SOC Engineer

Quzara LLC•Remote, US,
•$120,000 - $150,000•Remote

About The Position

Quzara is seeking a hands-on SOC Engineer to onboard customers into our managed security services and keep their security tooling and telemetry running reliably. The SOC Engineer works with customers and internal teams to integrate data sources, configure Microsoft security services, automate workflows, and resolve technical issues in federal and regulated environments.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience.
  • 5+ years in IT infrastructure, cloud, or security engineering, including 3+ years hands-on with Microsoft Azure.
  • 2+ years with Microsoft Sentinel or a comparable enterprise SIEM, including data-source onboarding.
  • Strong working knowledge of the Microsoft security stack (Sentinel, Defender XDR, Entra ID, Azure Monitor / Log Analytics) and multi-tenant delegated access (Azure Lighthouse, GDAP).
  • Hands-on experience onboarding a wide range of data sources (identity providers, endpoints, firewalls and network devices, SaaS applications, Syslog/CEF, API, and agent-based integrations) from Azure, AWS, and Google Workspace / Google Cloud.
  • Experience working across multiple SIEM platforms, such as Microsoft Sentinel, Splunk, SentinelOne, IBM QRadar, or similar.
  • Proficiency in KQL and scripting (PowerShell or Python), with solid troubleshooting skills across Windows, Linux, networking, and identity.
  • Strong written and customer-facing communication skills.
  • At least one current certification required: AZ-500 or SC-200.

Nice To Haves

  • Prior MSSP, MDR, or security consulting experience.
  • Experience supporting federal or defense-industrial-base customers, including GCC and GCC High environments.
  • Experience with EDR/XDR platforms such as CrowdStrike or SentinelOne.
  • SC-100 (Microsoft Cybersecurity Architect Expert).
  • Microsoft: AZ-104 (Azure Administrator), AZ-305 (Azure Solutions Architect Expert), SC-300 (Identity and Access Administrator), SC-401 (Information Security Administrator), MS-102 (Microsoft 365 Administrator).
  • Cloud security: AWS Certified Security – Specialty, Google Professional Cloud Security Engineer.
  • SIEM / EDR: Splunk Enterprise Security Certified Admin, IBM QRadar SIEM, SentinelOne, or CrowdStrike Falcon (CCFA) certifications, or equivalent.
  • General security: CISSP, CCSP, CompTIA Security+ or CySA+, GIAC (GCDA, GCIH, or GCED).

Responsibilities

  • Lead technical onboarding of new customers, from discovery and requirements through configuration, validation, and handoff.
  • Configure and integrate Microsoft security services, including Microsoft Sentinel, Defender XDR, and Entra ID, with customer environments.
  • Onboard and validate security telemetry from identity, endpoint, network, SaaS, and multi-cloud sources, including Azure, AWS, and Google Workspace.
  • Integrate and troubleshoot log sources across multiple SIEM platforms, including Microsoft Sentinel, Splunk, SentinelOne, and IBM QRadar.
  • Troubleshoot ingestion and integration issues across cloud, identity, network, Windows, and Linux layers.
  • Build automation and scripts that make onboarding and operations repeatable.
  • Support customers operating under federal and regulated requirements, including FedRAMP, CMMC, and NIST frameworks.
  • Produce clear technical documentation and work directly with customer stakeholders to resolve onboarding blockers.
  • Other duties as assigned
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service