Sr. SOC Engineer
Dallas, United States · Hybrid · Full-time
- Posted 1w ago
- From Zimperium’s careers page
- Location
- Dallas, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Senior
- Experience
- 8+ years
- Department
- Information Technology
Apply on Zimperium’s site
Opens the listing on jobs.lever.co
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Key Responsibilities:
- 8+ years in security operations, threat detection, or incident response, with at least 4 years in a SIEM/SOC engineering or detection engineering role.
- Deep hands-on experience with at least one major SIEM platform (Splunk, ELK, Chronicle/Google SecOps, Sentinel, Sumo Logic). Production experience with detection authoring and tuning.
- Strong understanding of log types and sources—OS logs, application logs, network flow, DNS, proxy, endpoint telemetry, CNAPP/runtime security events. Ability to interpret and normalize heterogeneous data.
- Experience building or tuning threat detection rules and correlation logic. Working knowledge of attack frameworks (MITRE ATT&CK) and how to operationalize them.
- Proficiency in at least one scripting/programming language (Python, Go, Bash) sufficient to build and maintain automation, not just modify examples.
- Experience integrating security tools—APIs, webhooks, orchestration platforms (Zapier, Make, native SOAR). Comfortable debugging API calls and data flow.
- Hands-on incident investigation experience—evidence collection, root cause analysis, timeline reconstruction, scope determination.
- Familiarity with mobile threat detection, CNAPP, or endpoint threat detection. Understanding of how mobile/app security signals differ from infrastructure security.
- Strong written and verbal communication—ability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.
Required Qualifications:
- CNAPP & SecOps Integration. Orchestrate data flow from Zimperium's CNAPP platform into Google SecOps and other security tools. Build and own integrations to coordinate threat notifications, ensure consistent severity assignment, and enable unified response across mobile and cloud/infrastructure security.
- Google SecOps Platform Engineering. Own and maintain Google SecOps as the operational hub—SOAR workflows, alert routing logic, case management, automation rules, integrations with ticketing systems (Jira), notification channels, and escalation procedures. You make architectural decisions on how alerts flow through the system and how the team works.
- Investigative Leadership. Lead investigations into high-severity and complex incidents. Conduct root cause analysis, determine scope and impact, coordinate containment and remediation, and produce clear post-incident reports. You own the investigative strategy and mentor junior analysts on tradecraft.
- SOC Automation & Tooling. Write or adapt tools and scripts (Python, Go, Bash) to automate SOC workflows—bulk event analysis, data enrichment, response actions, reporting. Integrate third-party tools and APIs into Google SecOps workflows. You own the efficiency and scale of the SOC's technical operations.
- Metrics & Reporting. Define, instrument, and own SOC KPIs—detection latency, mean time to respond (MTTR), investigation duration, false positive rate, automation coverage. Build dashboards and reports for leadership. You are accountable for continuous improvement in SOC performance.
- On-Call & Incident Response. Serve as incident commander or key investigator for high-priority events. Drive incidents to root cause, not just closure. You own the incident response quality.
- Compliance & Audit Support. Generate evidence and documentation for security audits (ISO 27001, FedRAMP). Translate technical findings into auditor-readable format.
Preferred Qualifications:
- Prior experience with Google Chronicle, Google SecOps, or similar cloud-native SIEM platforms.
- Experience with AI/ML-based alert triage, anomaly detection, or automated incident response.
- Experience operating in regulated or compliance-heavy environments—FedRAMP, DoD, PCI-DSS, HIPAA.
- Hands-on experience with mobile threat detection, mobile app security, or container/Kubernetes runtime security.
- Experience with threat modeling, vulnerability disclosure coordination, or security research.
- Relevant certifications (GCIH, ECIH, OSINT, GIAC certifications, or vendor-specific: Google Cloud Security, AWS Security, etc.).
- Prior DevSecOps, security engineering, or cloud security experience. A background in building systems shows a level of thinking we value.
Skills they ask for
Pick one to see other roles that ask for it.
About Zimperium
Mobile security for apps and devicesZimperium provides mobile security products for protecting mobile applications and devices against threats.
See all 8 roles at ZimperiumMore roles at Zimperium
See all 8- Partner and Alliance Manager/Director, Americas EnterpriseUnited States · RemoteBusiness Development · RemoteUnited States1w
- Business Development Representative (SaaS & Cybersecurity) - Central or NortheastUnited States · RemoteSales · RemoteUnited States2w
- Site Reliability Engineer - Dallas, TXDallas · Senior · HybridEngineering · Senior · HybridDallas, United States2w
- Sr. Sales Operations/Deal Desk & Order Management SpecialistDallas · Senior · HybridSenior · HybridDallas, United States3w
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.