Mercury Insurance

SOC Engineer

Mercury Insurance$83K — $161K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • BS degree in Computer Science, Information Technology, or related field; or equivalent experience.
  • 2-4 years of 24x7x365 Security Operations experience; 5+ preferred.
  • GIAC Security Essentials Certification; additional preferred certifications include GIAC Security Leadership, ISACA CISM, and (ISC)2 CISSP.
  • Understanding of IT infrastructure, networking, and common security principles.
  • Proficiency in security monitoring tools such as ExtraHop, Qradar, Splunk.

Responsibilities

  • Monitor security tools & systems for suspicious activity.
  • Investigate potential threats to identify real incidents and vulnerabilities.
  • Supervise all security incidents, including triage and remediation.
  • Gather and analyze evidence to assess incident impact.
  • Contain threats and implement measures to address vulnerabilities.
  • Assist in restoring affected systems and reporting security incidents to management.
  • Document findings and create process roadmaps for improvement.
  • Administer all SOC/NOC tools, including scripting and report building.

Benefits

  • Flexibility to work from anywhere in the U.S. for most positions.
  • Paid time off including vacation, sick leave, and holidays.
  • Incentive bonuses including performance-based and referral bonuses.
  • Comprehensive insurance including medical, dental, vision, and life.
  • 401(k) retirement savings plan with company match.
  • Professional development opportunities and education assistance.
Full Job Description
Overview

 

Position Summary:

 

The primary job function of the Security Operations Center Engineer is to identify, investigate, and escalate alerts and events to safeguard sensitive information from unauthorized access or breaches of malicious and potentially damaging intent in a 7x24x365 environment. Manages and configures security monitoring tools. Assess security systems and measures for weaknesses and possible improvements. Maintain up-to-date knowledge of the IT security industry including awareness of new or revised security solutions. Must be ethical, curious, and detail oriented.

 

Will also be responsible for definition of security process road maps and knowledge articles (KB), change management validations, user/system impacted security incident management and resolutions; Administration of Security Operations Center owned tools including scripting, customizations, report building, alert modifications, automations and maintenance; Minimize risk and exposure to system security and business interruptions of companys infrastructure; actively participate in disaster recovery and BCP events. Some scripting, coding and/or technical certificates may be needed to achieve certain job functions, so willingness to expand technical attributes will be expected.

 

Geo-Salary Information

An in-person interview may be required during the hiring process

 

State specific pay scales for this role are as follows:

$83,670 to $161,815 (NJ, NY, WA, HI, AK, MD, CT, RI, MA)

$76,064 to $147,104 (NV, OR, AZ, CO, WY, TX, ND, MN, MO, IL, WI, FL, GA, MI, OH, VA, PA, DE, VT, NH, ME)

$68,457 to $132,394 (UT, ID, MT, NM, SD, NE, KS, OK, IA, AR, LA, MS, AL, TN, KY, IN, SC, NC, WV)

 

In CA: Typical hiring range is $110,468 to $153,428

 

The expected base salary for this position will vary depending on a number of factors, including relevant experience, skills and location.

Responsibilities

Essential Job Functions:

  • Monitor security tools & systems: Analyze logs, alerts, and data for suspicious activity.
  • Investigate potential threats: Determine if alerts are real incidents and identify vulnerabilities.
  • Supervise all Incident/Security issues, including preliminary triage, troubleshooting and remediation.
  • Gather evidence: Collect and analyze evidence to understand incident scope and impact.
  • Contain the threat and remediate vulnerabilities: Quickly contain the incident to minimize damage, and implement patching, configuration changes, or other measures to address the exploited vulnerabilities.
  • Recover from the incident and report to management: Assist in restoring affected systems and data to their normal state, and keep management informed about security incidents and response efforts.
  • Documentation: Document findings for future reference and improvement, including process roadmaps, change management validations, and user/system impacted incident management and resolutions.
  • Administer SOC/NOC tools: Manage and administer all SOC/NOC Operations center owned tools, including scripting, customizations, report building, alert modifications, automations, and maintenance.
  • Minimize risk and exposure to system security and business interruptions of the companys infrastructure.
  • Participate in disaster recovery and BCP events: Actively participate in disaster recovery and Business Continuity Plan (BCP) events.e

 

Qualifications

Education:

Minimum:

  • BS degree in Computer Science, Information Technology, related field; and/or equivalent combination of education or work experience

Preferred:

  • GIAC Security Essentials Certification
  • GIAC Security Leadership Certification
  • ISACA Certified Information Security Manager
  • Microsoft Certified Systems Engineer: Security
  • (ISC)2 SCCP
  • (ISC)2 CISSP
  • (ISC)2 ISSAP
  • CCSK4

Experience:

Minimum:

  • 2-4 years of 24x7x365 Security Operations experience and related technologies

Preferred:

  • 5 or more years of 24x7x365 Security Operations and related technologies

Skills & Abilities:

Enterprise Security Operations support experience

  • Enterprise security document creation.
  • Understanding of IT infrastructure and networking: This includes knowledge of operating systems, network protocols, and basic infrastructure components.
  • Security principles and technologies: Familiarity with common security threats, vulnerabilities, and mitigation strategies like firewalls, intrusion detection/prevention systems (IDS/IPS), and SIEM tools.
  • Scripting and automation: Ability to write basic scripts to automate tasks and generate reports.
  • Incident response procedures: Understanding of established processes for handling security incidents, including containment, eradication, and recovery.
  • Security tools and software: Proficiency in using the specific security tools and software typically employed by a security organization.
  • Experience in using ExtraHop, Qradar, Splunk and/or any other security related tools for the visibility, monitoring, detection, alerting, response, and investigation of security related events.
  • Communication: Clear and concise communication with technical and non-technical audiences, including reporting incidents to management and collaborating with other IT teams (including public speaking, critical business writing skills, process documentation and knowledge base article composure)
  • Critical thinking and problem-solving: Ability to analyze complex security data, identify root causes of incidents, and develop effective solutions.
  • Attention to detail: Meticulous focus on identifying subtle anomalies and potential threats within vast amounts of data.
  • Decision-making under pressure: Making quick and informed decisions during critical security incidents.

Preferred:

  • ServiceNow
  • SIEM Solutions
  • TrustWave
  • Email Protection Solutions
  • Endpoint Detection & Response Solutions
  • Microsoft 365 Security Suite
  • Incident Management Communication tools
  • CV/CIRT Gov9t notification process
  • Load balancers & Web Application Firewall Solutions
  • Firewall/router/networking equipment
  • Web Content Filtering (WSS)
  • Secure Web Gateway Solutions
  • ITIL Foundations certifications (V3 or V4)

Perks and Benefits

We offer many great benefits, including:

  • Competitive compensation
  • Flexibility to work from anywhere in the United States for most positions
  • Paid time off (vacation time, sick time, 9 paid Company holidays, volunteer hours)
  • Incentive bonus programs (potential for holiday bonus, referral bonus, and performance-based bonus)
  • Medical, dental, vision, life, and pet insurance
  • 401 (k) retirement savings plan with company match
  • Engaging work environment
  • Promotional opportunities
  • Education assistance
  • Professional and personal development opportunities
  • Company recognition program
  • Health and wellbeing resources, including free mental wellbeing therapy/coaching sessions, child and eldercare resources, and more

Pay RangeUSD $83,670.00 - USD $161,815.00 /Yr.

About Mercury Insurance

Mercury Insurance Group is a multiple-line insurance organization offering personal automobile, homeowners, renters and business insurance. Founded in 1961 and headquartered in Los Angeles, Mercury has assets in excess of $4 billion, employs 4,500 people and has more than 8,000 independent agents in 11 states. Mercury has been named one of America's Most Trustworthy Companies by Forbes magazine, and has been recognized as one of the Best Places to Work in Los Angeles for eight years running. The company has also been named one of America's Best Midsize Employers by Forbes.
Learn more about Mercury Insurance
Size
4,300 employees
Market Cap
$1.8 billion
Industry
Net Income
$374.6 million
Founded
1962
5 Year Trend
+4.3%
Revenue
$3.7 billion
NASDAQ

Similar Jobs

More Jobs at Mercury Insurance

More Information Technology Jobs

Find similar SOC Engineer jobs: