FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior SOC Engineer
SANS Institute. Design the architecture of the agentic SOC .
Posted 9/24/2026full-timeRemote • Maryland • United StatesSenior💰 $155,000 - $205,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security operations and detection engineering, with a strong focus on designing and implementing end-to-end security pipelines, managing detection lifecycles, and ensuring compliance. Proficient in leveraging cloud security practices and integrating various security tools to enhance operational efficiency.
Highest-signal resume keywords
Detection EngineeringExpert-Level Command of Detection Query LanguagesExperience with EDR and SIEM PlatformsStrong Python Programming SkillsAWS Cloud Security Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Detection EngineeringAlert Triage WorkflowsDetection Query LanguagesEDR PlatformsSIEM PlatformsPython ProgrammingREST API IntegrationsCloud Security Posture AssessmentThreat ModelingIncident Response Lifecycle
Soft Skills
CuriosityOperator EmpathyComfort with AmbiguityCalibrated Skepticism
Tools & Technologies
MSSPSOAR PlatformsCloud InfrastructureIdentity PlatformsGit-Based WorkflowsJSONMarkdown
Industry Keywords
MITRE ATT&CKSecurity AutomationCompliance ActivitiesVulnerability IdentificationIncident Response
Tech Stack
Tools & technologiesAWSAzureCloudPythonSplunk
About the role
Key responsibilities & impact- Design the architecture of the agentic SOC
- Define data flows through detection and response pipelines
- Define agent structure, orchestration, human-in-the-loop checkpoints, and system evolution
- Write, tune, and maintain detections across the internal SIEM environment
- Establish a detection lifecycle of design, deploy, measure, tune, and improve
- Identify alert triage, investigation, and response work suitable for agent augmentation
- Build integrations, scripts, and playbooks across MSSP, EDR, SIEM, cloud infrastructure, and identity platforms
- Partner with AI Engineering to build and govern the agent stack
- Co-design MCP servers and tool integrations
- Contribute to prompt design, evaluation harnesses, and feedback loops
- Own audit trails and checkpoints for safe and accountable agent actions
- Monitor agent performance, investigate failures, tune behavior, and incorporate real-world outcomes
- Own vulnerability identification, prioritization, and remediation tracking
- Assess and improve AWS and Azure cloud security posture
- Review IAM policies, harden configurations, implement cloud-native detection, and monitor posture
- Partner on identity architecture, access reviews, privilege management, and authentication standards
- Conduct code reviews, threat models, and security assessments for internal applications and integrations
- Evaluate technologies, integrations, and infrastructure changes for security risk
- Provide pragmatic, risk-based security guidance
- Support compliance activities, evidence collection, and audit engagements
- Respond to security incidents
- Perform other related duties as assigned
Requirements
What you’ll need- 7+ years in security operations, detection engineering, or security automation
- First-hand experience with alert triage workflows, escalation paths, investigation patterns, and incident response lifecycle
- Detection engineering experience, including writing and tuning detections, measuring efficacy, and managing false positives
- Expert-level command of at least one detection query language: KQL, SPL, Lucene, Sigma, or equivalent
- MITRE ATT&CK fluency
- Hands-on experience with EDR and SIEM platforms in production environments
- Ability to design end-to-end security operations pipelines
- Systems thinking and ability to reason about data flows, dependencies, failure modes, and architectural implications
- Experience designing for scale and maintainability
- Exposure to threat modeling concepts applied to security infrastructure
- Strong Python, including production-quality code, testing, version control, and code review discipline
- Experience building integrations against REST APIs across heterogeneous security tools
- Experience with SOAR platforms, security automation frameworks, or equivalent tooling
- Git-based workflows and as-code mindset
- Working knowledge of AWS
- Curiosity about LLM-based agents and traditional automation
- Willingness to learn agent frameworks, MCP, and prompt engineering
- Comfort with JSON and Markdown
- Calibrated skepticism about over-automation
- Operator empathy
- Comfort with ambiguity
- Unrestricted authorization to work in the USA; visa sponsorship is not available
- Preferred: experience with MSSP-managed detection and response environments
- Preferred: detection-as-code experience, including CI/CD pipelines, automated testing, and content packaging
- Preferred: prior SOAR playbook experience with Tines, Torq, Cortex XSOAR, Splunk SOAR, or equivalent
- Preferred: incident response experience beyond Tier 1
- Preferred: cloud detection and response experience
- Preferred: identity-focused detection experience with Entra, Okta, Active Directory, or similar
- Preferred: hands-on LLM tooling experience
- Preferred: familiarity with agentic development workflows such as CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar
- Preferred: prompt injection and LLM adversarial thinking experience
Benefits
Comp & perks- Competitive base salary
- Bonus opportunities
- 401(k) plan with company match
- Medical, dental, and vision plans
- Company-provided short term disability
- Optional long-term disability
- Supplemental life and AD&D insurance for employees and dependents
- Voluntary accident insurance
- Identity theft protection
- Fitness and wellness programs
- Company-paid employee assistance program (EAP)
- Generous paid time off, including volunteer time
- Professional development opportunities
- SANS training opportunities
- Primarily remote work environment
- Tools and flexibility to thrive professionally and personally