Jobs · Information Technology · Illinois

Senior Security Operations Center Engineer

Vizient, Inc · Chicago, IL · 1 wk ago
Information Technology$89k–$156k/yrFull-time

Responsibilities

  • Design, implement, optimize, and maintain enterprise security monitoring and detection capabilities.
  • Develop and maintain SIEM detections, correlation rules, analytics, dashboards, and threat intelligence integrations.
  • Engineer, administer, and optimize SIEM, SOAR, EDR/XDR, and cloud security platforms.
  • Develop security automation playbooks that reduce manual analyst effort and improve incident response efficiency.
  • Lead technical investigations during cybersecurity incidents and implement post-incident improvements to strengthen security posture.
  • Conduct proactive threat hunting activities and develop reusable threat hunting content.
  • Collaborate with Infrastructure, Cloud, Identity, Application Security, and Vulnerability Management teams to integrate security controls across the enterprise.
  • Mentor SOC analysts and junior engineers by providing technical guidance, coaching, and engineering best practices.
  • Participate in the Security Operations Center on-call rotation and respond to high-priority security incidents outside normal business hours.
  • Provide technical leadership during major security incidents and assist with incident response coordination.
  • Continuously evaluate emerging security technologies and recommend improvements to enhance security operations capabilities.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related technical field, or equivalent practical experience.
  • 5+ years of experience designing, implementing, integrating, or supporting complex enterprise technology or cybersecurity solutions.
  • Experience working within a Security Operations Center (SOC) or cybersecurity engineering environment.
  • Experience administering one or more SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, or similar technologies.
  • Experience with EDR/XDR platforms such as Microsoft Defender XDR or equivalent endpoint security technologies.
  • Experience with SOAR platforms and security workflow automation.
  • Experience developing scripts or automation using Python, PowerShell, C#, Java, or similar programming languages.
  • Strong understanding of Windows, Linux, networking, identity management, cloud technologies, and enterprise infrastructure.
  • Experience integrating APIs and automating enterprise security processes.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
  • Ability to participate in the team's rotating on-call schedule.
  • Experience securing Azure, AWS, Microsoft 365, or other cloud environments.
  • Experience with threat hunting methodologies and threat intelligence integration.
  • Knowledge of MITRE ATT&CK, NIST Cybersecurity Framework, CIS Controls, and other industry security frameworks.
  • Experience creating SIEM detections using Kusto Query Language (KQL), Splunk Processing Language (SPL), SQL, or similar query languages.
  • Familiarity with JSON, YAML, and infrastructure automation.
  • Relevant cybersecurity certifications such as CISSP, GIAC (GCIA, GCIH, GMON), Microsoft Security certifications, Splunk certifications, or comparable industry certifications.
  • Experience mentoring engineers or leading technical security initiatives.

Similar jobs