What are the responsibilities and job description for the 100% Remote Role - Senior Security Operations Engineer (SOC Engineer) position at Vinsys Information Technology Inc?
Job Description
Job Description
Job Title : Senior Security Operations Engineer (SIEM / SOAR Specialist)
Terms : 100% Remote
Key Responsibilities :
- Incident Detection & Response : Lead and manage incident response activities, ensuring rapid detection, analysis, and resolution of security incidents. Provide hands-on support to the Security Operations Center (SOC) team during high-priority events and major incidents.
- SIEM & SOAR Management : Oversee and configure Rapid7 InsightIDR and InsightConnect, managing log source integration, developing custom parsers, and optimizing correlation rules and use cases to enhance detection and response capabilities.
- Threat Analysis : Perform detailed analysis of security events to identify successful intrusions, compromises, or potential threats. Distinguish between false positives and legitimate threats to minimize noise and ensure accurate detection.
- Automation & Orchestration : Use tools such as Ansible, Puppet, Python, and PowerShell to automate repetitive SOC tasks, streamline incident response processes, and improve operational efficiency.
- Configuration Management : Leverage Ansible and Puppet to standardize, configure, and manage SOC system environments across multiple platforms, ensuring consistency and reliability.
- Investigation Management : Lead investigations for incidents escalated by Level 1 analysts, ensuring thorough documentation and resolution of findings, while maintaining clear communication with all relevant stakeholders.
- Quick Mitigation Techniques : Implement quick, interim defensive measures in response to security incidents, maintaining the security posture until permanent solutions can be applied.
- Security Enhancements : Develop and maintain playbooks in Rapid7 InsightConnect to automate and orchestrate SOC operations, ensuring smooth workflows and enhanced incident response.
- Gap Analysis & Recommendations : Conduct gap analyses within the security environment to identify vulnerabilities and recommend measures for risk mitigation, enhancing the overall security framework.
- Vulnerability Awareness : Stay current with emerging vulnerabilities, threat advisories, penetration techniques, and evolving security risks to proactively defend against new and evolving threats.
Desired Skills :