Security Operations Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• Excited about Alpaca’s mission and what we’re building • 3+ years of experience in Security Operations roles • Hands-on experience operating and tuning a SIEM (on-prem or cloud-based) • Hands-on experience maintaining Kubernetes clusters • Working with Linux • Scripting or automation experience (Python, Bash) for security operations tasks • Experience working with a third-party SOC or MSSP • Strong incident response and alert investigation skills across identity, endpoint, network, and cloud environments • Understanding of common attacker techniques and detection methodologies • Experience working closely with IT/helpdesk teams and translating security requirements into operational workflows • Familiarity with endpoint security, identity monitoring, and log-based detections • Strong written and verbal communication skills, especially during incidents • Comfortable working cross-functionally and handling escalations calmly and decisively • Who You Might Be (Nice-to-Haves): • Who You Might Be • Nice-to-Haves): • Experience securing financial, trading, or other highly regulated platforms • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or PCI • Experience with detection engineering frameworks (MITRE ATT&CK) • Knowledge of cloud security logging (AWS/GCP/Azure) and SaaS security telemetry • Experience working with GitOps and CI/CD pipelines • Experience running tabletop exercises or incident response simulations • Security certifications (GCIA, GCIH, GCED, CISSP, or similar) • Ability to balance security rigor with operational efficiency and business needs • How We Take Care of You: • Competitive Salary & Stock Options • Health Benefits • New Hire Home-Office Setup: One-time USD $500 • Monthly Stipend: USD $150 per month via a Brex Card • Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce. • Recruitment Privacy Policy
Responsibilities
• We are seeking a Security Operations Engineer to mature Alpaca’s day-to-day security operations. This role will be responsible for managing our third-party SOC relationship, operating and tuning our on-prem SIEM, and acting as a critical bridge between IT Helpdesk and the Security team to ensure security issues are identified, triaged, and resolved quickly and consistently. • You will be both hands-on and operationally minded: improving detection quality, streamlining alert triage, coordinating incident response, and ensuring security operations scale with the business. You’ll play a key role in turning security signals into action and ensuring operational issues don’t become security incidents. • This role reports to the Enterprise Security Architect and works closely with IT, DevOps, Engineering, and our external SOC partner. • The Security Team is 100% distributed and remote. • Things You Get To Do: • The core responsibilities of the Security Operations Engineer are focused on detection, response, operational excellence, and cross-functional coordination. • Security Operations and Detection Engineering: • Security Operation Center: Own the relationship with our managed SOC, including alert quality, escalation workflows, SLAs, runbooks, and continuous improvement of detection coverage and response effectiveness. Assist with triage, investigations, and respond to security alerts across endpoints, identity, cloud, network, and application logs. • Security Operation Center: • SIEM Management: Operate and maintain our SIEM, including log onboarding, parsing, normalization, correlation rules, alert tuning, and lifecycle management to reduce noise and increase signal. • SIEM Management • Log Coverage & Telemetry: Ensure critical systems generate the right security telemetry, filling gaps across endpoints, identity providers, network devices, SaaS tools, and cloud platforms. • Log Coverage & Telemetry: • Detection Improvements: Continuously refine detection logic based on threat intelligence, SOC feedback, incident learnings, and emerging attack techniques. • Detection Improvements: • Incident Response & Metrics: • Incident Handling: Assist with security incidents, working with IT, Engineering, and external partners to contain, eradicate, and recover from incidents. • Incident Handling: • Runbooks & Playbooks: Develop, maintain, and continuously improve incident response playbooks, escalation paths, and communication procedures. • Runbooks & Playbooks: • Operational Metrics: Track and report on key security operations metrics such as alert volumes, false positive rates, mean time to detect (MTTD), mean time to respond (MTTR), and SOC performance. • Operational Metrics: • IT & Security Collaboration: • Bridge IT and Security: Act as the security liaison to the IT Helpdesk, ensuring security-related tickets are properly triaged, prioritized, and resolved without slowing down business operations. • Bridge IT and Security: • Security Enablement: Provide guidance and context to IT teams on security alerts, risks, and required actions, helping raise the overall security maturity of frontline support teams. • Security Enablement:
Benefits
• New Hire Home-Office Setup: One-time USD $500 • Monthly Stipend: USD $150 per month via a Brex Card • Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce. • Recruitment Privacy Policy