Security Operations Engineer - Level 3
We are seeking an experienced Level 3 Security Engineer with strong expertise in Security Operations, Detection Engineering, SIEM/SOAR, EDR, and cloud security. The ideal candidate will support advanced security monitoring, detection development, alert tuning, and incident investigation across enterprise environments.
Primary Responsibilities
Monitor and investigate advanced security events using SIEM, SOAR, EDR, email security gateways, and firewalls.
Develop, implement, and maintain security detections, rules, and alerts.
Perform rule and alert tuning to improve detection accuracy and reduce false positives.
Conduct advanced security investigations and support incident response and threat analysis.
Map security detections and activities to the MITRE ATT&CK framework, including relevant tactics and techniques.
Develop and enhance detection use cases based on emerging threats and attack patterns.
Work across AWS, Azure, and/or GCP environments to monitor and improve cloud security.
Collaborate with Security Operations, Incident Response, Threat Intelligence, and Engineering teams.
Troubleshoot complex security monitoring and detection issues and provide Level 3 technical support.
Continuously improve security monitoring, detection coverage, and operational processes.
Required Skills
Strong experience in Security Operations / Security Engineering.
Hands-on experience with SIEM/SOAR, EDR, email security, and firewall technologies.
Proven experience in Detection Engineering.
Experience developing and tuning security rules, alerts, and detection logic.
Strong understanding of the MITRE ATT&CK framework.
Experience with AWS, Azure, and/or GCP security environments.
Familiarity with Google Security Operations.
Strong analytical, troubleshooting, and incident investigation skills.