SNOC Engineer III
Accountabilities: Drive continuous improvement across SNOC operations by identifying opportunities to strengthen monitoring, incident response, automation, workflows, and operational efficiency.
Serve as the primary escalation point for complex and high-severity incidents, leading advanced analysis and supporting containment, eradication, recovery, and root cause investigations.
Perform advanced threat analysis using SIEM, EDR, identity protection, network telemetry, and other security monitoring platforms.
Investigate complex alerts and correlated incidents across endpoint, identity, email, cloud, and network environments.
Develop and refine detection capabilities, including SIEM analytics rules, threat-hunting queries, alert enrichment logic, and automated response playbooks.
Identify potential risks, vulnerabilities, and suspicious activity and recommend appropriate remediation and long-term risk mitigation strategies.
Support the onboarding and integration of telemetry from new platforms and technologies into the monitoring environment.
Maintain and improve operational documentation, including runbooks, investigation guides, incident response procedures, and knowledge base materials.
Mentor junior SNOC engineers during investigations, troubleshooting, and incident response activities.
Collaborate with engineering, infrastructure, and client teams to implement remediation measures and improve security operations.
Ensure incidents, investigations, and operational actions are accurately documented in ticketing and case management systems.
Support compliance initiatives, audits, incident reporting, disaster recovery validation, and operational readiness exercises.
Requirements:
Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred, or equivalent professional experience.
Advanced knowledge of security operations, incident investigation, threat detection methodologies, and operational best practices.
Experience working with SIEM and monitoring platforms such as Microsoft Sentinel, Wazuh, SentinelOne, or comparable technologies.
Strong understanding of networking fundamentals, endpoint protection, identity security, and cloud environments such as Azure and AWS.
Experience with advanced log analysis, threat hunting, alert triage, and investigation across multiple telemetry sources.
Demonstrated ability to troubleshoot complex technical issues and provide leadership during high-severity operational events.
Experience improving security monitoring through detection engineering, alert tuning, automation, and analytics.
Strong written and verbal communication skills, including the ability to produce clear operational documentation and communicate effectively with clients and internal teams.
Familiarity with relevant security frameworks, compliance standards, and operational best practices.
Preferred certifications include GIAC GCIH, GCIA, or GCFA; CompTIA CySA+ or CASP+; Microsoft Certified: Azure Security Engineer Associate; AWS Certified Specialty; and Cisco CCNP or equivalent.
Benefits:
Annual salary of $105,000.
Fully remote work.
Standard business hours, first shift schedule.
Medical, dental, and vision coverage.
Life insurance.
401(k) with company match.
Paid holidays.
FSA and HSA options.
Pet insurance.
Certification, training, and professional development opportunities.
Collaborative environment focused on technical growth, mentorship, and continuous improvement.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1