Sr. SOC Engineer

Zimperium•Dallas, TX
•Onsite

About The Position

Zimperium is seeking a Sr. SOC Engineer to take full ownership of our Google SecOps platform. This role involves architecting log ingestion, developing threat detection rules, designing AI-powered triage and response automation, integrating our CNAPP platform with security operations, and leading incident investigations. This is a hands-on engineering position where you will execute tasks directly. You will be responsible for the detection strategy, platform architecture, automation design, and the quality of incident response. You will be the go-to person for log source integration, detection rule issues, and complex incident leadership. You will drive the SOC's operational outcomes and collaborate closely with DevOps, Cloud Security, and Product Security teams. Independent operation, architectural decision-making, and sound judgment are expected.

Requirements

  • 8+ years in security operations, threat detection, or incident response.
  • At least 4 years in a SIEM/SOC engineering or detection engineering role.
  • Deep hands-on experience with at least one major SIEM platform (Splunk, ELK, Chronicle/Google SecOps, Sentinel, Sumo Logic).
  • Production experience with detection authoring and tuning.
  • Strong understanding of log types and sources (OS logs, application logs, network flow, DNS, proxy, endpoint telemetry, CNAPP/runtime security events).
  • Ability to interpret and normalize heterogeneous data.
  • Experience building or tuning threat detection rules and correlation logic.
  • Working knowledge of attack frameworks (MITRE ATT&CK) and how to operationalize them.
  • Proficiency in at least one scripting/programming language (Python, Go, Bash) sufficient to build and maintain automation.
  • Experience integrating security tools (APIs, webhooks, orchestration platforms).
  • Comfortable debugging API calls and data flow.
  • Hands-on incident investigation experience (evidence collection, root cause analysis, timeline reconstruction, scope determination).
  • Familiarity with mobile threat detection, CNAPP, or endpoint threat detection.
  • Understanding of how mobile/app security signals differ from infrastructure security.
  • Strong written and verbal communication skills.
  • Ability to explain technical findings to non-technical stakeholders.
  • Ability to brief executives on incidents and trends.
  • Proven ability to operate independently, take ownership, and make decisions with sound judgment.

Nice To Haves

  • Prior experience with Google Chronicle, Google SecOps, or similar cloud-native SIEM platforms.
  • Experience with AI/ML-based alert triage, anomaly detection, or automated incident response.
  • Experience operating in regulated or compliance-heavy environments (FedRAMP, DoD, PCI-DSS, HIPAA).
  • Hands-on experience with mobile threat detection, mobile app security, or container/Kubernetes runtime security.
  • Experience with threat modeling, vulnerability disclosure coordination, or security research.
  • Relevant certifications (GCIH, ECIH, OSINT, GIAC certifications, or vendor-specific: Google Cloud Security, AWS Security, etc.).
  • Prior DevSecOps, security engineering, or cloud security experience.
  • A background in building systems.

Responsibilities

  • Own and operate the Google SecOps platform end-to-end.
  • Architect log ingestion and data normalization.
  • Author and tune threat detection rules and correlation logic.
  • Design and implement agentic AI-powered triage and response automation.
  • Integrate the CNAPP platform with security operations workflows.
  • Lead investigative response to high-severity incidents.
  • Execute tasks related to detection strategy, platform architecture, automation design, and incident response quality.
  • Manage new log source ingestion and routing.
  • Troubleshoot detection rules.
  • Provide technical leadership during complex incidents.
  • Drive SOC operational outcomes.
  • Collaborate with DevOps, Cloud Security, and Product Security teams.
  • Operate independently, make architectural decisions, and act with sound judgment.
  • Orchestrate data flow from Zimperium's CNAPP platform into Google SecOps and other security tools.
  • Build and own integrations to coordinate threat notifications, ensure consistent severity assignment, and enable unified response across mobile and cloud/infrastructure security.
  • Own and maintain Google SecOps as the operational hub, including SOAR workflows, alert routing logic, case management, automation rules, integrations with ticketing systems (Jira), notification channels, and escalation procedures.
  • Make architectural decisions on alert flow and team workflows.
  • Lead investigations into high-severity and complex incidents.
  • Conduct root cause analysis, determine scope and impact, and coordinate containment and remediation.
  • Produce clear post-incident reports.
  • Own the investigative strategy and mentor junior analysts.
  • Write or adapt tools and scripts (Python, Go, Bash) to automate SOC workflows.
  • Integrate third-party tools and APIs into Google SecOps workflows.
  • Own the efficiency and scale of the SOC's technical operations.
  • Define, instrument, and own SOC KPIs (detection latency, MTTR, investigation duration, false positive rate, automation coverage).
  • Build dashboards and reports for leadership.
  • Serve as incident commander or key investigator for high-priority events.
  • Drive incidents to root cause.
  • Generate evidence and documentation for security audits (ISO 27001, FedRAMP).
  • Translate technical findings into auditor-readable format.

Benefits

  • Equal Opportunity employer
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service