The posting
Location: Jacksonville, FL
Schedule: Monday - Friday 8-5 with On-call rotation
Summary: The senior security operations center (SOC) engineer role is a technical leader responsible for engineering, implementing and optimizing security monitoring and response capabilities across the enterprise. Leads technical initiatives to enhance detection coverage, implement automated solutions and build comprehensive security metrics and KPIs to measure operational effectiveness. Essential Responsibilities:
Be a subject matter expert for team of engineers designing use cases for monitoring and responding 24x7x365. Engineer and implement solutions to enhance the SOC’s ability to detect and respond to incidents. Lead design, implementation and maintenance of security infrastructure technology stack. Develop containment and remediation strategies and coordination across security and technical teams. Work alongside teams to engineer comprehensive controls, auditing and monitoring strategy. Automate repetitive tasks in SOAR environment with ML/AI to drive efficiencies toward more advanced work. Implement AI-assisted threat detections aligned to the MITRE ATT&CK Framework to improve operations. Build or modify AI-enhanced scripts for detection engineering, log enrichment or threat hunting. Be familiar with prompting, AI agents, copilots and MCP solutions to analyze events across data sources. Validate data pipelines with AI systems are securely managed and monitored. Partner with analysts, incident response, IT, business units and management to improve monitoring, workflow and response. Validate effective SecOps controls are implemented and maintained and adapt to threat landscape. Refine and maintain playbooks, policies, procedures and guidelines and align with industry best practices. Support monitoring and response metrics, KPIs and SLOs for security events and incidents. Engage in tabletop exercises to test, identify gaps, improve skills and enhance communication. Engineer improvements from tabletop, vulnerability and penetration testing assessments. Examine log source data across endpoints, databases, applications, identity, network, mobile and cloud. Upon request, report on the state of the SOC to cybersecurity leaders and stakeholders.
Required Minimum Experience and Education:
High School diploma or GED 7 years of SOC engineering and security administration experience.
1 year of experience using copilots or assistants to query logs, threat intelligence and/or multiple sources of data.
Preferred Experience and Education:
Bachelor's degree with major in cybersecurity, computer science, or engineering 1 year of experience supporting deployment through CI/CD pipelines. Currently hold one or more of the following certifications: GSOC, GCIH, GDAT, Microsoft Certified SecOps Analyst Associate, CISSP
Knowledge, Skills, and Abilities:
Ability to operative with integrity, trustworthiness, professionalism and character. Exceptional written and verbal communication skills across multiple levels of the organization. Skilled in SOAR, SIEM, threat intelligence, identity, sandboxes, vulnerability management and EDR/XDR. Knowledge of technical understanding of emerging cybersecurity threats and principles of incident response Skilled in Windows and Linux operating systems. Advanced knowledge of emerging cybersecurity threats and principles of incident response. Ability to create detections aligning with MITRE ATT&CK and NIST’s AI Risk Management Framework. General knowledge of ML/AI and use with SecOps processes. Technical knowledge of emerging cybersecurity threats and adversary’s use of AI. Ability to script in Python, Bash, or PowerShell. Knowledge of one or more: NIST AI RMF, NIST CSF, NIST 800-171, PCI DSS, SOX, HIPAA, GDPR, CCPA
**This job posting is not designed to cover or contain a comprehensive listing of all activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change, or new ones may be assigned at any time with or without notice.



