Job Closed
This listing is no longer active.
Secure greatness™
Senior SecOps Engineer
Location
Ohio + 3 moreAll locations: Ohio | Massachusetts | Michigan | Missouri
Posted
128 days ago
Salary
0
Seniority
Senior
Job Description
Senior SecOps Engineer
Optiv
• Serve as a primary responder for AFC customer systems, taking ownership of client configuration issues and tracking through resolution. • Act as a point of escalation for junior level Engineers and provide guidance and mentoring. • Advise best practice on SIEM/MDR/SOAR products to both technical and relatively non-technical personnel. • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies. • Implement and configure SIEM/MDR/SOAR software and appliance-based products in large enterprise and Government environments. • Develop and maintain security content and reporting. • Perform knowledge transfers to clients regarding security and system configuration awareness.
Job Requirements
- 4-7 years professional experience maintaining SIEM or infrastructure systems in the Information Security field.
- Minimum 18-months hands-on experience in Google Sec Ops.
- College degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.
- Understanding of network architecture and implementation is a must; ideal candidate will have worked with network security analysis.
- Excellent time management, reporting, and communication skills.
- Superior IT problem-solving skills.
- Experience with SIEM content and reporting.
- Experience working with Linux OS.
- Experience writing/developing scripts (e.g. python, bash, ruby, powershell).
- Experience working with Internal and client Ticketing and Knowledge Base Systems for Incident and Problem tracking as well as procedures. (i.e. Jira, Confluence, etc.).
- Experience with various SIEM security products such as: Exabeam, Chronicle, Sentinel, LogRhythm, QRadar, Splunk, and infrastructure components such as proxies, firewalls, IDS/IPS, DLP etc.
- General security knowledge (GIAC, CISSP, CCSE, CISA, HBSS, NSA, CEH, Cisco Security, Security +, or other security certifications).
- Knowledge of Linux and Windows Operating Systems.
- An understanding of a wide array of server grade applications such as: DBMS, Exchange, DNS, SMTP, IIS, Apache, SharePoint, Active Directory, Identity Management, Patch Management, LDAP, SQL, and others.
- Training and experience in one or more non-SIEM network security products to include: Enterprise endpoint security products, Network components such as Firewalls and Proxies to include Palo Alto / Checkpoint / Juniper / McAfee / Cisco / Blue Coat / Imperva or other similar network security products.
- CCNA, CCDA, CCSA, CCIE, CISSP, CEH, or MCSE.
- Familiarity with DevOps
- Professional experience working with networks and network architecture.
- Ability to participate in on-call support.
- Demonstrated experience and success in a Managed Service client environment.
- Ability to work greater than 40 hours per week as needed.
Benefits
- Work/life balance
- Professional training resources
- Creative problem-solving and the ability to tackle unique, complex projects
- Volunteer Opportunities.
- “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
- The ability and technology necessary to productively work remotely/from home (where applicable)
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Security Operations Analyst
Climb Channel Solutions NAA different breed of specialty technology distributor. #ClimbWithUs
• Monitor Delinea security platforms to identify, investigate, and respond to security events. • Lead cross-functional response coordination for security incidents. • Develop, design, and implement security operations enhancements to reduce risk. • Work with other business areas to enhance security and provide security awareness. • Research, evaluate, and implement security products and services as directed by security management.
Security Operations Center Architect
accesa.euThe place where creative problem-solvers that care for people, solutions, and their impact thrive
• Architect the Modern SOC → Lead the end-to-end design of a cloud-native SOC, defining the strategy, Azure technical architecture, and operational model aligned with Zero Trust and business needs. • Translate Risk into Detection → Convert abstract security strategies and business risks into actionable detection logic by designing and maintaining advanced analytics rules using KQL in Microsoft Sentinel. • Optimize Security at Scale → Design cost-efficient ingestion and retention strategies, including Log Tiering (Analytics, Basic, Archive), balancing visibility, performance, and Azure ingestion costs. • Engineer SIEM & XDR Integrations → Architect seamless integrations between Microsoft Sentinel and the Microsoft Defender XDR suite (MDE, MDI, MDA, MDO), enabling bi-directional synchronization and enriched incidents. • Automate Response & Operations → Design and implement advanced SOAR playbooks using Azure Logic Apps or Power Automate to automate incident enrichment, response, and containment actions. • Enable Operational Excellence → Define SOC workflows, incident response processes, health monitoring, and KPI visualization (MTTD, MTTR, FPR), while mentoring Tier 3 analysts and ensuring sustainable operations.
• Act as the primary technical escalation point for complex operational issues, ensuring quick and effective resolutions. • Maintain and optimize critical systems, including SIEM platforms (e.g., Splunk, ELK, SumoLogic, Sentinel), Anti-Virus tools (Trend Micro Deep Security Manager, Microsoft Defender, Crowdstrike) and vulnerability management tools (e.g., Nessus, Qualys, Burp). • Monitor and improve the team’s use of automation and monitoring tools to drive operational efficiency. • Analyze and resolve system performance issues, ensuring compliance with security and operational standards. • Participate in incident response and post-mortem analysis to identify root causes and prevent recurrence. • Mentor and support the professional growth of engineers through training, feedback, and career development planning. • Assist with hiring, onboarding, and retention to ensure team stability and growth. • Oversee day-to-day delivery of security services, ensuring operational consistency and high-quality outcomes. • Track and optimize key metrics such as incident response times, operational efficiency, and compliance posture. • Develop and refine processes for incident response, vulnerability remediation, and compliance reporting. • Work with cross-functional teams, including consulting teams, SREs, and professional services teams, to improve service delivery.
• Lead and coordinate responses to security incidents, including ransomware, host compromise, credential and account compromise, phishing, insider threats, third-party risks, and data spillage while collaborating closely with information security leadership, business stakeholders, and the rest of the incident response team • Produce clear, accurate incident documentation and post‑incident analysis focused on root cause and measurable improvement • Participate in incident response tabletop exercises to identify gaps, enhance skills, and engage stakeholders; review technical reports from vulnerability and penetration testing assessments to identify potential exposure to future incidents • Improve Security Operations practices by contributing to the development, refinement, and maintenance of SOC procedures, playbooks, policies, and guidelines • Assess the effectiveness of security controls and technical risks across hosting environments, and communicate findings clearly to both technical and non-technical stakeholders • Own and act as a subject matter expert for one or more core security tools or platforms, ensuring data quality, reliable operation, and effective use.




