Senior Security Operations Engineer
Dispel LLC
Location: Remote (US-based)
About Dispel:
Dispel is the fastest-growing cybersecurity company recognized in the 2025 Cybersecurity Excellence Awards. We deliver zero trust secure remote access and real-time data streaming for operational technology (OT) and industrial control systems (ICS). Our patented Moving Target Defense technology — referenced in NIST 800-172 — protects critical infrastructure for utilities serving 54 million+ people, manufacturers producing over 50% of US baby formula, and major defense contracts including a $950M IDIQ with the US Air Force.
Why This Role Exists:
Dispel is pursuing FedRAMP High authorization while simultaneously operating a commercial security program. We have a functioning SOC built on Google SecOps (Chronicle) and SentinelOne, but we need a senior IC who can take it from "stood up" to "operationally mature." You'll own the log ingestion pipeline end-to-end and drive material expansion of coverage across federal and commercial environments, including AWS, Azure, and Entra ID.
This person will be the day-to-day technical owner of SOC operations, responsible for closing coverage gaps, building detections, maturing incident response, and providing senior technical direction to the existing SOC analyst. This is a hands-on-keyboard role with leadership expectations — you will not formally manage people, but you will set priorities, review deliverables, and drive execution across the SOC function.
Requirements
Key Responsibilities:
SIEM/SOAR Operations (Google SecOps)
- Own the log ingestion pipeline end-to-end: identify gaps, build feeds, validate parsing, maintain coverage dashboards
- Close the federal logging gap and stand up commercial logging across AWS, Azure, Entra ID, and SaaS
- Activate and configure SecOps SOAR capabilities including Domain-Wide Delegation, marketplace integrations, and bidirectional response actions
- Build and maintain SOAR playbooks for major incident types such as phishing, malware, account compromise, lateral movement, and cloud-specific threats
- Develop and maintain operational dashboards for SOC metrics, alert volumes, MTTA/MTTR, and coverage status
- Manage Google SecOps RBAC
Detection Engineering
- Build and deploy production detection rules mapped to MITRE ATT&CK within the first year
- Develop custom parsers for AWS-native security services including GuardDuty, Security Hub, Inspector, WAF, CloudTrail, and VPC Flow Logs
- Establish a detection lifecycle including proposal, testing, deployment, tuning, and retirement
- Conduct quarterly detection quality reviews to measure false positive rates, coverage gaps, and rule health
- Develop alert threshold optimization to reduce noise and analyst fatigue
Endpoint Detection and Response (SentinelOne)
- Drive SentinelOne deployment across Azure VMs in commercial environments and all federal endpoints
- Configure and operationalize Cloud Funnel for log export into Google SecOps
- Build correlation rules between EDR alerts and SIEM detections
- Manage SentinelOne RBAC groups and policy configuration
- Coordinate with IT on agent deployment, health monitoring, and version management
Incident Response
- Serve as senior escalation point for SOC incidents, ensuring investigations are thorough and reports include root cause, remediation actions, credential rotation plans, and follow-up timelines
- Improve MTTA and MTTR through process optimization, better tooling, and analyst development
- Lead quarterly tabletop exercises and after-action reviews
- Maintain and improve incident response runbooks for all major incident categories
- Integrate incident response workflows with Jira Service Management for tracking and escalation
Vulnerability Management
- Operationalize monthly scanning cadence across all environments using tools such as Nessus, AWS Inspector, and Azure Defender
- Define and enforce remediation SLAs by severity: Critical within 72 hours, High within 7 days, Medium within 30 days
- Build consolidated vulnerability dashboards in Google SecOps
- Track SLA compliance and report metrics to the CISO
- Coordinate remediation with engineering and infrastructure teams
MSSP Oversight
- Serve as primary technical interface with MSSP partner for 24/7 SOC coverage
- Define and hold the MSSP accountable to SLAs, alert quality, and escalation procedures
- Review MSSP deliverables such as dashboards, reports, and playbooks for quality and completeness
- Manage the transition from the previous MSSP and ensure no coverage gaps
SOC Team Technical Leadership
- Provide day-to-day technical direction to SOC analysts by setting priorities, assigning tasks, and reviewing work products
- Ensure incident response reports, playbooks, and dashboards meet quality standards before delivery to leadership or external stakeholders
- Drive OKR execution for SOC-related objectives including logging coverage, detection counts, incident response metrics, and vulnerability SLA compliance
- Identify skill gaps and development opportunities for junior analysts
- Establish and enforce SOC processes that are documented, repeatable, and auditable
Required Qualifications:
- 6+ years of experience in security operations, detection engineering, or SIEM/SOAR engineering
- Hands-on experience with Google SecOps (Chronicle) or equivalent enterprise SIEM such as Splunk, Sentinel, or QRadar, with Chronicle strongly preferred
- Production experience with SentinelOne, CrowdStrike, or a comparable EDR platform
- Deep knowledge of AWS security services including GuardDuty, Security Hub, Inspector, CloudTrail, WAF, and Config
- Experience building detection rules mapped to the MITRE ATT&CK framework
- SOAR playbook development and automation experience
- Demonstrated ability to lead without formal authority by setting direction for peers or junior analysts
- Strong incident response skills with experience writing complete reports for executive and external audiences
- Understanding of NIST 800-53 controls, particularly Audit, System Integrity, and Incident Response families
- Excellent written communication skills
Preferred Qualifications:
- Experience with Google SecOps (Chronicle), SentinelOne, or similar SIEM/SOAR platforms; certifications are a plus
- Experience working in a FedRAMP High environment such as AWS GovCloud
- Azure security experience including Defender for Cloud, Entra ID, Log Analytics, and Event Hubs
- Experience managing MSSP relationships and enforcing SLAs
- Background in OT/ICS security monitoring
- Experience with vulnerability management tools such as Nessus, Inspector, or Defender
- Previous experience in a startup or high-growth environment building SOC capabilities from early stages
Certifications (Preferred, not required):
- GCIA, GCIH, GSOM, or other GIAC blue team certifications
- Google Chronicle or SecOps certifications
- AWS Security Specialty
- CISSP or CISM
- Detection engineering certifications such as SANS SEC555 or SEC511
Benefits
What We Offer:
- 136K-155K base + equity and performance bonus eligible, depending on experience and location
- Full medical, vision, and dental insurance
- Generous PTO
- Remote-first culture with flexible hours
- Opportunity to protect critical infrastructure at scale
- Work with patented, cutting-edge security technology
- Direct ownership of SOC maturation
- Collaborative team with military, federal, and private sector expertise
Security Clearance
- Due to federal customer and FedRAMP requirements, this role requires US Person status (citizen or permanent resident) under ITAR/EAR regulations.
- Ability to obtain and maintain a security clearance preferred
Dispel is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We are committed to building a diverse team and encourage applicants from all backgrounds to apply.
- Who are we?Cohere is the leading security-first enterprise AI company. We build cutting... .... Cohere is a team of researchers, engineers, designers, and more, who are all... ...Seoul, Germany and Paris. Join us!As a Senior Security Operations Engineer you will:Serve as trusted advisor...SeniorFull timeWork at officeLocal areaRemote workHome officeFlexible hours
$192k - $240k
...founders and finance teams to accelerate operations, gain real-time visibility, and control... ...support you need to grow your career.Engineering at BrexEngineering at Brex is about building... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy...SeniorWork at officeRemote workWork from home$148.5k - $237.6k
...real change. Constantly grow as you work hard for a mission that matters at a company where you matter.Your Impact As a Senior Security Operations Engineer II, you will play a key role in building secure, reliable, and developer-friendly infrastructure that enables teams...SeniorWork experience placementWork at officeRemote work$143.91k
Agency: Health Resources and Services AdministrationDepartment: Department of Health and Human ServicesSub agency: Division of Cyber Security to Office of the Chief Information Office (OCIO)Salary: Starting at $143,913 Per year (GS 14)Dates: Open 08/07/2026 to 08/17/2026...SeniorWork at office- ...fighting fires. You'll partner closely with Engineering, IT, Legal, and Business leaders to... ...incidents, and continuously raise the security bar across the company. What will you... ...exercises, runbooks, metrics, and operational reviews. • Manage security tooling configuration...Senior
- ...Job Description Job Description **CONTINGENT UPON CONTRACT AWARD**Overview: Job Title: Security Operations Engineer – Senior Location : Washington, DC (Due to the nature of the work and contract requirements, U.S. Citizenship is required. ) Description:...SeniorContract work
- ...priority goals faster. And because Tines is secure and private by design, it's popular with security, IT, engineering, finance, and other security-focused teams... ...on our journey. We are looking for a Senior Security Operations Engineer passionate about security and automation...SeniorRemote work
$130k - $150k
...oversees and manages all aspects of computer operations, including network systems administration, network security, helpdesk support and overall... ...We are seeking an experienced Senior Security Operations Engineer to work with the team in the Information...SeniorLocal areaAfternoon shift- ...Senior Security Operations Engineer Home based - Worldwide The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center...SeniorLocal areaRemote workWork from homeWorldwide
- ...Senior Security Operations Engineer At MNTN, we put our people first, full stop. This allows our company culture to be defined by our team members and their shared values, like trust, ambition, quality, radical honesty, and compassionate leadership. It's why we all...SeniorLive inRemote work
- ...monitoring and analyzing our organization's security infrastructure, detecting and... ...internal technology teams-including Cloud Engineering, Network Security, IAM, DevOps, and Governance... ...the continuous maturation of the SOC's operational processes. Participate in tabletop...SeniorFull timeWork at officeRemote workFlexible hours
- ...Description Job Description Irvine, CA Operations – IT / Full Time / On-Site Who... ...the Job Field AI is looking for a senior hands-on IT infrastructure engineer to own the systems that keep a robotics engineering organization secure and productive: macOS/Linux...SeniorFull timeWork experience placementWork at office
$133k - $209k
...Ventures, General Catalyst, and Founders Fund, Sword is defining a new standard for healthcare. Role As a Senior Security Engineer (Security Operations) at Sword, you will be at the forefront of safeguarding our cloud infrastructure and applications. Your...SeniorFull timeRemote workFlexible hours- Senior Security Operations Center Engineer Contract Job Title: Senior Security Operations Center Engineer Client: Telecommunication Location: Dallas, TX, USA Rate: Market Rate Job Scope: Manages / administers the company's day-to-day information security infrastructure...SeniorContract work
$112.5k - $150k
Senior Security Operations & Incident Response Engineer Salary: $112,500-$150,000 The Engineer - Security Operations and Incident Response will be a critical function responsible for the transformation of the organization's Security Operations and Incident Response program...Senior- Senior Security Operations Engineer (Viator) AWS GCP Security Operations Incident Response SIEM As a Senior Security Operations Engineer at Viator, a Tripadvisor company, you will play a crucial role in advancing our security processes. Your responsibilities will span...SeniorRemote workFlexible hours
- Description Title- Security Operations Engineer Classification- IT Security - Senior/Specialist Job Status- Full-Time / Permanent WDFW Program- Directors Office - Information Technology Services Division (ITS) - Cybersecurity Unit (CSU) Duty Station- Olympia, Washington...SeniorPermanent employmentFull timeWork at officeRemote workMonday to Friday
$160k - $200k
...in every domain. Umbra’s ecosystem operates through three business units: Remote... ...are looking to add a talented Senior Cyber Threat Operations Engineer to become a key player in our vibrant... ...with crafting and executing robust security strategies, performing in-depth threat...SeniorPermanent employmentFull timeWork at officeLocal areaRemote workWorldwide$139k - $242k
...CRWV) in March 2025. Learn more at .What You’ll Do:The Security Production Engineering team at CoreWeave is responsible for building, scaling,... ...rapidly growing global footprint, enabling safe and efficient operations for enterprise and AI workloads at scale.About the Role:...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours- Washington Department of Fish and Wildlife is seeking a Security Operations Engineer to design, implement, and monitor application security across on‑premises and cloud environments in a hybrid work model. The role collaborates with incident response, architecture, and...SeniorRemote work
- ...infrastructure, and business teams to reduce operational risk, eliminate manual processes, and... ...through automation.Collaborate with engineering and business teams to align automation... ...experience.Minimum of 7 years of experience in security engineering or related cybersecurity...SeniorFull timePart timeShift workDay shift
$120k - $165k
...speed, and flexibility. What we need We are looking for a Senior Security Automation Engineer to join our Security Automation team within our... ...workflows that help Security, IT, GRC, and business teams operate more efficiently and securely — and to help build the guardrails...SeniorFull time- Senior Security Operations Platform Engineer Location: New York, NY 10004 (Hybrid) Experience: 10+ years in SOC roles (analyst/engineer/architect/consultant). Responsibilities: As Senior Security Operations Platform Engineer, you will partner with SOC leadership, engineering...SeniorShift work
$140k - $155k
...threat intelligence, monitoring, detection engineering, and response into one proactive,... ...down silos to reduce risk and strengthen security across the enterprise. The team prioritizes... ...automation opportunities and translate operational needs into technical solutionsDeploy...SeniorFull timeSecond jobLive inWorldwideFlexible hours- ...safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend... ...loss. Role Overview We are seeking an experienced Senior Cyber Threat Defense - Security Operations Engineer to join our global security team in Draper, UT....SeniorFull timeFlexible hoursNight shift
- ...Leading the design and implementation of complex automation solutions, the full-time Senior Security Automation Engineer will work remotely to architect end-to-end automation systems, define integration standards, and mentor junior engineers while enhancing security capabilities...SeniorFull timeRemote work
- ...Senior Security Automation Engineer Position Overview We are seeking a Senior Security Automation Engineer to design, build, and scale... ...on engineering role focused on reducing manual security operations, suppressing alert and ticket noise, and enabling...SeniorRemote work
- We are seeking a Senior Security Automation Engineer to design, build, and scale enterprise-grade security automation that reduces manual effort, suppresses operational noise, and accelerates cyber defense outcomes. This role focuses on hands-on automation engineering...SeniorTemporary workRemote work
$120k - $160k
...from Unsafe Mobile Apps! NowSecure is the mobile app security software company trusted by the world’s most demanding... ...Cyber . Your Opportunity: We're looking for a Senior Agentic Security Automation Engineer who thrives on technical challenges, enjoys building things...SeniorFull timeWork experience placementRemote workHome officeFlexible hoursWeekend work$190k - $228k
Foster City, CAInformation Technology and Applications - Enterprise Security /Full-time /HybridWe are seeking a Senior Information Security Engineer who views security operations through an engineering lens. In this role, you won't just stare at a pane of glass watching...SeniorFull timeTemporary workRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Operations Engineer. Be the first to apply!
- offensive security engineer United States
- entry level security engineer United States
- staff security engineer United States
- cloud security engineer United States
- electronic security engineer United States
- security support engineer United States
- IT security engineer United States
- information technology security engineer United States
- systems security engineer United States
- security engineer United States


