Engineer, Security

11:11 Systems Inc
United States
7 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

ARM Architecture Microsoft Azure Cyber Security Digital Forensics Internet Protocol Linux System Administration Network Connections Packet Analyzer Network Protocols Kusto Query Language Security Information and Event Management Data Processing
+6 more
Scripting Mitre Att&ck Kubernetes Information Technology Security Orchestration, Automation & Response Vulnerability Analysis

Job description

You’ll also serve as an escalation point for the SOC team and play a key role in reviewing high-severity customer incidents, including participation in an on-call rotation. We’re looking for someone with a strong Security Engineering background, prior analyst experience in the telecom and/or enterprise cybersecurity industry, a knack for driving system and process efficiency, and a proactive mindset toward continuous improvement., * Support SOC Management in setting tactical and operational goals, and in developing policies and procedures for timely detection, assessment, reporting, and response to security events.

  • Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
  • Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts.
  • Provide “first responder” incident response advisory support for clients experiencing security incidents, within the scope of 11:11 Systems’ software and systems (not a Digital Forensics and Incident Response role).
  • Own the timeliness and accuracy of critical incident identification, advisement, and reporting, both internally and to customers.
  • Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs.
  • Drive implementation and continuous improvement of new technologies, capabilities, frameworks, and methodologies.
  • Develop and maintain customer-facing security stacks (SIEM, EDR, SOAR, WAF, vulnerability scanning) and architect technical improvements to existing processes.
  • Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team.
  • Advise on and help build SOC analyst training programs; provide cross-functional training as needed.
  • Stay current on emerging threats, risks, and exploits, and translate that knowledge into updated SIEM detection rulesets.
  • Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.
  • Participate in an on-call rotation for after-hours support.
  • Work in alignment with 11:11’s Code of Business Ethics and Company Values, including responsible data handling and completion of required compliance training.

Requirements

  • 5+ years in information security, including 3+ years in information technology.
  • 3+ years’ experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools (focus on Azure Sentinel, Cortex XDR, and Tenable).
  • Analyst-level experience in the telecom and/or enterprise cybersecurity industry.
  • 1+ years’ experience with Python scripting or development.
  • 1+ years’ experience with Linux administration and troubleshooting.
  • Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.
  • Experience with enterprise security architecture, detection, and response.
  • Mature understanding of industry-standard incident response practices and SOC operations.
  • Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
  • Experience with Kubernetes.
  • Experience with Palo Alto products (Cortex XDR, Panorama, next-gen firewalls).
  • Experience with ThreatX or similar WAF platforms.
  • Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
  • Working knowledge of security frameworks (ISO, NIST, CIS, etc.).
  • Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
  • Up-to-date knowledge of attacker tactics, techniques, and procedures.
  • Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work.
  • Must be a US Citizen and legally eligible to work in the US without visa sponsorship.

To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ World Congress 2026 Europe

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter ¡ World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn ¡ World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

Videos

See all

Related articles

See all