remote
SOC Engineer - Mercury Insurance Company
Software Engineer
Security Operations Center Engineer responsible for monitoring, investigating, and escalating security alerts in a 24/7 environment, leveraging SIEM tools, Splunk, and scripting to protect sensitive data and improve security posture.
About the role
Key Responsibilities
- Monitor security alerts and events across a 24/7 environment using SIEM platforms and Splunk.
- Investigate, triage, and escalate incidents, documenting findings and remediation steps.
- Configure, tune, and maintain security monitoring tools, firewalls, IDS/IPS, and endpoint protection solutions.
- Conduct vulnerability assessments and recommend improvements to security controls.
- Develop and maintain automation scripts (e.g., Python) to streamline detection and response workflows.
- Stay current with emerging threats, industry best practices, and regulatory requirements.
Requirements
- 3+ years of experience in a SOC or similar security operations role.
- Proficiency with SIEM technologies (Splunk, QRadar, or similar) and log analysis.
- Strong knowledge of network protocols, firewalls, IDS/IPS, and endpoint security.
- Hands‑on scripting experience, preferably Python, for automation and data parsing.
- Solid understanding of incident response processes and vulnerability management.
Skills
siemsplunkpythonlinuxnetwork security