Remote job
SNOC Engineer III
Job details
About this role
Role overview A senior Security Network Operations Center engineer is needed to lead advanced incident response, detection engineering, and operational improvements within a fast-paced cyber defense environment. This remote role focuses on strengthening monitoring, mentoring junior engineers, and driving continuous improvement in threat detection and response workflows. The position suits someone who combines deep technical expertise with leadership and a commitment to operational excellence.
Responsibilities - Serve as the primary escalation point for complex and high-severity incidents, guiding containment, eradication, and recovery efforts. - Lead advanced threat analysis using SIEM, EDR, identity protection, and network telemetry to detect malicious or suspicious activity. - Engineer and refine detection capabilities, including analytics rules, threat-hunting queries, alert enrichment logic, and automated playbooks. - Mentor junior engineers during investigations, troubleshooting, and incident response, while providing technical guidance and training. - Identify risks and vulnerabilities across endpoint, identity, email, cloud, and network environments, recommending remediation actions. - Maintain runbooks, response procedures, investigation guides, and knowledge base articles, and support compliance and audit documentation.
Requirements - Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent practical experience. - Hands-on experience with SIEM and monitoring platforms such as Microsoft Sentinel, Wazuh, or SentinelOne. - Strong understanding of networking fundamentals, endpoint protection, identity protection, and cloud environments such as Azure or AWS. - Demonstrated ability to perform advanced log analysis, threat hunting, and alert triage across multiple telemetry sources. - Experience leading high-severity operational events, conducting root cause analysis, and coordinating cross-team response. - Strong written and verbal communication skills for internal documentation and client-facing discussions.
Nice to have - GIAC certifications such as GCIH, GCIA, or GCFA. - CompTIA CySA+ or CASP+. - Microsoft Certified: Azure Security Engineer Associate or AWS Certified Specialty. - Cisco CCNP or equivalent networking certification. - Familiarity with detection engineering, alert tuning, automation, and compliance or operational best-practice frameworks.
Benefits and work setup - Remote position with standard business hours on the first shift. - Annual salary of $105,000. - Medical, dental, and vision coverage, plus life insurance. - 401(k) with company match. - Flexible spending account and health savings account options. - Pet insurance and a "you pick a day" paid holiday, plus additional benefits.