Security Operations Engineer (Incident Response)

ProCircularNorth Liberty, IA
Onsite

About The Position

This position serves as a senior technical authority for response operations on the most critical and complex events, spanning both advanced (Tier III) security operations and incident response engineering. On the operations side, this role leads immediate containment, investigation, and management of remediation actions for critical incidents, acting as the primary escalation point for Tier I and Tier II analysts and driving the most difficult investigations through to resolution. It also turns the knowledge gained throughout each response into stronger defenses, developing and tuning threat detection content across tools to identify anomalous, suspicious, and malicious behavior within security data lake architectures. On the engineering side, this person works with a team to develop and maintain automated workflows that orchestrate incident response actions and optimize security operations for our clients across all phases of the incident response lifecycle. The role requires deep, cross-product expertise and close collaboration with SOC leadership, service delivery, and clients to provide ongoing communication of status and timely, decisive response to tickets and events.

Requirements

  • Prior SOC experience with a focus on detection content development (Splunk, AlienVault, ELK, or similar).
  • Strong hands-on experience in threat hunting, incident response, digital forensics, security analysis, and security engineering.
  • Strong incident-handling skills across all IR phases of preparation, identification, containment, eradication, recovery, and lessons learned.
  • Working knowledge of SOC and detection tooling: EDR, SOAR, SIEM, XDR, network analytics, and intrusion detection.
  • Knowledge of core security devices such as firewalls, network- and host-based IDS/IPS, WAF, proxy, AV, and operating system logs, including firewall rule and policy fundamentals.
  • Ability to interpret IOCs and a strong understanding of various log formats and source data for security analysis.
  • Experience writing suppression and detection rules and developing and maintaining content and reporting.
  • Proficiency in one or more programming/scripting languages such as Python, PowerShell, and Bash.
  • Experience with Windows and Linux operating systems.
  • Experience with network technologies, security and network monitoring tools, packet-capture analysis, and custom intrusion-signature development.
  • Deep understanding of networking concepts and a broad range of cyber-attacks.
  • Thorough understanding of the latest security principles, techniques, and protocols.
  • Experience with internal and client ticketing and knowledgebase systems for incident and problem tracking (e.g., Jira, Confluence).
  • Ability to drive process improvements and identify gaps.
  • Strong written and oral communication, able to facilitate technical and non-technical conversations and communicate positively with clients, including via phone.
  • Natural curiosity to find root cause, and the ability to remain calm under pressure.
  • Able to work effectively both independently and in a team; self-motivated, goal- and detail-oriented; flexible and adaptable; able to prioritize multiple tasks and manage time efficiently.
  • At least 3 years' experience performing SOC analysis and/or incident response, including at least 6-months of experience supporting a security platform in a content development role.

Nice To Haves

  • Prior experience with Git/GitHub and CI/CD pipelines.
  • Knowledge of Active Directory environments and Windows Active Directory domains.
  • Working knowledge of virtualization platforms such as VMware and Hyper-V.
  • Prior experience with container-based technologies such as Docker and Kubernetes.
  • Knowledge of penetration-testing methodologies.
  • Knowledge of network security architecture concepts such as topology, protocols, components, and defense-in-depth.
  • Knowledge of vulnerability information sources (alerts, advisories, errata, and bulletins).
  • Understanding of server-grade applications such as DBMS/SQL, Exchange, DNS, SMTP, IIS, Apache, SharePoint, Active Directory, identity management, vulnerability/patch management, and LDAP.
  • Broad knowledge of attack techniques and defenses such as buffer overflows, DoS, reconnaissance and scanning, session hijacking and cache poisoning, password attacks, web application attacks, and worms / bots / botnets.
  • Awareness of emerging attack vectors, including cloud computing and mobile platforms.
  • Prior consulting experience.
  • Security certifications a plus. (ex. CISSP, GCFA, GCIA, GCIH, GMON, etc.)

Responsibilities

  • Lead incident response engagements to scope work, perform forensic investigations, contain security incidents, and provide guidance on remediation.
  • Serve as the Tier III escalation point for alerts and trouble tickets escalated by Tier I and Tier II analysts that signal an incident requiring advanced review.
  • Own the most complex and critical security investigations through to resolution, determining relevancy, urgency, and root cause of escalated alerts and incidents.
  • Conduct host forensics, network forensics, log analysis, and malware triage to support incident response investigations.
  • Collect and analyze asset data (configurations, running processes, memory, etc.) from affected systems to drive investigation and containment.
  • Act as senior first responder to security event escalations via email, phone, and ticket.
  • Direct and support Tier I and Tier II analysts in the remediation of critical information security incidents.
  • Review and provide quality assurance on trouble tickets and investigative work produced by other team members.
  • Monitor advanced security alerts and incidents within established customer Service Level Agreements.
  • Craft new detection content and use cases based on threat intelligence, analyst feedback, available log data, and previous incidents.
  • Tune rules, filters, and policies for detection-related security technologies to improve accuracy and visibility.
  • Build parsers and field extractions to facilitate reliable content development within security data lake architectures.
  • Build, implement, and maintain scripts and tools that contribute to ProCircular's security operations and incident response methodologies.
  • Design, develop, and maintain security orchestration and automation workflows using industry-leading SOAR platforms.
  • Manage, monitor, and maintain assigned security platforms while following and improving established procedures.
  • Prepare detailed and accurate reports from analysis outcomes, and write documentation for tasks, procedures, and knowledgebase articles that support the understanding and efficiency of SOC services.
  • Mentor junior engineers and analysts, and practice continual self-improvement through education, training, and certification.
  • Communicate positively with clients, determine client needs, obtain clarification as required, and escalate issues and messages accordingly.
  • Complete assigned projects on time and with excellent quality.
  • Provide flexible on-call coverage, including after-hours and weekends, to support incident response efforts and 24/7/365 security operations.
  • Operate with integrity and accountability, uphold the values of ProCircular, and abide by the Company handbook.
  • Perform additional responsibilities as necessary.

Benefits

  • Occasional lifting up to 40 lbs. may be necessary from time to time.
  • Must be able to sit for long periods of time, view a computer monitor, and type frequently/constantly (up to 8 hours a day).
  • A valid driver's license is required for occasional travel.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service