SOC Engineer - US

Inforcer•Tampa, FL
•Hybrid

About The Position

We are seeking a SOC Engineer to play a critical role in monitoring, investigating, and responding to security threats across our environment. The role has two key parts. Firstly, you will act as the front line of our security operations; reviewing alerts, identifying suspicious activity, and conducting hands‑on investigations using our SIEM, EDR, and threat intelligence tools. This is an operational role with real ownership, ideal for someone who thrives in a fast‑paced environment, enjoys digging into logs, and can bring clarity to complex behaviours across our network, endpoints, and cloud platforms. As part of this, you will take part in regular out‑of‑hours work, which is a natural component of a 24/7 security operation and compensated as overtime. Secondly, you will help strengthen our detection and response capabilities by improving playbooks, enhancing alert quality, and contributing insights that increase our overall readiness. As our environment grows, you’ll play a pivotal role in reducing noise, closing detection gaps, and ensuring incidents are handled quickly, consistently, and with high quality. Your work will directly support our ability to remain secure, resilient, and able to operate without interruption.

Requirements

  • Hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, LogRhythm).
  • Familiarity with EDR/XDR tools such as CrowdStrike, Microsoft Defender, SentinelOne, or Cortex.
  • Ability to analyze logs from servers, endpoints, firewalls, IDS/IPS, and cloud environments.
  • Understanding of common attack frameworks (MITRE ATT&CK) and threat actor behaviours.
  • Basic knowledge of network security, TCP/IP, authentication flows, and identity logs.
  • Experience responding to security incidents in a SOC or cyber operations environment.
  • Strong analytical mindset with the ability to spot patterns and anomalies.
  • Clear written communication for incident documentation and escalation.
  • Ability to stay calm and focused during high‑pressure security events.
  • Comfortable working in a fast‑paced, alert‑driven operational environment.
  • Collaborative, curious, and proactive about learning new threat vectors and tools.

Nice To Haves

  • Exposure to scripting or automation (Python, PowerShell) is a plus.
  • Relevant certifications are helpful (Security+, CySA+, GSEC, GCIA, GCIH, CEH) but not required if experience is equivalent.

Responsibilities

  • Monitor SIEM, EDR/XDR, and security tooling for real‑time alerts and suspicious activity.
  • Triage, investigate, and document security incidents following established playbooks.
  • Perform log analysis across network, endpoint, cloud, and identity systems to identify potential threats.
  • Escalate incidents as needed and collaborate with Security Engineering, IT, and Incident Response teams.
  • Support containment and remediation efforts, including isolating endpoints, collecting forensic artifacts, and validating indicators of compromise (IOCs).
  • Contribute to improving detection content by identifying gaps, false positives, and tuning opportunities.
  • Participate in threat hunting exercises and proactive investigations into anomalous behaviour.
  • Maintain accurate incident records, timelines, and post‑incident reporting.
  • Assist with onboarding and operationalizing new security tools and processes.
  • Stay current with emerging threats, attack techniques, and security best practices.

Benefits

  • Attractive salary
  • Pension contribution scheme through Nest
  • Competitive annual leave allowance
  • Flexible working hours
  • Hybrid/remote working options
  • Regular Team Socials
  • Continuous learning opportunities
  • Professional training programs
  • Career advancement paths
  • Supportive and inclusive workplace
  • Programs to recognise and reward employees for their contributions and achievements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service