SOC Engineer Level 1 - Threat Intelligence

Rightworks Llc
Nashua, NH, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$80,000.0 - $95,000.0
Working hours
Regular working hours
Job source

Tech stack

Data Analysis Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Query Languages Intrusion Detection and Prevention Open Source Intelligence Cloud Services Kusto Query Language Security Information and Event Management Mitre Att&ck
+3 more
Cyber Threat Analysis HybridCloud Cybercrime

Job description

  • Develop and tune detection rules (WAF, EDR, SIEM alerts, etc.) based on known threat actor tactics, techniques, and procedures (TTPs)
  • Perform structured threat hunting across endpoints, identity, and cloud workloads
  • Conduct threat intelligence research and IOC enrichment
  • Support External Attack Surface Management (EASM)
  • Assist in the triage and incident response process and in correlating activity across multiple security tools (Defender, Sentinel, etc.) when required
  • Contribute to detection improvement through tuning, validation, and feedback
  • Document investigations, queries, and findings clearly and consistently
  • Assist with security tool optimization, dashboards, and reporting
  • Assist with monitoring of artificial intelligence (AI) products to ensure alignment with safety and security policies.

Requirements

Do you have experience in Threat intelligence?, Rightworks is seeking a motivated Security Operations Engineer to support detection, threat hunting, and security operations across our hybrid cloud environment. This role will focus on developing and improving detection capabilities, performing structured threat hunting, and supporting incident response activities under the guidance of senior team members.

The ideal candidate will have foundational experience in cloud security and security operations, with a strong ability to analyze data, identify suspicious activity, and contribute to improving the organization’s overall security posture. This role requires a detail-oriented individual who can follow structured processes, document findings clearly, and continuously develop technical skills in areas such as detection engineering, threat intelligence, and cloud security while working both independently and as part of a team.

This is a hybrid work position, with 3 days per week in our Nashua, NH headquarters., * 2+ years of hands-on experience implementing technical policies and controls in a hybrid cloud environment, including but not limited to Azure.

  • 2+ years of experience correlating external and internal threat intelligence and enriching IoCs.
  • 1+ year of experience in proactive threat hunting using advanced query languages (e.g., KQL, CQL, SPL, etc.) and automation techniques.
  • 1+ year of experience performing external attack surface management (EASM) across hybrid environments.
  • Demonstrated ability to conduct a hypothesis-driven threat hunt and strong knowledge of the MITRE ATT&CK framework and common threat actor TTPs.
  • Cybersecurity certifications required (e.g., Microsoft AZ-500, CEH, CySA+ or equivalent).
  • Strong OSINT and threat research capabilities, with experience leveraging automation and scripting for enrichment.
  • Excellent analytical, documentation, and communication skills; ability to present findings to technical and non-technical audiences.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance, Our Compensation range for this role ranges from $80,000 to $95,000 annually, and is determined based on factors such as relevant experience, skills, and internal equity., To provide best-in-class solutions, we need a best-in-class team. We offer competitive salaries to recruit the best talent. We provide company-paid short and long-term disability insurance, life insurance and a generous 401K match. We offer highly affordable medical, dental, vision coverage, and many other valuable benefits. We offer flexible PTO, and numerous paid holidays, affording you the time to be there for what is important in your life. We encourage giving back to our communities by providing paid volunteer time off. We are proud to be an Equal Opportunity Employer!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:23 min

Mitigating social engineering and identifying technical security resources

Vandana Verma · LIVE

46 sec

Using LLMs to reverse engineer undocumented legacy code

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all