Senior Security Operations Center Engineer
Vizient, Inc · Chicago, IL · 1 wk ago
Information Technology$89k–$156k/yrFull-time
Responsibilities
- Design, implement, optimize, and maintain enterprise security monitoring and detection capabilities.
- Develop and maintain SIEM detections, correlation rules, analytics, dashboards, and threat intelligence integrations.
- Engineer, administer, and optimize SIEM, SOAR, EDR/XDR, and cloud security platforms.
- Develop security automation playbooks that reduce manual analyst effort and improve incident response efficiency.
- Lead technical investigations during cybersecurity incidents and implement post-incident improvements to strengthen security posture.
- Conduct proactive threat hunting activities and develop reusable threat hunting content.
- Collaborate with Infrastructure, Cloud, Identity, Application Security, and Vulnerability Management teams to integrate security controls across the enterprise.
- Mentor SOC analysts and junior engineers by providing technical guidance, coaching, and engineering best practices.
- Participate in the Security Operations Center on-call rotation and respond to high-priority security incidents outside normal business hours.
- Provide technical leadership during major security incidents and assist with incident response coordination.
- Continuously evaluate emerging security technologies and recommend improvements to enhance security operations capabilities.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related technical field, or equivalent practical experience.
- 5+ years of experience designing, implementing, integrating, or supporting complex enterprise technology or cybersecurity solutions.
- Experience working within a Security Operations Center (SOC) or cybersecurity engineering environment.
- Experience administering one or more SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, or similar technologies.
- Experience with EDR/XDR platforms such as Microsoft Defender XDR or equivalent endpoint security technologies.
- Experience with SOAR platforms and security workflow automation.
- Experience developing scripts or automation using Python, PowerShell, C#, Java, or similar programming languages.
- Strong understanding of Windows, Linux, networking, identity management, cloud technologies, and enterprise infrastructure.
- Experience integrating APIs and automating enterprise security processes.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent written and verbal communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
- Ability to participate in the team's rotating on-call schedule.
- Experience securing Azure, AWS, Microsoft 365, or other cloud environments.
- Experience with threat hunting methodologies and threat intelligence integration.
- Knowledge of MITRE ATT&CK, NIST Cybersecurity Framework, CIS Controls, and other industry security frameworks.
- Experience creating SIEM detections using Kusto Query Language (KQL), Splunk Processing Language (SPL), SQL, or similar query languages.
- Familiarity with JSON, YAML, and infrastructure automation.
- Relevant cybersecurity certifications such as CISSP, GIAC (GCIA, GCIH, GMON), Microsoft Security certifications, Splunk certifications, or comparable industry certifications.
- Experience mentoring engineers or leading technical security initiatives.