> Markdown version of [/jobs/ext/1180549-security-engineer-soc-ii](https://www.wearedevelopers.com/jobs/ext/1180549-security-engineer-soc-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer SOC II - **Company:** Paul May & Associates - **Location:** Skokie, IL, United States - **Experience:** Expert - **Salary:** $85,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Automation of Tests, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Intrusion Detection Systems, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Information Technology, Sumo Logic (Software), Splunk, Servicenow - **Published:** July 4, 2026 - **Apply:** https://www.careerjet.com/jobad/usf1077b6e03bf41274b5f0661fdb5a3bd ## About the Role Minimum eight (8) years combined IT/ Cybersecurity experience five (5) years Cybersecurity experience and must have Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience). 5+ years of cybersecurity experience (SOC, Incident Response, or related functions). Strong hands-on experience with Sumo Logic (or Splunk) for SIEM operations. Must have familiarity with incident response frameworks and playbook development Experience with at least enterprise security applications (EDR (CrowdStrike), SIEM, IAM, Vulnerability Management, DLP, etc.). Knowledge of regulatory and compliance standards (HIPAA, NIST, FedRAMP). Industry certifications (e.g., GCIA, GCIH, CISSP, Azure Security) preferred. Participate in compliance reviews and security assessments (HIPAA, NIST, ISO). Contribute to security projects and mentor junior team members. ## Description Seeking a Security Engineer II to strengthen our SOC (Security Operations Center) and lead incident response activities across cloud, network, and endpoint environments. This mid-level role requires hands-on expertise with Sumo Logic and a strong grasp of the incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned). The ideal candidate will be comfortable investigating alerts, refining SOC processes, and working with multiple enterprise security platforms (CrowdStrike, Tenable SC, Delinea, Palo Alto xDome, Bitsight, Azure, ServiceNow, Splunk). Key Responsibilities Monitor and investigate SOC alerts from SIEM, EDR, IDS/IPS, DLP, and cloud security tools. Lead incident response activities, including containment, remediation, documentation, and reporting. Build, maintain, and tune Sumo Logic dashboards, queries, and integrations. Support vulnerability management and coordinate remediation with IT teams. Document playbooks, improve SOC processes, and provide lessons-learned feedback. Collaborate with infrastructure, cloud, and application teams to reduce risks. Independently conduct complex incident investigations and report results and attack information to leaders/management. Partner with engineering and IT teams to mitigate IoT/IoMT security risks., As a QA Automation Engineer, you will play a crucial role in shaping the future of AI systems by designing and implementing automated testing solutions. Your expertise will directl… + 1 day ago, Join a dynamic team as a Software Engineer, contributing to innovative backend software development and AI model evaluation. This role offers the opportunity to leverage your engin… + 4 days ago + ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)