Skip to content

Open nowPosted 20 hours ago

Sr. SOC Engineer

Zimperium16 open roles

Where
Dallas, Texas
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. SOC EngineerZimperium · Dallas, Texas
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Zimperium's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 20 hours ago

The posting

Zimperium® is the world leader in mobile security, purpose-built to protect the modern mobile enterprise. Trusted by leading organizations and governments, our AI-driven platform delivers real-time, on-device protection for mobile applications and devices. We help organizations stay ahead with proactive defense against evolving threats—including mobile-targeted phishing (mishing), malware, app vulnerabilities, and zero-day exploits. Our mission is to empower organizations to operate securely and confidently in today’s dynamic digital environment.

We are looking for a Sr. SOC Engineer to own and operate our Google SecOps platform end-to-end. You will architect log ingestion, author threat detection rules, design agentic AI-powered triage and response automation, integrate our CNAPP platform with security operations workflows, and lead investigative response to high-severity incidents. This is a hands-on engineering role: you will execute the work yourself, not manage others' execution. You will own the detection strategy, platform architecture, automation design, and incident response quality. You will be the person your team calls when a new log source needs to be ingested and routed, when detection rules aren't firing, or when a complex incident demands technical leadership.

You will own the outcomes and drive how the SOC operates. You will work in close collaboration with our DevOps, Cloud Security, and Product Security teams. You are expected to operate independently, make architectural decisions, and have the judgment to act without direction. Your technical and strategic decisions will drive Zimperium's security posture directly.

Location: Dallas, TX preferred

Key Responsibilities:

  • 8+ years in security operations, threat detection, or incident response, with at least 4 years in a SIEM/SOC engineering or detection engineering role.
  • Deep hands-on experience with at least one major SIEM platform (Splunk, ELK, Chronicle/Google SecOps, Sentinel, Sumo Logic). Production experience with detection authoring and tuning.
  • Strong understanding of log types and sources—OS logs, application logs, network flow, DNS, proxy, endpoint telemetry, CNAPP/runtime security events. Ability to interpret and normalize heterogeneous data.
  • Experience building or tuning threat detection rules and correlation logic. Working knowledge of attack frameworks (MITRE ATT&CK) and how to operationalize them.
  • Proficiency in at least one scripting/programming language (Python, Go, Bash) sufficient to build and maintain automation, not just modify examples.
  • Experience integrating security tools—APIs, webhooks, orchestration platforms (Zapier, Make, native SOAR). Comfortable debugging API calls and data flow.
  • Hands-on incident investigation experience—evidence collection, root cause analysis, timeline reconstruction, scope determination.
  • Familiarity with mobile threat detection, CNAPP, or endpoint threat detection. Understanding of how mobile/app security signals differ from infrastructure security.
  • Strong written and verbal communication—ability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.
  • Proven ability to operate independently, take ownership, and make decisions with sound judgment to non-technical stakeholders and brief executives on incidents and trends.
  • Proven ability to operate independently, take ownership, and make decisions with sound judgment.
  • Strong written and verbal communication—ability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.

Required Qualifications:

  • CNAPP & SecOps Integration. Orchestrate data flow from Zimperium's CNAPP platform into Google SecOps and other security tools. Build and own integrations to coordinate threat notifications, ensure consistent severity assignment, and enable unified response across mobile and cloud/infrastructure security.
  • Google SecOps Platform Engineering. Own and maintain Google SecOps as the operational hub—SOAR workflows, alert routing logic, case management, automation rules, integrations with ticketing systems (Jira), notification channels, and escalation procedures. You make architectural decisions on how alerts flow through the system and how the team works.
  • Investigative Leadership. Lead investigations into high-severity and complex incidents. Conduct root cause analysis, determine scope and impact, coordinate containment and remediation, and produce clear post-incident reports. You own the investigative strategy and mentor junior analysts on tradecraft.
  • SOC Automation & Tooling. Write or adapt tools and scripts (Python, Go, Bash) to automate SOC workflows—bulk event analysis, data enrichment, response actions, reporting. Integrate third-party tools and APIs into Google SecOps workflows. You own the efficiency and scale of the SOC's technical operations.
  • Metrics & Reporting. Define, instrument, and own SOC KPIs—detection latency, mean time to respond (MTTR), investigation duration, false positive rate, automation coverage. Build dashboards and reports for leadership. You are accountable for continuous improvement in SOC performance.
  • On-Call & Incident Response. Serve as incident commander or key investigator for high-priority events. Drive incidents to root cause, not just closure. You own the incident response quality.
  • Compliance & Audit Support. Generate evidence and documentation for security audits (ISO 27001, FedRAMP). Translate technical findings into auditor-readable format.

Preferred Qualifications:

  • Prior experience with Google Chronicle, Google SecOps, or similar cloud-native SIEM platforms.
  • Experience with AI/ML-based alert triage, anomaly detection, or automated incident response.
  • Experience operating in regulated or compliance-heavy environments—FedRAMP, DoD, PCI-DSS, HIPAA.
  • Hands-on experience with mobile threat detection, mobile app security, or container/Kubernetes runtime security.
  • Experience with threat modeling, vulnerability disclosure coordination, or security research.
  • Relevant certifications (GCIH, ECIH, OSINT, GIAC certifications, or vendor-specific: Google Cloud Security, AWS Security, etc.).
  • Prior DevSecOps, security engineering, or cloud security experience. A background in building systems shows a level of thinking we value.

Zimperium is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Zimperium's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Zimperium's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Zimperium's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.