enough depth to lead engineering efforts independently - and enough intellectual curiosity to be genuinely excited about rebuilding how a SOC works from the ground up.
      • First-hand experience with what a well-run SOC looks like - alert triage workflows, escalation paths, investigation patterns, incident response lifecycle.
      • Detection engineering experience: writing and tuning detections, measuring efficacy, managing false positives. Expert-level command of at least one detection query language (KQL, SPL, Lucene, Sigma, or equivalent).
      • MITRE ATT&CK fluency as a working tool, not a reference.
      • Hands-on experience with EDR and SIEM platforms in production environments.
  • Ability to design end-to-end security operations pipelines - from log ingestion and detection through enrichment, triage, investigation, and response - with a clear understanding of where automation fits at each stage.
  • Systems thinking: comfortable reasoning about data flows, dependencies, failure modes, and the operational implications of architectural decisions before they are built.
  • Experience designing for scale and maintainability - architectures that a small team can operate, extend, and recover when things break.
  • Exposure to threat modeling concepts applied to security infrastructure - you do not need to have owned this, but you should be ready to grow into it.
  • Comfort thinking through architectural tradeoffs and documenting your reasoning - this is a skill we will develop together, not a prerequisite.
  • Strong Python - production-quality code with testing, version control, code review discipline.
  • Comfortable building integrations against REST APIs across heterogeneous security tools.
  • Experience with SOAR platforms, security automation frameworks, or equivalent home-grown tooling.
  • Git-based workflows; as-code mindset for detections, automations, and infrastructure.
  • Working knowledge of AWS; experience with Azure or GCP is a plus.
  • Curiosity about how LLM-based agents differ from traditional automation, and where each fits.
  • Willingness to learn agent frameworks, MCP, and prompt engineering on the job, working alongside our AI Engineering team.
  • Side projects, reading, courses, or hobby experiments with LLMs or agents are a real plus - not because we need expertise, but because we need engagement.
  • Comfortable working with JSON and Markdown - the connective tissue of modern agent tooling, API integrations, MCP server schemas, and documentation.
  • Calibrated skepticism about over-automation - willing to say this should be a script, not an agent, or we should not automate this at all.
  • Operator empathy. A small security team will live with what you build. If you cannot sit with them and understand the work, you will build the wrong things.
  • Comfort with ambiguity. This program is being built, not maintained.
  • Unrestricted authorization to work in the USA; visa sponsorship is not available.


Preferred qualifications include:
  • Experience with MSSP-managed detection and response environments.
  • Detection-as-code experience: CI/CD pipelines for detection content, automated testing, content packaging.
  • Prior experience building SOAR playbooks (Tines, Torq, Cortex XSOAR, Splunk SOAR, or equivalent).
  • Incident response experience beyond Tier 1 - you have owned investigations end to end.
  • Cloud detection and response experience: audit logging, threat detection services, cloud security posture.
  • Identity-focused detection experience (Entra, Okta, Active Directory, or similar).
  • Any hands-on experience with LLM tooling: building with LLM APIs, agent frameworks (LangGraph, CrewAI, etc.), or MCP servers - even hobby-level.
  • Familiarity with agentic development workflows - CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar AI-assisted engineering tools.
  • Prompt injection and LLM adversarial thinking - particularly relevant since security agents constantly read attacker-controlled data.


Benefits and Perks of Working at SANS

We're committed to fair and equitable compensation. The expected salary range for this position is $155,000 to $205,000 which is comprised of base salary and bonus, depending on geographic location, skills, and experience. At SANS, pay equity and transparency are priorities.

We offer a comprehensive benefits package that supports your total well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
  • Financial Benefits: Competitive base salary, bonus opportunities, and a 401(k) plan with company match.
  • Health & Wellness: Robust medical, dental, and vision plans; company-provided short term disability; optional long-term disability, supplemental life and AD&D insurance for employees and dependents; voluntary benefits including accident insurance and identity theft protection; fitness and wellness programs; and a company paid employee assistance program (EAP).
  • Time Off & Flexibility: Generous paid time off, including volunteer time.
  • Learning & Development: Access to professional development and SANS training opportunities.


Flexibility and Balance at SANS

We support our colleagues with the tools and flexibility they need to thrive, both professionally and personally. As a primarily remote work environment, we are committed to maintaining strong connections, collaboration, and a vibrant culture across virtual teams. While most roles operate remotely, some positions may require occasional in-person presence depending on role-specific or business needs.

Similar Jobs

More Jobs at SANS Institute

  • Director of Software Engineering
    $200K — $240K *
    Bethesda, MD 20817 (Montgomery County)
    Enterprise Technology
    In-Person
  • Paid Media Manager
    $100K — $120K *
    Culver City, CA 90230 (Los Angeles County)
    Consumer Technology
    In-Person
  • Marketing Manager
    $95K — $100K *
    Culver City, CA 90230 (Los Angeles County)
    Retail & Consumer Goods
    In-Person

More Information Technology Jobs

Find similar Senior SOC Engineer - Agentic jobs: