Security Operations Engineer

United RentalsCharlotte, NC

About The Position

Serve as a senior technical operator in the Security Operations Center (SOC), responsible for leading response to Critical-level and complex multi-stage incidents, performing proactive threat hunting, and engineering improvements to the organizations detection and response capabilities. Act as the escalation point for SecOps Technicians on high-complexity events and take ownership of incidents that require advanced forensic analysis, cross-team coordination, or executive-level communication. This is a handson defense role focused on reducing attacker dwell time, improving detection fidelity, closing coverage gaps, and ensuring the SOC continuously matures its capabilities.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, or comparable work experience
  • 3+ years of hands-on experience in a SOC, blue team, or incident response role
  • Strong expertise with at least two of the following: SIEM content development, EDR investigation and response, firewall and IPS policy management, email security operations, log correlation and analysis
  • Demonstrated ability to investigate and contain complex attacks including targeted intrusions, lateral movement campaigns, and credential abuse chains
  • Strong understanding of adversary behaviors and techniques, with the ability to map detections and investigations to structured threat models
  • Ability to write clear incident timelines, investigative findings, and executive-facing narratives
  • Experience prioritizing detection investments based on the value and persistence of threat indicators
  • Advanced organizational skills, ability to successfully manage multiple tasks/incidents simultaneously
  • CySA+, GCIH, GCIA, GSOM, Cisco Cyber Professional, or equivalent technical certifications
  • Experience with Splunk (including ES/SOAR), Trend Micro, Cisco security platforms, or similar enterprise tools
  • Familiarity with scripting (Python, PowerShell) for automation, data enrichment, or log analysis
  • Experience contributing to maturity assessments or improving programs in a SOC environment
  • Knowledge of packet capture and network traffic analysis techniques

Nice To Haves

  • ITIL Incident Management certification preferred

Responsibilities

  • Lead investigation and containment of Critical-level and complex multi-stage security incidents across the full lifecycle, from preparation through lessons learned, ensuring incidents are scoped, contained, eradicated, and recovered with clear handoffs at each phase.
  • Act as the escalation point for SecOps Technicians on incidents that exceed standard runbook procedures, providing guidance on investigation direction and containment strategy.
  • Perform proactive threat hunting using hypothesis-driven searches across SIEM, EDR, and network data, mapping findings to known adversary behaviors and techniques.
  • Conduct deep-dive analysis of advanced threats including targeted attacks, persistent access mechanisms, credential abuse chains, and supply chain compromise indicators.
  • Coordinate containment and recovery actions across teams during Critical incidents, including working with Infrastructure, GRC, and business stakeholders on impact assessment and communication.
  • Produce clear incident narratives for leadership and executive communication, translating technical findings into stage-based summaries suitable for non-technical audiences.
  • Lead tabletop exercises and after-action reviews, identifying detection gaps and driving remediation.
  • Maintain and optimize SIEM detection rules, correlation logic, notable event configurations, threat intelligence feed integrations, and behavioral analytics content.
  • Engineer enhancements to alert response workflows through SOAR playbooks, scripting, or automation to reduce mean time to respond.
  • Integrate new log sources and data feeds into the SIEM, ensuring proper field parsing, field extraction, and baseline coverage.
  • Tune detection content to improve signal-to-noise ratio, documenting suppression logic and false positive reduction decisions.
  • Evaluate detection coverage against known adversary techniques and prioritize investment recommendations based on the value and persistence of threat indicators.
  • Monitor tool efficacy and performance across the security stack, coordination with vendors on escalations, patches, and feature requests.
  • Train and mentor SecOps Technicians on investigation methodology, incident handling techniques, and tool usage.
  • Create and maintain advanced technical playbooks, forensic procedures, and knowledge base articles.
  • Participate in a rotating on-call schedule for Critical incident response.
  • Maintain current, high-level technical skills in detection, response, and security engineering technologies the organization uses or may adopt.

Benefits

  • Paid Parental Leave
  • United Compassion Fund
  • Employee Discount Program
  • Career Development & Promotional Opportunities
  • Additional Vacation Buy Up Program (US Only)
  • Early Wage Access through Payactiv (US Hourly Only)
  • Paid Sick Leave
  • An inclusive and welcoming culture
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service