Security Operations Engineer
Quick Summary
design, write, and tune analytics rules and correlation logic in Microsoft Sentinel, aligned to MITRE ATT&CK.
About the Role
~1 min read"You'll build the detections that catch what alerts alone would miss, and the automation that keeps a lean team ahead of the threats."
As a Security Operations Engineer on Mastery's Information Security team, you'll own detection engineering and SOAR automation for MasterMind, our Azure-native transportation management platform. You'll design and tune the analytics rules running in Microsoft Sentinel, build automated response workflows that cut manual triage time, and close visibility gaps across our AKS, endpoint, and network telemetry as we bring new log sources online.
This role is ideal for a deeply technical engineer who wants to build and ship detections and automation — not manage people or run the team's day-to-day. If you'd rather spend the day in KQL and automation workflows than in a status meeting, this is built for you.
- Build real detections: design, write, and tune analytics rules and correlation logic in Microsoft Sentinel, aligned to MITRE ATT&CK.
- Close the gaps: identify and close visibility blind spots across our infrastructure and telemetry as new log sources come online.
- Reduce the noise: continuously validate and refine detections to cut false positives without losing real signal.
- Automate the busywork: design and build SOAR playbooks and workflows that automate triage, enrichment, and response, freeing the analyst team to focus on real investigations.
- Integrate the stack: build and maintain integrations across Sentinel, Defender, and other security tooling via APIs and scripting.
- Translate intel into detections: turn emerging threats and adversary TTPs into actionable, tuned detection logic.
- Stay hands-on: keep pace with evolving attacker techniques and Sentinel/SOAR platform capabilities through direct, ongoing technical work.
- 4+ years in security operations, detection engineering, or a closely related technical security role.
- Demonstrated, hands-on experience building or substantially tuning detection rules and correlation logic in a SIEM (Sentinel strongly preferred).
- Experience building SOAR playbooks or comparable security automation workflows.
- Deep query language fluency: comfortable writing and debugging complex KQL (or equivalent SIEM query language) without hand-holding.
- Scripting and API proficiency: Python or PowerShell for automation, with experience integrating tools via REST APIs.
- Self-directed technical focus: prefers to own and ship technical work independently over managing people or processes.
Nice to Have
~1 min read- Experience in an Azure/AKS or other Kubernetes-based cloud environment.
- Experience supporting SOC 2 or similar compliance audits from a technical evidence standpoint.
- Familiarity with Sentinel Logic Apps or another SOAR automation platform.
- Detection coverage measurably improves: new log sources come online with real, tuned detections behind them, not just raw ingestion.
- False positive rates drop: the analyst team trusts what fires in the queue instead of triaging noise.
- Manual triage time shrinks: SOAR playbooks handle the repeatable work so the team's time goes to real investigations.
Most TMS platforms are tolerated. We've proven a better way — one platform built for every facet of transportation: shippers, carriers, private fleets, and brokers, all under one roof. Built to be loved. We're still the only ones who mean that.
What We Offer
~1 min readWe don't do "bare minimum" here — not in the product, not in the culture, and definitely not in how we take care of our people. Mastery's benefit package is built to give you real coverage, real flexibility, and real peace of mind.
Location & Eligibility
Listing Details
- First seen
- October 2, 2026
- Last seen
- October 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 57%
- Scored at
- October 2, 2026
Signal breakdown
Similar Security Operations Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.