Security Operations Engineer

United RentalsCharlotte, NC

About The Position

Serve as a senior technical operator in the Security Operations Center (SOC), responsible for leading response to Critical-level and complex multi-stage incidents, performing proactive threat hunting, and engineering improvements to the organizations detection and response capabilities. Act as the escalation point for SecOps Technicians on high-complexity events and take ownership of incidents that require advanced forensic analysis, cross-team coordination, or executive-level communication. This is a handson defense role focused on reducing attacker dwell time, improving detection fidelity, closing coverage gaps, and ensuring the SOC continuously matures its capabilities.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, or comparable work experience
  • 3+ years of hands-on experience in a SOC, blue team, or incident response role;
  • Strong expertise with at least two of the following: SIEM content development, EDR investigation and response, firewall and IPS policy management, email security operations, log correlation and analysis;
  • Demonstrated ability to investigate and contain complex attacks including targeted intrusions, lateral movement campaigns, and credential abuse chains;
  • Strong understanding of adversary behaviors and techniques, with the ability to map detections and investigations to structured threat models;
  • Ability to write clear incident timelines, investigative findings, and executive-facing narratives;
  • Experience prioritizing detection investments based on the value and persistence of threat indicators;
  • Advanced organizational skills, ability to successfully manage multiple tasks/incidents simultaneously;
  • CySA+, GCIH, GCIA, GSOM, Cisco Cyber Professional, or equivalent technical certifications;
  • Experience with Splunk (including ES/SOAR), Trend Micro, Cisco security platforms, or similar enterprise tools;
  • Familiarity with scripting (Python, PowerShell) for automation, data enrichment, or log analysis;
  • Experience contributing to maturity assessments or improving programs in a SOC environment;
  • Knowledge of packet capture and network traffic analysis techniques;

Nice To Haves

  • ITIL Incident Management certification preferred

Responsibilities

  • Lead investigation and containment of Critical-level and complex multi-stage security incidents across the full lifecycle, from preparation through lessons learned, ensuring incidents are scoped, contained, eradicated, and recovered with clear handoffs at each phase;
  • Act as the escalation point for SecOps Technicians on incidents that exceed standard runbook procedures, providing guidance on investigation direction and containment strategy;
  • Perform proactive threat hunting using hypothesis-driven searches across SIEM, EDR, and network data, mapping findings to known adversary behaviors and techniques;
  • Conduct deep-dive analysis of advanced threats including targeted attacks, persistent access mechanisms, credential abuse chains, and supply chain compromise indicators;
  • Coordinate containment and recovery actions across teams during Critical incidents, including working with Infrastructure, GRC, and business stakeholders on impact assessment and communication;
  • Produce clear incident narratives for leadership and executive communication, translating technical findings into stage-based summaries suitable for non-technical audiences;
  • Lead tabletop exercises and after-action reviews, identifying detection gaps and driving remediation
  • Maintain and optimize SIEM detection rules, correlation logic, notable event configurations, threat intelligence feed integrations, and behavioral analytics content;
  • Engineer enhancements to alert response workflows through SOAR playbooks, scripting, or automation to reduce mean time to respond;
  • Integrate new log sources and data feeds into the SIEM, ensuring proper field parsing, field extraction, and baseline coverage;
  • Tune detection content to improve signal-to-noise ratio, documenting suppression logic and false positive reduction decisions;
  • Evaluate detection coverage against known adversary techniques and prioritize investment recommendations based on the value and persistence of threat indicators;
  • Monitor tool efficacy and performance across the security stack, coordination with vendors on escalations, patches, and feature requests;
  • Train and mentor SecOps Technicians on investigation methodology, incident handling techniques, and tool usage;
  • Create and maintain advanced technical playbooks, forensic procedures, and knowledge base articles;
  • Participate in a rotating on-call schedule for Critical incident response;
  • Maintain current, high-level technical skills in detection, response, and security engineering technologies the organization uses or may adopt;

Benefits

  • Paid Parental Leave
  • United Compassion Fund
  • Employee Discount Program
  • Career Development & Promotional Opportunities
  • Additional Vacation Buy Up Program (US Only)
  • Early Wage Access through Payactiv (US Hourly Only)
  • Paid Sick Leave
  • An inclusive and welcoming culture
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service