- Company Name
- CAPTRUST
- Job Title
- Security Operations Engineer II
- Job Description
-
**Job Title**
Security Operations Engineer II
**Role Summary**
Mid‑level SOC professional (3‑5 years experience) responsible for monitoring, analyzing, and responding to security events across the organization. Owns telecom and enterprise collaboration platform security, drives threat detection, vulnerability management, and process improvements while mentoring junior staff.
**Expectations**
- Deliver timely threat detection and incident response to maintain a secure posture.
- Manage and enhance security tooling (SIEM, firewalls, IDS/IPS, endpoint solutions).
- Provide expert support for telecom and collaboration platforms.
- Drive continuous improvement of SOC processes and playbooks.
- Collaborate cross‑functionally and provide security guidance to teams.
**Key Responsibilities**
- Monitor SIEM and other security tools, correlate alerts, and perform triage.
- Determine severity, recommend containment actions, and escalations.
- Lead investigations of moderate to complex incidents, document evidence, and participate in containment, eradication, and recovery.
- Conduct root‑cause analysis and post‑incident reviews.
- Monitor, configure, and troubleshoot network security devices (firewalls, switches, routers).
- Administer and secure telecom systems and enterprise collaboration platforms, enforcing access policies and monitoring.
- Integrate threat‑intelligence feeds; proactively hunt for IOCs.
- Analyze vulnerability scan results, assess risk, and coordinate remediation with owners.
- Create and maintain dashboards and reports for metrics.
- Mentor and train junior SOC engineers and end users on secure practices.
**Required Skills**
- Proficiency with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, etc.).
- Strong knowledge of network protocols, routing, and switching.
- Hands‑on experience with firewalls, IDS/IPS, and EDR solutions.
- Familiarity with telecom protocols and enterprise collaboration technologies.
- Solid understanding of incident‑response processes and playbooks.
- Ability to script/automate using Python, PowerShell, or Bash.
- Excellent analytical, troubleshooting, and communication abilities.
**Required Education & Certifications**
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience).
- 3–5 years experience in SOC operations, incident response, or network/security engineering.
- Experience supporting telecom and/or collaboration platforms.