IT Security Engineer
Job Description
Role Overview
The SOC Engineer serves as the technical lead for the organization’s SIEM platform and acts as the SOC Tier 3 escalation resource. This position is responsible for designing, tuning, and continuously improving detection content. It also drives SOAR playbook creation and adherence, and provides deep investigative support for the most complex security incidents. The ideal candidate combines strong hands-on SIEM engineering and query-language skills with sound judgment and the ability to mentor Tier 1 and Tier 2 analysts while shaping the SOC’s detection strategy.
Key Responsibilities
- Own and advance the SIEM platform, including analytics and correlation rules, dashboards, data connectors, ingestion and cost management, and the detection roadmap.
- Lead detection engineering by designing, building, tuning, and validating analytics rules across identity, endpoint, cloud, and network telemetry.
- Serve as the SOC’s Tier 3 escalation point for deep technical investigation, root-cause analysis, and forensic collection on the most complex or high-severity incidents.
- Design, build, and maintain SOAR playbooks, ensuring consistent analyst adherence to documented procedures.
- Build automation and enrichment pipelines, including AI-assisted triage where applicable, to reduce manual work and improve mean time to detect and mean time to respond.
- Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts, including review of investigations and coaching on playbook execution.
- Evaluate, onboard, and tune new log sources, data connectors, and threat intelligence feeds to broaden detection coverage.
- Partner with IAM, endpoint, and network security teams to ensure detection coverage evolves with control and infrastructure changes.
- Track and report detection engineering and SOC performance metrics, including MTTD, MTTR, playbook adherence, and false-positive rates.
- Maintain thorough documentation for detection logic, playbooks, and incident response procedures.
- Participate in the on-call rotation and respond to security incidents after hours when necessary.
Minimum Requirements
- 4+ years of experience in cybersecurity, including at least 2 years of hands-on experience with an enterprise SIEM platform and its query language(s).
- Proven ability leading or serving as a senior Tier 3 resource within a SOC or incident response function.
- Strong hands-on experience building and tuning SIEM analytics rules and detection content.
- Experience designing and maintaining SOAR playbooks or comparable security orchestration and automation tools.
- Solid incident response and forensics experience, including investigation, evidence handling, and documentation.
- Proficiency with scripting and automation using PowerShell, Python, or similar tools.
- Experience integrating security tools (EDR, email security, identity, network) into a SIEM for detection and correlation.
- At least one relevant security certification, such as GCIA, GCIH, CySA+, Security+, or a vendor-specific SIEM certification.
- Strong understanding of the MITRE ATT&CK framework and common adversary tactics, techniques, and procedures.
- Ability to respond to security incidents after hours when necessary.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
- Experience developing SIEM dashboards and reporting, including executive and board-level security metrics.
- Experience with AI or LLM-assisted alert enrichment or triage pipelines.
- Familiarity with common enterprise security stack components (EDR, secure web gateway/CASB, identity providers, email security) and how they integrate into detection workflows.
- Familiarity with SOC 2, risk assessments, and other GRC functions.
- Advanced certifications such as GCFA, GCTI, OSCP, or CISSP are a plus.
- Excellent problem-solving skills and the ability to lead through ambiguity under pressure.
- Strong communication skills, including the ability to present technical findings to technical and non-technical stakeholders.
Physical Demands
The physical demands described for this position are representative of those that must be met by an employee to successfully perform the essential functions of the job. While performing these duties, the employee is regularly required to talk or hear. The employee is frequently required to stand, walk, use hands to handle and feel, reach with hands and arms, and use and operate objects, tools, or controls.
Work Environment
While performing the duties of this job, the employee is not substantially exposed to adverse environmental conditions (such as typical office or administrative work). The employee may be subject to atmospheric conditions that can affect the respiratory system or skin, including fumes, odors, dust, mists, gases, or poor ventilation.
Competencies
- Excellent oral and written communication skills to interact effectively with internal customers and department staff.
- Self-motivated.
- Team-oriented.
- Customer-oriented.
- Ability to follow Company safety rules and all other Company policies.
Pike Enterprises, LLC is an Equal Opportunity Employer. EOE/Minorities/Females/Vet/Disabled. NOTE: This job description is not intended to be all-inclusive. The employee may perform other related duties as requested to meet the ongoing needs of the organization.