> Markdown version of [/jobs/ext/736750-soc-engineer-level-1-threat-intelligence](https://www.wearedevelopers.com/jobs/ext/736750-soc-engineer-level-1-threat-intelligence). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Engineer Level 1 - Threat Intelligence - **Company:** Rightworks Llc - **Location:** Nashua, NH, United States - **Salary:** $80,000.0 - $95,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Query Languages, Intrusion Detection and Prevention, Open Source Intelligence, Cloud Services, Kusto Query Language, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, HybridCloud, Cybercrime - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ba704d17fdfc9c2f ## About the Role Do you have experience in Threat intelligence?, Rightworks is seeking a motivated Security Operations Engineer to support detection, threat hunting, and security operations across our hybrid cloud environment. This role will focus on developing and improving detection capabilities, performing structured threat hunting, and supporting incident response activities under the guidance of senior team members. The ideal candidate will have foundational experience in cloud security and security operations, with a strong ability to analyze data, identify suspicious activity, and contribute to improving the organization's overall security posture. This role requires a detail-oriented individual who can follow structured processes, document findings clearly, and continuously develop technical skills in areas such as detection engineering, threat intelligence, and cloud security while working both independently and as part of a team. This is a hybrid work position, with 3 days per week in our Nashua, NH headquarters., * 2+ years of hands-on experience implementing technical policies and controls in a hybrid cloud environment, including but not limited to Azure. * 2+ years of experience correlating external and internal threat intelligence and enriching IoCs. * 1+ year of experience in proactive threat hunting using advanced query languages (e.g., KQL, CQL, SPL, etc.) and automation techniques. * 1+ year of experience performing external attack surface management (EASM) across hybrid environments. * Demonstrated ability to conduct a hypothesis-driven threat hunt and strong knowledge of the MITRE ATT&CK framework and common threat actor TTPs. * Cybersecurity certifications required (e.g., Microsoft AZ-500, CEH, CySA+ or equivalent). * Strong OSINT and threat research capabilities, with experience leveraging automation and scripting for enrichment. * Excellent analytical, documentation, and communication skills; ability to present findings to technical and non-technical audiences. ## Description * Develop and tune detection rules (WAF, EDR, SIEM alerts, etc.) based on known threat actor tactics, techniques, and procedures (TTPs) * Perform structured threat hunting across endpoints, identity, and cloud workloads * Conduct threat intelligence research and IOC enrichment * Support External Attack Surface Management (EASM) * Assist in the triage and incident response process and in correlating activity across multiple security tools (Defender, Sentinel, etc.) when required * Contribute to detection improvement through tuning, validation, and feedback * Document investigations, queries, and findings clearly and consistently * Assist with security tool optimization, dashboards, and reporting * Assist with monitoring of artificial intelligence (AI) products to ensure alignment with safety and security policies. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)