Cyber Security Engineer II
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
We are looking for a Sr. SOC Engineer with 3-5 years of experience to serve as the senior resource for our threat detection ecosystem. You will be responsible for the end-to-end lifecycle of our security operations infrastructure, from engineering high-fidelity correlation rules in the SIEM to orchestrating automated response playbooks in SOAR. Your goal is to move the SOC beyond reactive alerting by building a proactive, intelligence-driven defense posture that can identify and neutralize sophisticated adversaries in real-time.
Key Skills for This Role
Full Job Posting
Job Summary
We are looking for a Sr. SOC Engineer with 3-5 years of experience to serve as the senior resource for our threat detection ecosystem. You will be responsible for the end-to-end lifecycle of our security operations infrastructure, from engineering high-fidelity correlation rules in the SIEM to orchestrating automated response playbooks in SOAR. Your goal is to move the SOC beyond reactive alerting by building a proactive, intelligence-driven defense posture that can identify and neutralize sophisticated adversaries in real-time.
1. Detection Engineering & Framework Alignment
Correlation Logic: Design, build, and maintain advanced detection rules within the SIEM/XDR environment that correlate disparate data sources (Identity, Network, Cloud, and Endpoint).
MITRE Integration: Map all detection capabilities to the MITRE ATT&CK Framework to identify visibility gaps and ensure comprehensive coverage against modern TTPs (Tactics, Techniques, and Procedures).
Logic Tuning: Conduct continuous "noise reduction" by fine-tuning alerting logic and suppression lists to maximize the signal-to-noise ratio for frontline analysts.
2. Security Orchestration & Lifecycle Management
SOAR Architecting: Develop and maintain automated response playbooks (SOAR) to standardize incident handling, from automated enrichment and evidence collection to one-click containment.
Tooling Ecosystem: Manage the health and integration of the SOC tech stack, ensuring seamless data ingestion from cloud providers (AWS/Azure/GCP) and SaaS applications into central monitoring hubs.
Continuous Improvement: Regularly audit log sources for "telemetry health," ensuring that critical security logs are being ingested correctly and meet compliance retention requirements.
3. Advanced Hunting & Incident Leadership
Proactive Hunting: Lead hypothesis-based threat hunting engagements, utilizing EDR and SIEM data to find "silent" lateral movement or credential harvesting that automated tools might miss.
SME Escalation: Act as the Tier 2 escalation point for high-priority security incidents, performing deep-dive forensic analysis and providing technical leadership during the containment and recovery phases.
Root Cause Analysis: Lead post-incident reviews to identify systemic weaknesses and implement automated technical controls to prevent recurrence.
Technical Experience
Experience: 3-5 years of hands-on experience in a Security Operations Center (SOC) or Security Engineering role.
SIEM/XDR Mastery: Deep technical proficiency with platforms such as Splunk ES, Microsoft Sentinel, Google Chronicle, or Palo Alto Cortex XDR .
Cloud Security: Solid understanding of monitoring cloud-native environments (log types like CloudTrail, VPC Flow Logs, and GuardDuty).
Querying & Scripting: Expert-level proficiency in query languages ( KQL, SPL, or Lucene ) and scripting languages (primarily Python or PowerShell ) for automation and data manipulation.
Soft Skills & Education
- Education: Bachelor’s degree in Cybersecurity, Computer Science, or a related technical field.
- Analytical Mindset: Ability to synthesize complex, fragmented data points into a cohesive narrative of an attack.
- Collaboration: Strong ability to document complex workflows and lead technical training sessions for junior SOC analysts.
Certifications (Highly Desired)
SOC & Detection: GIAC Certified Detection Analyst (GCDA), GIAC Certified Intrusion Analyst (GCIA). GCIH (GIAC Certified Incident Handler)
Vendor Specific: Microsoft SC-200, Splunk Core Certified Advanced Power User, or AWS Certified Security - Specialty.
About HighRadius
HighRadius is a SaaS company providing autonomous finance software for CFO offices.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at HighRadius
Associate Project Manager
Hyderabad, IND
Payroll Specialist | US/EMEA
Hyderabad, IND
Forward Deployed Architect II
Hyderabad, IND
Enterprise Account Executive
London, GBR
Enterprise Account Executive - DACH Region
, GBR
Join our Talent Community!
, USA
Account Executive - Mid-Market Net New
Houston, USA
Account Executive - Enterprise Net-New
Houston, USA