> Markdown version of [/jobs/ext/1254687-information-security-engineer-security-operations-soc](https://www.wearedevelopers.com/jobs/ext/1254687-information-security-engineer-security-operations-soc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - Security Operations (SOC) - **Company:** Harris Health - **Location:** Bellaire, TX, United States - **Experience:** Experienced - **Salary:** $99,216.0 - $129,002.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Microsoft Office, Windows PowerShell, Kusto Query Language, Runbook, Security Information and Event Management, Scripting, Data Ingestion, Microsoft Power Automate, Mitre Att&ck, Mttr, Azure Security Center, Microsoft Sentinel - **Published:** July 13, 2026 - **Apply:** https://kshealthjobs.net/jobs/rss/22421568/information-security-engineer-security-operations-soc ## About the Role Bachelor's degree in Cybersecurity/IT or equivalent experience. 2 - 4+ years in SOC, SIEM engineering, or detection/response roles. Experience building automation. Strong understanding of incident response and MITRE ATT&CK. Experience integrating MSSP feeds and third-party tools. Certifications such as SC-200, SC-100, AZ-500, Security+, CEH Strong analytical and communication skills. Team-oriented with a positive and professional approach. Preferred Qualifications: Hands-on experience with Microsoft Sentinel (KQL, analytics rules, workbooks, connectors). Hands-on experience with Microsoft Defender (Endpoint/XDR, Office 365, Identity). Scripting experience (PowerShell, Python). Experience building automation using Azure Logic Apps. ## Description The Information Security SOC Engineer is a hands-on cybersecurity professional responsible for engineering, operating, and automating detection and response capabilities. The engineer designs and maintains content in Microsoft Sentinel (data connectors, analytics rules, hunting queries, workbooks), enhances protections with Microsoft Defender (Endpoint/XDR, Office 365, Identity), and builds automation using Azure Logic Apps., Typical duties may include: Detection Engineering & SIEM Operations (Microsoft Sentinel and Rapid 7) Own Sentinel content lifecycle including data ingestion, analytic rules, KQL queries, UEBA tuning, watchlists, and dashboards. Develop hunting queries and proactive threat detection logic. Implement incident enrichment and correlation across multiple data sources. Endpoint, Email, and Identity Protection (Microsoft Defender) Engineer configurations within Microsoft Defender for Endpoint/XDR, Defender for Office 365, and Identity protection. Integrate Defender alerting with Sentinel for enhanced detection correlation. Automation & Orchestration (Azure Logic Apps) Build, deploy, and manage Logic Apps SOAR playbooks for automated triage, enrichment, and response. Implement approval flows, track automation metrics, and improve MTTR. Incident Response & Collaboration Support containment, eradication, and recovery of security incidents. Conduct post-incident reviews and update detection logic and processes accordingly. Runbooks, Documentation & Continuous Improvement Maintain engineering runbooks, playbooks, and process documentation. Track SOC metrics and produce security operational dashboards. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [3 Key Steps for Optimizing DevOps Workflows](https://www.wearedevelopers.com/videos/962-3-key-steps-for-optimizing-devops-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)