Security Operations Platform Engineer

First QualityHome Office (PA), MI
Remote

About The Position

The Information Security team is actively seeking a platform engineer to join our SOC operations to support the design, implementation, management, and optimization of our SIEM/SOAR platform. This role ensures effective log ingestion, threat detection, alert tuning, reporting, automation, and overall platform health to enhance the organization’s security monitoring and incident response capabilities.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • 3+ years of experience managing a SIEM platform
  • Knowledge of network protocols, firewalls, IDS/IPS, EDR, cloud security logs
  • Understanding of data normalization standards (CEF, LEEF, JSON, etc.)
  • Experience with SIEM query languages
  • Experience with scripting (Python, PowerShell, or similar) for automation
  • Working knowledge of MITRE ATT&CK, threat intelligence, and incident response processes
  • Analytical and problem-solving skills
  • Strong troubleshooting and log analysis capabilities
  • Ability to translate security requirements into technical solutions
  • Strong communication skills for technical and executive audiences
  • Ability to work both independently and collaboratively in a fast-paced SOC environment

Nice To Haves

  • 3+ years managing SOAR platform
  • Experience developing automation, and response playbooks
  • Familiarity with Azure, AWS, or GCP log configurations
  • Experience supporting compliance frameworks (NIST, ISO 27001, SOX, HIPAA, etc.)
  • Security+, CySA+, CASP+, GCIA, GCIH, CISSP or equivalent

Responsibilities

  • Configure and maintain SIEM/SOAR platform
  • Monitor platform performance, availability, and data health
  • Review and maintain upgrades, integrations, and ongoing optimization
  • Manage role/scope-based access controls and data retention policies
  • Onboard and normalize log sources (firewalls, endpoints, servers, cloud, SaaS, identity providers, etc.)
  • Build integrations via scripting for custom data onboarding utilizing APIs
  • Troubleshoot ingestion issues and ensure log integrity and completeness
  • Review and maintain parsing rules and data mappings
  • Optimize data pipelines for performance and cost efficiency
  • Develop, tune, and maintain detection rules logic, and alerting thresholds to improve fidelity and reduce false positives
  • Collaborate with SOC analysts during active investigations to provide platform support, log extraction, and forensic data retrieval
  • Vendor management and escalation support
  • Build and maintain dashboards for SOC operations, compliance, and executive reporting
  • Develop and maintain scheduled and ad-hoc reports for stakeholders
  • Develop KPIs and metrics for security posture and incident trends
  • Evaluate new log sources and security integrations
  • Recommend enhancements to improve visibility and coverage
  • Stay current on platform updates and best practices
  • Evaluate existing integrations and data to improve parsing, data normalization, and data reduction

Benefits

  • Competitive base salary and bonus opportunities
  • Paid time off (three-week minimum)
  • Medical, dental and vision starting day one
  • 401(k) with employer match
  • Paid parental leave
  • Child and family care assistance (dependent care FSA with employer match up to $2500)
  • Bundle of joy benefit (years’ worth of free diapers to all team members with a new baby)
  • Tuition assistance
  • Wellness program with savings of up to $4,000 per year on insurance premiums
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service