SOC Security Engineer responsible for designing, developing, and maintaining SOC security platforms and tooling with a focus on SIEM, SOAR, and security automation; develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS and internal security platforms; build and maintain AWS security services and integrations (EC2, S3, Lambda, IAM, CloudWatch); support SIEM operations and detection engineering (log ingestion, parsing, normalization, correlation, and detection rule development); develop detection use cases and threat models; participate in SOC on-call rotation and incident response; collaborate with SOC analysts to improve security automation, detection coverage, and platform capabilities
Requirements
Hands-on Python development experience
Experience with Golang or Java is a plus
Hands-on experience with AWS (EC2, S3, Lambda, IAM, CloudWatch)
Experience developing production-quality services, automation, APIs, or internal security tools
Practical experience using SIEM platforms for security monitoring, log analysis, alert investigation
Compensation & benefits
Competitive salary and company benefits
Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)