Dispel logo
Dispel

Moving Target Defense-based remote access systems for people and machines.

Senior Security Operations Engineer

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 51-200Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

58 days ago

Salary

$136K - $155K / year

Seniority

Senior

6 yrs expEnglishAWSAzureCloudSplunk

Job Description

Senior Security Operations Engineer

Dispel

• Own the log ingestion pipeline end-to-end: identify gaps, build feeds, validate parsing, maintain coverage dashboards • Close the federal logging gap and stand up commercial logging across AWS, Azure, Entra ID, and SaaS • Activate and configure SecOps SOAR capabilities including Domain-Wide Delegation, marketplace integrations, and bidirectional response actions • Build and maintain SOAR playbooks for major incident types such as phishing, malware, account compromise, lateral movement, and cloud-specific threats • Develop and maintain operational dashboards for SOC metrics, alert volumes, MTTA/MTTR, and coverage status • Manage Google SecOps RBAC • Build and deploy production detection rules mapped to MITRE ATT&CK within the first year • Develop custom parsers for AWS-native security services including GuardDuty, Security Hub, Inspector, WAF, CloudTrail, and VPC Flow Logs • Establish a detection lifecycle including proposal, testing, deployment, tuning, and retirement • Conduct quarterly detection quality reviews to measure false positive rates, coverage gaps, and rule health • Develop alert threshold optimization to reduce noise and analyst fatigue • Drive SentinelOne deployment across Azure VMs in commercial environments and all federal endpoints • Configure and operationalize Cloud Funnel for log export into Google SecOps • Build correlation rules between EDR alerts and SIEM detections • Manage SentinelOne RBAC groups and policy configuration • Coordinate with IT on agent deployment, health monitoring, and version management • Serve as senior escalation point for SOC incidents, ensuring investigations are thorough and reports include root cause, remediation actions, credential rotation plans, and follow-up timelines • Improve MTTA and MTTR through process optimization, better tooling, and analyst development • Lead quarterly tabletop exercises and after-action reviews • Maintain and improve incident response runbooks for all major incident categories • Integrate incident response workflows with Jira Service Management for tracking and escalation • Operationalize monthly scanning cadence across all environments using tools such as Nessus, AWS Inspector, and Azure Defender • Define and enforce remediation SLAs by severity: Critical within 72 hours, High within 7 days, Medium within 30 days • Build consolidated vulnerability dashboards in Google SecOps • Track SLA compliance and report metrics to the CISO • Coordinate remediation with engineering and infrastructure teams • Serve as primary technical interface with MSSP partner for 24/7 SOC coverage • Define and hold the MSSP accountable to SLAs, alert quality, and escalation procedures • Review MSSP deliverables such as dashboards, reports, and playbooks for quality and completeness • Manage the transition from the previous MSSP and ensure no coverage gaps • Provide day-to-day technical direction to SOC analysts by setting priorities, assigning tasks, and reviewing work products • Ensure incident response reports, playbooks, and dashboards meet quality standards before delivery to leadership or external stakeholders • Drive OKR execution for SOC-related objectives including logging coverage, detection counts, incident response metrics, and vulnerability SLA compliance • Identify skill gaps and development opportunities for junior analysts • Establish and enforce SOC processes that are documented, repeatable, and auditable

Job Requirements

  • 6+ years of experience in security operations, detection engineering, or SIEM/SOAR engineering
  • Hands-on experience with Google SecOps (Chronicle) or equivalent enterprise SIEM such as Splunk, Sentinel, or QRadar, with Chronicle strongly preferred
  • Production experience with SentinelOne, CrowdStrike, or a comparable EDR platform
  • Deep knowledge of AWS security services including GuardDuty, Security Hub, Inspector, CloudTrail, WAF, and Config
  • Experience building detection rules mapped to the MITRE ATT&CK framework
  • SOAR playbook development and automation experience
  • Demonstrated ability to lead without formal authority by setting direction for peers or junior analysts
  • Strong incident response skills with experience writing complete reports for executive and external audiences
  • Understanding of NIST 800-53 controls, particularly Audit, System Integrity, and Incident Response families
  • Excellent written communication skills

Benefits

  • 136K-155K base + equity and performance bonus eligible, depending on experience and location
  • Full medical, vision, and dental insurance
  • Generous PTO
  • Remote-first culture with flexible hours
  • Opportunity to protect critical infrastructure at scale
  • Work with patented, cutting-edge security technology
  • Direct ownership of SOC maturation
  • Collaborative team with military, federal, and private sector expertise

Related Categories

Related Job Pages

More Security Operations Jobs

Dispel logo

Senior Security Operations Engineer

Dispel

Moving Target Defense-based remote access systems for people and machines.

Full TimeRemoteTeam 51-200Since 2014H1B No Sponsor

Location: Remote (US-based) About Dispel: Dispel is the fastest-growing cybersecurity company recognized in the 2025 Cybersecurity Excellence Awards. We deliver zero trust secure remote access and real-time data streaming for operational technology (OT) and industrial control systems (ICS). Our patented Moving Target Defense technology — referenced in NIST 800-172 — protects critical infrastructure for utilities serving 54 million+ people, manufacturers producing over 50% of US baby formula, and major defense contracts including a $950M IDIQ with the US Air Force. Why This Role Exists: Dispel is pursuing FedRAMP High authorization while simultaneously operating a commercial security program. We have a functioning SOC built on Google SecOps (Chronicle) and SentinelOne, but we need a senior IC who can take it from "stood up" to "operationally mature." Today our SIEM ingests approximately 35% of total log sources. Our federal environment is at 75% coverage; commercial AWS sits at 30%; Azure and Entra ID are at 0%. Our MSSP recently transitioned and needs an internal technical owner to drive accountability. Our detection library, SOAR playbooks, and vulnerability dashboards are in draft or partially built. This person will be the day-to-day technical owner of SOC operations, responsible for closing coverage gaps, building detections, maturing incident response, and providing senior technical direction to the existing SOC analyst. This is a hands-on-keyboard role with leadership expectations — you will not formally manage people, but you will set priorities, review deliverables, and drive execution across the SOC function.

United States
$136K - $155K / year
MassMutual Financial Group logo

Director, Global Security Operations Center

MassMutual Financial Group

MassMutual Financial Group is a financial services firm that supplies individuals and businesses with insurance, retirement, investment, and financial planning assistance. MassMutu

• Execute SOC Operational Strategy • Oversee all global SOC operations, ensuring alignment with MassMutual’s cybersecurity strategy and regulatory requirements • Review SOC metrics, staffing needs, and budget requirements with security leadership • Drive Threat Detection & Incident Response Excellence • Lead the response to cybersecurity events and critical incidents, ensuring appropriate analysis, prioritization, escalation, and communications • Ensure structured and consistent incident handling processes across all SOC tiers • Strengthen Enterprise Communication & Decision Support • Act as the escalation and communication liaison with senior leadership and other critical stakeholders • Ensure timely, risk-aware decisions and clear communication of incident impacts and recommended actions • Advance Detection Engineering & Automation Capabilities • Partner with Detection Engineering and Security Platforms to optimize SIEM/SOAR alerting logic, tuning, and playbook development • Expand automation to improve analyst efficiency and response consistency • Develop & Inspire a High-Performing Global Team • Guide analyst growth through training, mentorship, certifications, and hands-on exercises • Foster a culture rooted in MassMutual values of inclusion, innovation, and continuous improvement

New York + 1 moreAll locations: New York | Massachusetts
$156K - $204.7K / year
Fastly logo

SOC Analyst – Security Operations

Fastly

Fastly’s edge cloud platform enables the best of the web to thrive, and helps you deliver better online experiences.

Full TimeRemoteTeam 501-1,000Since 2011H1B Sponsor

• Active Incident Response: Lead the identification and mitigation of high-impact security events. You will analyze sophisticated traffic patterns and implement precise countermeasures, including rate limiting and custom WAF & Security rules to neutralize threats in real-time. • Managed Security Delivery: Serve as a primary security consultant for MSS Customers. This involves continuous tuning and refining of security policies to optimize detection accuracy and maintaining a hardened security posture tailored to each client's unique environment. • Advanced Threat Hunting: Conduct data-driven investigations using log analysis to uncover potential threats and hardenings opportunities • Security Intelligence & Reporting: Author comprehensive After Action Reports (AARs) and monthly security summaries. You will translate complex telemetry and attack data into high-level actionable insights for customer stakeholders. • Strategic Communication: Act as the Subject Matter Expert (SME) during active security incidents. You will provide clear, calm, and professional guidance via real-time communication channels, ensuring customers are informed and confident in our defensive strategy.

Japan
Job Closed
DeepSeas logo

SOC Analyst Co-Op

DeepSeas

First & only Managed Detection & Response solution covering all attack surfaces for enterprises & the mid-market.

InternshipRemoteTeam 201-500Since 30 yearsH1B No Sponsor

• A SOC intern assists the Security Operations Center team by monitoring security alerts and events in real-time • Analyzing potential threats • Investigating incidents • Learning to respond to cybersecurity issues using various security tools, all while gaining practical experience in the field of cybersecurity under the guidance of experienced analysts • Key responsibilities include threat monitoring, incident triage, log analysis, and reporting on potential security breaches.

United States
Job Closed