Security Operations Center (SOC) Cloud Engineer

Lakeview Loan Servicing
United States
7 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$165,000.0 - $175,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security HTML Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Delivery Continuous Integration DevOps
+26 more
Domain Name System (DNS) Identity and Access Management Internet Security Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Transport Layer Network Configuration and Change Management Network Protocols Windows PowerShell Cloud Services Security Information and Event Management Software Engineering TCP/IP Transmission Control Protocol (TCP) Cloud-native Network Functions (CNF) Scripting Computer Network Operations Cloud Platform System Data Ingestion HybridCloud Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Infrastructure Automation Frameworks Information Technology Splunk

Job description

The IT Security Team is looking for a seasoned professional to support a passionate, innovative, and results driven team. The Senior Security Operations Center (SOC) Cloud Engineer is responsible for monitoring, detecting, and responding to threats in AWS and Azure environments. This role focuses on integrating cloud logs into the SIEM, developing threat detections, and supporting incident response. The ideal candidate has strong technical expertise in cloud security and works closely with SOC analysts to enhance visibility and response across cloud workloads., * Collect, monitor, and analyze log sources from AWS and Azure, including CloudTrail, GuardDuty, Security Hub, Azure Activity Logs, Defender for Cloud, and other relevant telemetry sources.

  • Ensure AWS and Azure log sources are properly ingested into the SIEM (e.g., Splunk) and normalized for effective detection, alerting, and investigation.
  • Design and implement cloud threat detections for activities such as unauthorized access, privilege escalation, lateral movement, and data exfiltration in cloud environments.
  • Collaborate with SOC analysts to triage and respond to security alerts and incidents related to AWS and Azure platforms.
  • Proactively hunt for threats in AWS and Azure environments using SIEM, native cloud tools, and EDR platforms.
  • Develop, document, and automate cloud incident response procedures using SOAR platforms such as Splunk SOAR.
  • Work with infrastructure and DevOps teams to improve visibility and security posture across AWS and Azure.
  • Stay up to date on new and evolving threats and vulnerabilities targeting cloud platforms and recommend appropriate mitigations.
  • Mentor and support junior analysts on cloud detection and response techniques.

Requirements

  • 8+ years of related experience in IT and Cyber Security.
  • 3+ years of direct experience securing AWS and Azure cloud environments.
  • 5+ years of experience working in an operational security environment (e.g., SOC, NOC).
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field preferred.
  • One or more of the following certifications preferred: AWS Certified Security - Specialty, Azure Security Engineer Associate, GCIH, GCIA, GCFA.
  • Experience using SIEM platforms (preferably Splunk) for log ingestion, correlation, and threat detection in cloud environments.
  • Strong knowledge of AWS and Azure security services such as GuardDuty, Security Hub, IAM, VPC Flow Logs, Azure Activity Logs, Defender for Cloud, and Sentinel.
  • Familiarity with cloud IAM, network configurations, encryption, and resource monitoring in AWS and Azure.
  • Hands-on experience with endpoint protection platforms, IDS/IPS, and firewalls in hybrid and cloud networks.
  • Scripting skills (e.g., Python, PowerShell, Bash) for automating detections, investigations, or response actions.
  • Deep understanding of network protocols such as TCP/IP, HTTP/S, and DNS as they relate to cloud services.
  • Detail-oriented with strong analytical skills and the ability to troubleshoot complex security issues.
  • Experience with cloud forensic techniques and incident response is a strong plus
  • Exposure to container security, Infrastructure-as-Code (IaC), and CI/CD security best practices in cloud environments is a plus.

Knowledge and Skills Required:

  • Strong problem-solving and analytical skills with attention to detail.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Self-starter with strong interpersonal, written, and verbal communication skills and the ability to interact with technical and non-technical stakeholders.

Certifications

  • Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect OR Splunk Cloud Certified Admin, Splunk SOAR Certified Automation Developer preferred, Amazon Web Services (AWS), Analysis Skills, Automation, Bash Scripting, Best Practices, Cloud Architecture, Cloud Computing, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cryptography, DNS (Domain Name System), Detail Oriented, DevOps, Endpoint Security, Enterprise Architecture, Firewalls, GCFA - GIAC Certified Forensic Analyst, GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, HTTP (HyperText Transport Protocol), Hybrid Cloud, Identify Issues, Incident Response, Internet Security, Interpersonal Skills, Intrusion Detection Systems, Intrusion Prevention Systems, Mentoring, Microsoft Windows Azure, Network Configuration Management, Network Operations Center, Network Protocols, Operations Security (OPSEC), Presentation/Verbal Skills, Problem Solving Skills, Protective Services, Python Programming/Scripting Language, Scripting (Scripting Languages), Security Information and Event Management (SIEM), Security Infrastructure, Software Engineering, Splunk, TCP/IP (Transmission Control Protocol/Internet Protocol), Telemetry, Windows PowerShell, Writing Skills

Benefits & conditions

  • The salary range for this role is $165-175K depending on the individual’s experience
  • Role can be 100% fully remote depending on geographic location

Lakeview is an Equal Employment Opportunity employer. All aspects of consideration for employment and employment with the Company are governed on the basis of merit, competence, and qualifications without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, or any other category protected by federal, state, or local law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:21 min

Projecting external HTML content using default and named slots

Rowdy Rabouw Rowdy Rabouw · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all