Security Operations Engineer
vertexinc · Remote USA · United States · Remote
Pay: USD 91,200 – 118,600 a year
Posted Oct 9, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Job Description:
Vertex Inc. is looking for a Security Operations Engineer role to strengthen our security monitoring, incident response, detection engineering, and SecOps automation capabilities. This role is ideal for a hands-on security practitioner who has a passion for investigating threats, responding to incidents, improving security tooling, and building operational solutions that help security teams work faster and more effectively. Given the 24/7/365 nature of the security operations function, the Security Operations Engineer participates in a rotating shift schedule designed to provide continuous security analysis and incident response coverage. Within the coverage, this will require working nights, weekends, holidays, and extended hours based on the assigned coverage and operational needs.
Responsibilities
Monitor, triage, investigate, and respond to security alerts across endpoint, identity, network, cloud, SaaS, and application environments.
Lead end-to-end incident response — detection through containment, eradication, recovery, and post-incident improvement — including root-cause analysis and corrective action tracking.
Build, tune, and maintain detection logic across SIEM, EDR, cloud, and network platforms; conduct proactive threat hunting aligned to MITRE ATT&CK.
Develop and maintain SecOps tooling, scripts, API integrations, and workflow automations to improve investigation speed and response execution.
Apply AI responsibly in SecOps workflows, with the ability to explain, validate , test, and maintain all AI-assisted outputs.
Collaborate cross-functionally to close telemetry gaps, improve detection coverage, and translate incident findings into lasting security improvements.
Required Qualifications
Hands-on knowledge in security operations, incident response, detection engineering, or threat hunting, with demonstrated ability to lead significant investigations.
Strong knowledge of attacker tactics and techniques across endpoint, identity, network, cloud, and email environments, including MITRE ATT&CK mapping and IOC analysis.
Experience with SIEM platforms (Sentinel, Splunk, Chronicle, QRadar , or Elastic) and proficiency writing and tuning detection queries using KQL, SPL, Sigma, YARA, or equivalent.
Experience with EDR/XDR platforms (Defender for Endpoint, CrowdStrike, SentinelOne , Cortex XDR, or Carbon Black), including triage, investigation, and containment.
Scripting or automation experience using Python, PowerShell, or Bash; AI-assisted development acceptable provided the candidate can explain, validate , test, and maintain the code.
Practical use of AI tooling for securit y — such as Claude, GitHub Copilot, or OpenAI Codex — to accelerate tooling development, detection drafting, and a nalysi s workflows.
Experience with at least one cloud platform (AWS, Azure, GCP, or OCI), including cloud logging, identity, and security monitoring.
…