Security Operations Center Engineer
Coral Gables, Miami-Dade County, Florida, 33114, USA
Listed on 2026-02-05
-
IT/Tech
Cybersecurity, Security Manager, Systems Engineer, Cloud Computing
Overview
The IT Security Team is looking for a seasoned professional to support a passionate, innovative, and results‑driven team. The Security Operations Center (SOC) Engineer is responsible for managing and maintaining security tools such as Splunk SIEM and SOAR platforms, automating SOC workflows, and configuring log collection across on‑premises and cloud environments (Azure, AWS). This role collaborates closely with SOC analysts to enhance detection, response, and automation capabilities using SOAR and SIEM technologies.
The ideal candidate is skilled in scripting (Python, Power Shell), cloud security configurations, Linux administration, and integrating diverse security tools. They continuously advance SOC effectiveness by staying current on emerging threats, technologies, and best practices. This role can be remote anywhere in the country. The salary range for this role is $165,000 to $175,000, plus an annual bonus. However Lakeview considers several factors when extending an offer, including but not limited to, the roles and associated responsibilities, a candidate's work experience, education/training, location and key skills.
- Maintain and configure Splunk SIEM and SOAR infrastructure to support security operations and incident response efforts.
- Ensure accurate and reliable ingestion of security logs from on‑premises infrastructure, cloud environments (Azure, AWS), and SaaS applications into the SIEM platform.
- Develop and manage integrations between SIEM, SOAR, EDR, and other security tools to streamline alerting, enrichment, and automated response.
- Work closely with SOC analysts to identify use cases for automation and build playbooks in SOAR platforms (e.g., Splunk SOAR) to improve triage and response efficiency.
- Create and maintain detailed documentation, runbooks, and architectural diagrams for all supported security tools and data flows.
- Participate in proof‑of‑concept testing and implementation of new SOC tools, scripts, and detection technologies.
- Monitor the health, performance, and scalability of security infrastructure and recommend enhancements or fixes as needed.
- Provide mentorship and technical support to SOC analysts in areas such as scripting, tooling, and automation workflows.
- Stay current on evolving threat landscapes, detection techniques, and advances in security technologies to continuously improve SOC capabilities.
- 10+ years of experience in security engineering, security operations, or security automation roles.
- Splunk administration experience is required;
Splunk certifications such as Splunk Cloud Certified Admin, Splunk Enterprise Certified Architect, or Splunk SOAR Certified Automation Developer are preferred. - Experience with SOAR platforms is required;
Splunk SOAR (Phantom) is preferred. - Experience managing EDR platforms.
- Proficiency in scripting languages such as Python and Power Shell for automation and tool integration.
- Strong understanding of Azure and AWS logging architecture, including Azure Monitor, Activity Logs, Defender for Cloud, Guard Duty, and Cloud Trail.
- Linux administration experience with a focus on system security and monitoring.
- Familiarity with network protocols, firewall rules, and endpoint telemetry as they relate to hybrid and cloud environments.
- Experience integrating APIs across security tools for automation of enrichment, ticketing, and response workflows.
- Working knowledge of MITRE ATT&CK, detection engineering, and threat hunting techniques.
- Bachelor’s degree in Cybersecurity, Computer Science, or a related field, or equivalent work experience.
- Strong problem‑solving and analytical skills with attention to detail.
- Ability to work independently and collaboratively in a fast‑paced environment.
- Self‑starter with strong interpersonal, written, and verbal communication skills and the ability to interact with technical and non‑technical stakeholders.
- Splunk Enterprise Certified Admin, Splunk Enterprise Certified Architect OR Splunk Cloud Certified Admin, Splunk SOAR Certified Automation Developer preferred.
The physical demands described here are…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).