Cyber Security Engineer - SOC Lead

Remote • Posted 9 hours ago • Updated 9 hours ago
Full Time
No Travel Required
Remote
$80 - $85/hr
Fitment

Dice Job Match Score™

⭐ Evaluating experience...

Job Details

Skills

  • SOC
  • SIEM
  • QRadar
  • Threat Detection
  • incident response
  • EDR/XDR tools
  • MITRE ATT&CK

Summary

Job Title: Sr. Cybersecurity Engineer (SOC/Threat & Incident Detection)

Remote - EST/CST

Location: Cambridge, MA

 

Required Skills & Experience:

  • 8–12+ years in cybersecurity / SOC / threat detection roles
  • Experience in L2/L3 SOC or Security Operations leadership.

 

Technical Skills:

  • Strong hands-on expertise in:
    • SIEM: Sentinel / Splunk / QRadar
    • EDR/XDR tools
    • Threat hunting & incident response
  • Deep understanding of:
    • MITRE ATT&CK
    • Threat vectors, malware behavior, attack techniques
  • Experience with:
    • Log analysis, detection engineering, and correlation rules
    • Security automation (SOAR)

 

Cloud & DevSecOps

  • Experience securing AWS/Azure environments
  • Familiarity with:
    • CI/CD security (GitHub, GitLab, Jenkins)
    • IaC security (Terraform, CloudFormation)
    • Policy-as-code (OPA, Checkov)

Threat Detection & Incident Response

  • Lead end-to-end investigation of complex security incidents (malware, phishing, lateral movement, cloud compromise)
  • Perform advanced threat hunting using SIEM, EDR, and cloud telemetry
  • Conduct deep forensic analysis (endpoint, network, logs, email headers)

Detection Engineering & SOC Optimization

  • Design and implement high-fidelity detection rules and use cases
  • Develop and enhance SOC playbooks aligned with MITRE ATT&CK

Security Tooling & Platforms

  • Lead implementation and optimization of:
    • SIEM: Microsoft Sentinel / Splunk / QRadar
    • EDR/XDR: Defender, CrowdStrike, SentinelOne
    • Email Security: Proofpoint, Mimecast, Defender for Office
    • WAF & Network Security tools
  • Manage integrations across multi-vendor security stack

Automation & SOAR

  • Develop automation playbooks (SOAR) for triage, enrichment, and response

Cloud Security & DevSecOps

  • Monitor and secure cloud environments (AWS/Azure)
  • Implement logging and detection using:
    • CloudTrail, VPC Flow Logs, Defender, Sentinel
  • Drive DevSecOps practices (SAST, DAST, IaC scanning, policy-as-code)

Risk, Compliance & Governance

  • Perform vulnerability assessments and risk analysis
  • Ensure alignment with frameworks:
    • NIST, CIS Benchmarks, GDPR, PCI-DSS

 

Nice to Have

  • Experience with:
    • Email security platforms (Proofpoint, Mimecast)
    • WAF/CDN (Akamai, Cloudflare)
    • Threat intelligence platforms

 

Certifications (Preferred)

  • CISM / CISSP
  • CEH / CHFI
  • Vendor certifications (Microsoft Sentinel, QRadar, Splunk)
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91134724
  • Position Id: 8978895
  • Posted 9 hours ago
Contact the job poster
PC

Payal Chitnis

Recruiter @ Next Gen IT Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Full-time

Remote or New York

Today

Full-time

USD 178,200.00 - 297,000.00 per year

Remote or Johnston, Rhode Island

Today

Full-time

USD 66,320.00 - 99,480.00 per year

Remote or Jersey City, New Jersey

Today

Full-time

-

Search all similar jobs