Security Operations Engineer

Mastery Logistics Systems•Minneapolis, MN

About The Position

As a Security Operations Engineer on Mastery's Information Security team, you'll own detection engineering and SOAR automation for MasterMind, our Azure-native transportation management platform. You'll design and tune the analytics rules running in Microsoft Sentinel, build automated response workflows that cut manual triage time, and close visibility gaps across our AKS, endpoint, and network telemetry as we bring new log sources online. This role is ideal for a deeply technical engineer who wants to build and ship detections and automation — not manage people or run the team's day-to-day. If you'd rather spend the day in KQL and automation workflows than in a status meeting, this is built for you.

Requirements

  • 4+ years in security operations, detection engineering, or a closely related technical security role.
  • Demonstrated, hands-on experience building or substantially tuning detection rules and correlation logic in a SIEM (Sentinel strongly preferred).
  • Experience building SOAR playbooks or comparable security automation workflows.
  • Deep query language fluency: comfortable writing and debugging complex KQL (or equivalent SIEM query language) without hand-holding.
  • Scripting and API proficiency: Python or PowerShell for automation, with experience integrating tools via REST APIs.
  • Self-directed technical focus: prefers to own and ship technical work independently over managing people or processes.

Nice To Haves

  • Experience in an Azure/AKS or other Kubernetes-based cloud environment.
  • Experience supporting SOC 2 or similar compliance audits from a technical evidence standpoint.
  • Familiarity with Sentinel Logic Apps or another SOAR automation platform.

Responsibilities

  • Build real detections: design, write, and tune analytics rules and correlation logic in Microsoft Sentinel, aligned to MITRE ATT&CK.
  • Close the gaps: identify and close visibility blind spots across our infrastructure and telemetry as new log sources come online.
  • Reduce the noise: continuously validate and refine detections to cut false positives without losing real signal.
  • Automate the busywork: design and build SOAR playbooks and workflows that automate triage, enrichment, and response, freeing the analyst team to focus on real investigations.
  • Integrate the stack: build and maintain integrations across Sentinel, Defender, and other security tooling via APIs and scripting.
  • Translate intel into detections: turn emerging threats and adversary TTPs into actionable, tuned detection logic.
  • Stay hands-on: keep pace with evolving attacker techniques and Sentinel/SOAR platform capabilities through direct, ongoing technical work.

Benefits

  • Medical, Dental & Vision
  • Life & AD&D Insurance
  • Legal & Employee Assistance
  • 401(k) with 4% Match
  • Flexible PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service