Summary / Objective
The Security Operations Lead Engineer is responsible for guiding the day-to-day operation of the SOC while maturing detection pipelines, hardening the environment, and leading the security scrum team. The role blends hands on engineering with team leadership, incident response, threat detection, automation, and process ownership. The ideal candidate brings strong experience with SIEM, XDR, cloud security, and Fortinet tooling while being able to run sprints, refine backlogs, and drive a predictable security roadmap.
Key Responsibilities
Threat Detection and Incident Response
- Lead detection engineering, alert tuning, log pipeline improvements, and security content development
- Own incident response workflow including triage, investigation, containment, remediation, and retrospective reviews
- Manage SIEM dashboards, queries, correlation rules, and parsing logic
- Drive continuous improvement using real incidents as inputs for detection upgrades
Security Team Leadership and Scrum Execution
Serve as scrum master for the security team and maintain sprint cadenceLead daily standups, backlog refinement, sprint planning, and sprint reviewsPartner with IT, engineering, and compliance to align the security roadmap with organizational prioritiesMentor junior analysts and create growth paths within the SOCSecurity Engineering and Automation
Build and maintain automation in PowerShell or Python to reduce manual response workIntegrate security tools with internal systems to streamline alerting, enrichment, and responseImprove asset visibility, identity protections, endpoint controls, and zero trust policiesMaintain security baselines for servers, endpoints, network devices, and cloud workloadsFortinet and Infrastructure Security
Operate and tune FortiGate, FortiAnalyzer, FortiNAC, and FortiClient EMS for XDR and ZTNAManage firewall policies, segmentation, intrusion prevention, and VPN accessExpand monitoring through log forwarding, event correlation, and data retention planningWork with network and systems teams to validate architecture, resilience, and complianceCloud Security
Strengthen Azure identity, conditional access, network controls, workload protections, and audit pipelinesTune Azure Monitor, Sentinel, and Log Analytics for detection and responseImprove identity hygiene including MFA posture, privileged access, service principals, and workload identitiesDocumentation & Collaboration
Maintain runbooks, playbooks, detection notes, incident templates, and SOPs in version controlClearly document detection logic, expected behavior, and tuning criteriaEngage in cross functional reviews with IT, DevOps, compliance, and leadershipQualifications
Bachelor’s degree in cybersecurity, information systems, or related field, or equivalent experienceThree to seven years in SOC, incident response, or security engineering rolesHands on experience with SIEM platforms, XDR tooling, and log managementExperience tuning alerts, writing detections, and performing investigationsWorking knowledge of Azure identity and cloud security controlsFamiliarity with Fortinet platforms such as FortiGate, FortiAnalyzer, EMS, and ZTNAAbility to run scrum ceremonies with consistent cadenceStrong written and verbal communication skillsMust be available for full-time on-site workScripting experience in PowerShell or Python is a plusKnowledge of MITRE ATT&CK and threat hunting is a plusFCP Security Operations, AZ500 Security Engineer Associate, or GCIH certifications is a plusWhat We Offer
Exclusive Team Member Travel DiscountsAffordable Medical Insurance100% Employer Paid Dental and Vision InsuranceHSA with Company Contribution401(k)Basic and Voluntary Life & AD&DPet BenefitsFree ParkingAmazing Culture!ONE is an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate based on race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law. We’re looking for team members who thrive in a collaborative, in-person environment and want to grow their career alongside passionate technologists.