Senior Detection & Platform Engineer - SOC / Security Automation

Tixy Services LLC
Dallas, TX, United States
10 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Automation of Tests Microsoft Azure Cloud Computing Cloud Computing Security Code Review Cyber Security Continuous Integration DevOps Github
+32 more
Intrusion Detection and Prevention JSON Python (Programming Language) Runbook Security Software Security Information and Event Management Systems Integration Scripting Google Cloud Data Ingestion Microsoft Power Automate Delivery Pipeline Large Language Models Mitre Att&ck Software Troubleshooting QRadar Generative AI Cyber Threat Analysis Gitlab Git Cybercrime Microsoft Sentinel Enterprise Integration Cortex XSOAR Platform Restful APIs Splunk Webhooks SentinelOne Expertise Software Version Control Api Management Security Orchestration, Automation & Response Programming Languages

Job description

This is not a traditional SOC Analyst role. The ideal candidate will have a strong software-engineering mindset and experience building scalable solutions that improve the effectiveness and efficiency of security operations., The engineer will be responsible for developing and maintaining Detection-as-Code (DaC) pipelines, SIEM/SOAR integrations, security automation, detection content, API integrations, and AI-assisted SOC capabilities. The role will work closely with SOC Analysts, Threat Hunters, Detection Engineers, Threat Intelligence teams, Infrastructure Engineers, and Security Leadership., * Establish detection development standards, automated testing, code review, and deployment processes.

  • Develop and tune high-fidelity detections across:
  • Endpoint/EDR telemetry
  • Cloud security telemetry
  • Network telemetry
  • Email security telemetry
  • DLP telemetry
  • Reduce false positives while improving detection coverage and alert fidelity.
  • Maintain detection logic, metadata, documentation, ownership, and lifecycle management.
  • Translate threat intelligence and SOC analyst requirements into production-ready detection content.
  • Apply detection engineering methodologies aligned with MITRE ATT&CK and enterprise security requirements., * Develop and maintain SIEM queries, correlation rules, alerts, dashboards, and detection content.
  • Build and maintain SOAR playbooks for investigation, enrichment, containment, and response.
  • Develop integrations between SIEM, SOAR, EDR, identity, cloud, email, ticketing, and threat intelligence platforms.
  • Troubleshoot security data ingestion, platform integrations, automation failures, and detection deployment issues.
  • Improve the reliability, scalability, and performance of security operations platforms., * Identify repetitive SOC processes and develop automation to reduce manual analyst effort.
  • Develop reusable Python scripts, APIs, workflows, and automation components.
  • Integrate security platforms and services using REST APIs, JSON, and webhooks.
  • Automate alert enrichment using threat intelligence, asset information, identity data, and other contextual sources.
  • Improve investigation efficiency, response times, consistency, and overall SOC productivity.

AI-Assisted SOC Engineering

  • Identify opportunities to leverage Generative AI, LLMs, and AI agents within security operations.
  • Support AI-driven alert investigation, triage, enrichment, summarization, and detection development.
  • Integrate AI capabilities with existing SIEM, SOAR, and SOC workflows.
  • Establish appropriate validation, governance, and controls for AI-assisted security outcomes.

Platform Engineering & Operations

  • Monitor and optimize the performance, reliability, scalability, and availability of security platforms.
  • Troubleshoot production issues and participate in incident resolution.
  • Support platform upgrades, integrations, configuration changes, and operational improvements.
  • Develop and maintain technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Collaborate with SOC, Threat Hunting, Threat Intelligence, Detection Engineering, Infrastructure, and Security Leadership teams.

Requirements

  • 5+ years of experience in cybersecurity, SOC engineering, detection engineering, security automation, or related fields.
  • Hands-on experience with Detection-as-Code or automated security detection deployment.
  • Strong experience with SIEM and SOAR platforms and SOC operational workflows.
  • Experience developing and tuning security detections across endpoint, cloud, network, email, or DLP telemetry.
  • Strong experience with Python or similar scripting/programming languages.
  • Hands-on experience with security automation, SOAR playbooks, REST APIs, and platform integrations.
  • Experience with Git, CI/CD, version control, automated testing, and deployment pipelines.
  • Strong understanding of security events, logs, telemetry, detection logic, alerting, and incident response.
  • Experience integrating multiple security platforms through REST APIs and webhooks.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Ability to work independently in a fast-paced engineering environment., * Experience with Sigma, YARA, or other detection/content-as-code frameworks.
  • Experience with Splunk, Microsoft Sentinel, IBM QRadar, Elastic, or similar SIEM platforms.
  • Experience with Cortex XSOAR, Splunk SOAR, Microsoft Sentinel/Logic Apps, or similar SOAR platforms.
  • Experience with CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar EDR platforms.
  • Experience with security telemetry from AWS, Azure, and/or Google Cloud Platform.
  • Experience with GitHub, GitLab, Azure DevOps, or similar DevOps platforms.
  • Experience with threat intelligence platforms and automated enrichment.
  • Experience with Generative AI, LLMs, AI agents, or AI-assisted SOC operations.
  • Strong understanding of MITRE ATT&CK and modern detection engineering methodologies.
  • Experience working in a large-scale enterprise SOC environment.

Technical Skills

Detection Engineering: Detection-as-Code, Sigma, YARA, Detection Logic, Correlation Rules, MITRE ATT&CK

SIEM: Splunk, Microsoft Sentinel, QRadar, Elastic, or equivalent

SOAR: Cortex XSOAR, Splunk SOAR, Sentinel/Logic Apps, or equivalent

Endpoint Security: CrowdStrike, Microsoft Defender, SentinelOne, or equivalent EDR

Automation & Development: Python, REST APIs, JSON, Webhooks, Scripting

DevOps: Git, GitHub/GitLab, CI/CD, Automated Testing

Cloud Security: AWS, Azure, Google Cloud Platform

AI: Generative AI, LLMs, AI-Assisted Investigation, AI Agents, Automated Triage

Security Frameworks: MITRE ATT&CK, Threat Detection Lifecycle, Incident Response

Top 3 Required Skills

  1. Detection-as-Code + CI/CD Detection Engineering
  2. SIEM/SOAR Engineering + Security Automation
  3. Python + REST API Integrations + SOC Detection Engineering

Key Competencies

  • Strong security engineering and automation mindset
  • Detection engineering and content development
  • SIEM/SOAR platform engineering
  • Security automation and API integration
  • Detection quality and false-positive reduction
  • Threat detection and incident response
  • AI-assisted security operations
  • Production troubleshooting and platform reliability
  • Strong communication and technical documentation
  • Ability to work independently and collaborate across security teams

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all