> Markdown version of [/jobs/ext/2240918-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2240918-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - **Company:** Vertex, Inc. - **Location:** King of Prussia, PA, United States - **Salary:** $91,200.0 - $118,600.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, ARM Architecture, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Digital Forensics, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), PCI Data Security Standards, Windows PowerShell, Kusto Query Language, Reverse Engineering, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Data Logging, Scripting, Computer Networking Systems, Google Cloud, Cloud Platform System, GitHub Copilot, Mitre Att&ck, QRadar, Falcon Platform, Git Flow, Information Technology, Cybercrime, Oracle Cloud Infrastructure, Splunk, SentinelOne Expertise, Api Management - **Published:** August 26, 2026 - **Apply:** https://www.disabledperson.com/jobs/74544015-security-operations-engineer ## About the Role * Hands-on knowledge in security operations, incident response, detection engineering, or threat hunting, with demonstrated ability to lead significant investigations. * Strong knowledge of attacker tactics and techniques across endpoint, identity, network, cloud, and email environments, including MITRE ATT&CK mapping and IOC analysis. * Experience with SIEM platforms (Sentinel, Splunk, Chronicle, QRadar , or Elastic) and proficiency writing and tuning detection queries using KQL, SPL, Sigma, YARA, or equivalent. * Experience with EDR/XDR platforms (Defender for Endpoint, CrowdStrike, SentinelOne , Cortex XDR, or Carbon Black), including triage, investigation, and containment. * Scripting or automation experience using Python, PowerShell, or Bash; AI-assisted development acceptable provided the candidate can explain, validate , test, and maintain the code. * Practical use of AI tooling for securit y - such as Claude, GitHub Copilot, or OpenAI Codex - to accelerate tooling development, detection drafting, and a nalysi s workflows. * Experience with at least one cloud platform (AWS, Azure, GCP, or OCI), including cloud logging, identity, and security monitoring. * Solid understanding of identity security, including MFA, conditional access, privileged access, token abuse, and identity-based attacks. * Strong communication skills with the ability to explain complex security issues to technical and non-technical audiences. * Independent, self-starter, analytical, evidence-driven work style with strong attention to detail. Preferred Qualifications * Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field. * Experience with threat intelligence, malware triage, digital forensics, or reverse engineering. * Experience with vulnerability management or compliance-driven SecOps (SOC 2, ISO 27001, PCI DSS, or HIPAA). * Familiarity with detection-as-code, Git-based workflows, CI/CD pipelines, and code review practices. * Relevant certifications such as GIAC (GCFA, GCIH, GCFR, GCLD, GDAT, or GEIR), OffSec (OSIR, OSTH, OSCP, or OSAI), AWS Security Specialty, Google Professional Cloud Security Engineer, Microsoft SC-200, or CompTIA CASP+. * Equivalent combination of education, training, and relevant professional experience accepted in lieu of a formal degree. ## Description Vertex Inc. is looking for a Security Response Engineer role to strengthen our security monitoring, incident response, detection engineering, and SecOps automation capabilities. This role is ideal for a hands-on security practitioner who has a passion for investigating threats, responding to incidents, improving security tooling, and building operational solutions that help security teams work faster and more effectively. Given the 24/7/365 nature of the security operations function, the Security Response Engineer participates in a rotating shift schedule designed to provide continuous security analysis and incident response coverage. Within the coverage, this will require working nights, weekends, holidays, and extended hours based on the assigned coverage and operational needs. Responsibilities * Monitor, triage, investigate, and respond to security alerts across endpoint, identity, network, cloud, SaaS, and application environments. * Lead end-to-end incident response - detection through containment, eradication, recovery, and post-incident improvement - including root-cause analysis and corrective action tracking. * Build, tune, and maintain detection logic across SIEM, EDR, cloud, and network platforms; conduct proactive threat hunting aligned to MITRE ATT&CK. * Develop and maintain SecOps tooling, scripts, API integrations, and workflow automations to improve investigation speed and response execution. * Apply AI responsibly in SecOps workflows, with the ability to explain, validate , test, and maintain all AI-assisted outputs. * Collaborate cross-functionally to close telemetry gaps, improve detection coverage, and translate incident findings into lasting security improvements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Why Git Still Matters](https://www.wearedevelopers.com/videos/100288-why-git-still-matters) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)