Security Operations Engineer

MultiPlan
McLean, VA, United States
12 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Data Analysis Software System Penetration Testing Microsoft Azure Bash Shell Cloud Computing Security Cyber Security Linux Digital Forensics Domain Name System (DNS) Python (Programming Language)
+18 more
Networking Basics Routing PCI Data Security Standards Windows PowerShell Phishing Red Team (Cyber Security) Security Information and Event Management TCP/IP Mitre Att&ck QRadar Cyber Threat Analysis Firewalls (Computer Science) Information Technology Cybercrime Oracle Cloud Infrastructure Splunk SentinelOne Expertise Vulnerability Analysis

Job description

The Security Engineer is responsible for protecting our organization’s networks, systems, and data from evolving threats. In this role, you will design, implement, and operate various security tooling and continuously improve our detections, automation, and defensive posture. The engineer will also be an escalation point for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization’s technology environment. The engineer works closely with IT, infrastructure, cloud, and application teams to ensure security is embedded across our infrastructure and operations., Security Monitoring & Detection

  • Monitor, improve, and maintain security events and alerts across the enterprise using SIEM, EDR, and detection telemetry tools; triage and respond to potential incidents in a timely manner.
  • Develop and manage detection rules, correlation logic, and automated playbooks (SOAR) to improve response times.
  • Analyze and tune security tools to reduce false positives and improve detection fidelity.
  • Design, deploy, and maintain security infrastructure, including networking, cloud tooling, endpoint protection, and email security gateways.
  • Analyze and triage security alerts to determine legitimacy, severity, and business impact.
  • Identify and implement detections for indicators of compromise (IOCs), suspicious behavior, and emerging threats.
  • Perform continuous threat monitoring and situational awareness activities.
  • Support penetration testing and red team exercises; validate and remediate identified findings.
  • Develop and document security operating procedures, runbooks, and incident response plans.
  • Stay current on emerging threats, attacker tactics/techniques/procedures (TTPs), and industry best practices (e.g., MITRE ATT&CK). Incident Response

  • Lead or support incident response efforts, including containment, eradication, recovery, and root-cause analysis.
  • Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.
  • Execute incident response procedures, best practices, and playbooks.
  • Document findings, actions taken, and lessons learned for post mortems.
  • Escalate significant incidents according to established procedures.
  • Perform vulnerability assessments and coordinate remediation with system and application owners. Threat Hunting & Intelligence

  • Develop and refine detection use cases based on threat intelligence and incident trends.
  • Conduct threat hunting activities to proactively identify indicators of compromise and advanced persistent threats.
  • Utilize threat intelligence feeds and data analysis to enrich investigations.
  • Research emerging threats, vulnerabilities, and attack techniques. Security Operations

  • Assist with security architecture reviews for new systems, applications, and cloud deployments.
  • Collaborate with compliance teams to support audits and ensure adherence to relevant frameworks (NIST, ISO 27001, SOC 2, FedRAMP, HITRUST, PCI-DSS, etc.).
  • Provide on-call support for security incidents outside of normal business hours as needed.
  • And other duties as assigned.

Requirements

  • Bachelor’s degree in computer science, Information Security, or related field, or equivalent practical experience
  • 5+ years of experience in cybersecurity operations, security engineering, or a related role
  • Strong understanding of networking fundamentals (TCP/IP, DNS, routing, firewalls) and operating systems (Windows, Linux)
  • Hands-on experience managing SIEM platforms (e.g., Splunk, QRadar, Sentinel) and EDR/XDR tools (e.g., CrowdStrike, SentinelOne, Defender)
  • Experience with incident response methodologies and digital forensics investigations
  • Familiarity with scripting/automation (Python, PowerShell, Bash) for security tooling and response automation
  • Knowledge of common attack techniques, malware behavior, and the MITRE ATT&CK framework
  • Understanding of cloud security concepts (AWS, Azure, or Oracle OCI)
  • Strong analytical, problem-solving, and communication skills
  • Ability to work independently and manage competing priorities in a fast-paced environment Preferred Qualifications:

  • Relevant certifications such as GCIH, GCIA, GSEC, GCFA, CEH, CISSP, or OSCP
  • Experience managing SIEM, SOAR, & EDR platforms and security tools
  • Familiarity with managing detection lifecycles and tuning detections
  • Experience with cloud-native security tools (e.g. External Attack Surface Management (EASM), Continuous Threat Exposure Management (CTEM), GenAI Control Towers, Data Detection, and Secure Email Gateways (SEG))
  • Background in threat intelligence analysis
  • Prior experience in a regulated industry (finance, healthcare, government, defense)

Benefits & conditions

The salary range for this position is $130k -145k. Specific offers take into account a candidate’s education, experience and skills, as well as the candidate’s work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

About the company

At Claritev, you’ll do work that matters. Together, we’re helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you’re looking for purpose, growth, and a team that succeeds together, you’ll find it here.

What Guides Us

At Claritev, innovation, agility, and a focus on results drive our success. We embrace bold thinking, work as one team, take ownership, and strive for excellence in everything we do - creating meaningful impact for our clients, communities, and each other. As an Equal Opportunity Employer, the Company will provide equal consideration to all employees and job candidates without regard to sex, age, race, marital status, sexual orientation, religion, national origin, citizenship status, physical or mental disability, political affiliation, service in the Armed Forces of the United States, or any other characteristic protected by federal, state, or local law. Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Loading talks and stories from around this role…