SOC Engineer - Remote / Telecommute

CYNET SYSTEMS INC.
Cary, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 108K

Job location

Remote
Cary, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Bash
Cloud Computing Security
Computer Security
Database Queries
Identity and Access Management
Python
Network Security
Linux kernel
PCI Data Security Standards
Powershell
Kusto Query Language
Security Information and Event Management
Forensic Toolkit
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Mitre Att&ck
Information Technology
Microsoft Sentinel
Cortex XSOAR Platform
Cyber Warfare
Splunk
Security Orchestration, Automation & Response
ServiceNow

Job description

  • Lead deep-dive investigations of escalated security incidents, reconstructing attack chains and correlating multi-source telemetry.
  • Execute forensic triage of hosts, memory, disks, and logs, preserving evidence and providing comprehensive analysis for legal or regulatory needs.
  • Design and conduct hypothesis-driven and intelligence-led threat hunts using frameworks such as MITRE ATT&CK.
  • Act as incident commander for high-severity events, coordinating containment, eradication, and recovery efforts with internal teams.
  • Develop and tune SIEM/EDR/XDR detections, authoring advanced use cases that improve detection efficacy and reduce false positives.
  • Define, review, and validate SOAR (Security Orchestration, Automation, and Response) playbooks and automation workflows.
  • Integrate threat intelligence into SOC operations, contextualizing incidents and managing the IOC lifecycle.
  • Produce detailed root-cause analysis and lessons-learned reports, driving continuous improvement in detection and response processes.
  • Audit L1/L2 analyst work, provide targeted coaching, and uphold quality assurance standards across the SOC.
  • Mentor junior analysts, deliver knowledge transfer sessions, and contribute to internal training and capability building.
  • Represent the SOC in governance and post-incident review forums, presenting incident trends and improvement actions.
  • Participate in adversary emulation and purple-team exercises, translating findings into actionable detection and response enhancements.

Requirements

  • Bachelor s degree in Computer Science, Information Security, Cybersecurity, Engineering, or equivalent practical experience; Master s preferred.
  • 7 10+ years of hands-on experience in SOC/Cyber Defense operations, with at least 3 4 years at L2/L3, incident response, or threat hunting depth.
  • Expertise across the incident lifecycle: detection, triage, investigation, containment, eradication, recovery, and post-incident review.
  • Deep proficiency in SIEM technologies (e.g., Splunk, Microsoft Sentinel), EDR/XDR platforms (e.g., CrowdStrike, Microsoft Defender), and forensic tools (e.g., Volatility, KAPE, Autopsy).
  • Advanced knowledge of Windows and Linux internals, identity security (AD, Entra ID), cloud security (Azure, AWS, Google Cloud Platform), and network security telemetry.
  • Experience designing and executing threat hunts mapped to MITRE ATT&CK and related frameworks.
  • Strong scripting and data querying skills (Python, PowerShell, KQL, SPL, Bash).
  • Familiarity with security standards such as NIST 800-61, NIST CSF, ISO 27001, PCI-DSS, and HIPAA.
  • Excellent written and verbal communication skills for executive briefings, documentation, and customer engagement.
  • Availability for on-call rotation and ability to lead response during major incidents across time zones., * Preferred certifications: GIAC (GCIA, GCIH, GCFA, GCFE, GNFA, GCTI, GDAT), Microsoft SC-200 / SC-100, Splunk Certified Analyst, CrowdStrike CCFA/CCFR/CCFH, Offensive Security (OSCP/OSDA), CISSP, CISM, CCSP, EC-Council CHFI/CTIA, cloud security certifications (AZ-500, AWS Security Specialty, Google Cloud Platform Professional).
  • Experience with SOAR platforms (Cortex XSOAR or equivalent), ITSM tools (ServiceNow SecOps), and advanced threat intelligence platforms.
  • Exposure to purple teaming, adversary emulation, and regulatory-driven incident response.

Benefits & conditions

Our Benefits Include:

  • Medical, Dental, and Vision Insurance
  • 401(k) Retirement Plan
  • Health Savings Account (HSA)
  • Disability Insurance (Short-Term and Long-Term)
  • Life and AD&D Insurance
  • Paid Sick Leave (where required by applicable state or local law)
  • Supplemental Insurance Plans
  • Identity Theft Protection
  • Pet Insurance
  • Employee Wellness Programs
  • Employee Assistance Program (EAP)
  • Career Growth and Professional Development Opportunities

About the company

Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.

Apply for this position