← All open roles
IL-2026-025SOC

SOC Engineer

Build and operate detection, response, and tooling supporting IdentityLogic's managed services and client SOC engagements. Identity-focused detection at the core: SIEM content, SOAR playbooks, and IAM telemetry integration.

What you'll do

  1. Build and tune SIEM detection content (Splunk, Sentinel, QRadar) with a focus on identity-aware detections
  2. Develop SOAR playbooks (XSOAR, Tines, Sentinel Logic Apps) for triage and response automation
  3. Triage and respond to identity-related alerts: anomalous logins, MFA bypass attempts, privilege escalation
  4. Integrate IAM platforms (SailPoint, Okta, CyberArk, Entra ID) with the SOC tooling stack for telemetry and response
  5. Run incident triage; document timelines; partner with client incident response teams
  6. Maintain on-call rotation for managed clients

What we need from you

  1. 4+ years SOC engineering or detection engineering experience
  2. Hands-on with at least one major SIEM and one SOAR platform
  3. Working knowledge of identity attack patterns and IAM telemetry sources
  4. Strong scripting (Python, PowerShell) for detection and automation
  5. Familiarity with MITRE ATT&CK and detection engineering best practices
  6. US-based with unrestricted work authorization

Bonus, not required

  • GCIA, GCFA, GCIH, or equivalent SANS certification
  • Prior detection engineering experience with identity-focused content (Kerberoasting, OAuth abuse, MFA fatigue)
  • Experience with KQL, SPL, or equivalent SIEM query languages

What you'll get

Competitive base plus utilization and on-call premium. Paid certifications and conference sponsorship.