Security Operations Engineer

United StatesUnited States·Lake Forestmid
Security Operations EngineerCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

design, write, and tune analytics rules and correlation logic in Microsoft Sentinel, aligned to MITRE ATT&CK.

Technical Tools
Security Operations EngineerCybersecurity

About the Role

~1 min read

"You'll build the detections that catch what alerts alone would miss, and the automation that keeps a lean team ahead of the threats."

As a Security Operations Engineer on Mastery's Information Security team, you'll own detection engineering and SOAR automation for MasterMind, our Azure-native transportation management platform. You'll design and tune the analytics rules running in Microsoft Sentinel, build automated response workflows that cut manual triage time, and close visibility gaps across our AKS, endpoint, and network telemetry as we bring new log sources online.

This role is ideal for a deeply technical engineer who wants to build and ship detections and automation — not manage people or run the team's day-to-day. If you'd rather spend the day in KQL and automation workflows than in a status meeting, this is built for you.

  • Build real detections: design, write, and tune analytics rules and correlation logic in Microsoft Sentinel, aligned to MITRE ATT&CK.
  • Close the gaps: identify and close visibility blind spots across our infrastructure and telemetry as new log sources come online.
  • Reduce the noise: continuously validate and refine detections to cut false positives without losing real signal.
  • Automate the busywork: design and build SOAR playbooks and workflows that automate triage, enrichment, and response, freeing the analyst team to focus on real investigations.
  • Integrate the stack: build and maintain integrations across Sentinel, Defender, and other security tooling via APIs and scripting.
  • Translate intel into detections: turn emerging threats and adversary TTPs into actionable, tuned detection logic.
  • Stay hands-on: keep pace with evolving attacker techniques and Sentinel/SOAR platform capabilities through direct, ongoing technical work.
  • 4+ years in security operations, detection engineering, or a closely related technical security role.
  • Demonstrated, hands-on experience building or substantially tuning detection rules and correlation logic in a SIEM (Sentinel strongly preferred).
  • Experience building SOAR playbooks or comparable security automation workflows.
  • Deep query language fluency: comfortable writing and debugging complex KQL (or equivalent SIEM query language) without hand-holding.
  • Scripting and API proficiency: Python or PowerShell for automation, with experience integrating tools via REST APIs.
  • Self-directed technical focus: prefers to own and ship technical work independently over managing people or processes.

Nice to Have

~1 min read
  • Experience in an Azure/AKS or other Kubernetes-based cloud environment.
  • Experience supporting SOC 2 or similar compliance audits from a technical evidence standpoint.
  • Familiarity with Sentinel Logic Apps or another SOAR automation platform.
  • Detection coverage measurably improves: new log sources come online with real, tuned detections behind them, not just raw ingestion.
  • False positive rates drop: the analyst team trusts what fires in the queue instead of triaging noise.
  • Manual triage time shrinks: SOAR playbooks handle the repeatable work so the team's time goes to real investigations.

Most TMS platforms are tolerated. We've proven a better way — one platform built for every facet of transportation: shippers, carriers, private fleets, and brokers, all under one roof. Built to be loved. We're still the only ones who mean that.

What We Offer

~1 min read

We don't do "bare minimum" here — not in the product, not in the culture, and definitely not in how we take care of our people. Mastery's benefit package is built to give you real coverage, real flexibility, and real peace of mind.

Location & Eligibility

Where is the job
Lake Forest, United States
On-site at the office
Who can apply
US

Listing Details

First seen
October 2, 2026
Last seen
October 2, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
57%
Scored at
October 2, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Security Operations Engineer