The Role
11:11 Systems is looking for an experienced Security Engineer to join our Security Operations team. In this role, you'll support, build, and refine the systems and processes that power our global Security Operations Center (SOC), delivering 24/7 monitoring, support, and escalation for our customers.
You'll also serve as an escalation point for the SOC team and play a key role in reviewing high-severity customer incidents, including participation in an on-call rotation. We're looking for someone with a strong Security Engineering background, prior analyst experience in the telecom and/or enterprise cybersecurity industry, a knack for driving system and process efficiency, and a proactive mindset toward continuous improvement.
Responsibilities
- Support SOC Management in setting tactical and operational goals, and in developing policies and procedures for timely detection, assessment, reporting, and response to security events.
- Develop and fine-tune detection rules, correlation logic, and automation workflows across SIEM and SOAR platforms.
- Serve as customer-facing escalation support for issues and security incidents escalated from Tier 1 and Tier 2 SOC Analysts.
- Provide "first responder" incident response advisory support for clients experiencing security incidents, within the scope of 11:11 Systems' software and systems (not a Digital Forensics and Incident Response role).
- Own the timeliness and accuracy of critical incident identification, advisement, and reporting, both internally and to customers.
- Lead and support process improvement initiatives to advance operational objectives, drive efficiencies, and improve KPIs.
- Drive implementation and continuous improvement of new technologies, capabilities, frameworks, and methodologies.
- Develop and maintain customer-facing security stacks (SIEM, EDR, SOAR, WAF, vulnerability scanning) and architect technical improvements to existing processes.
- Troubleshoot network connectivity and infrastructure issues affecting the Security Operations Team.
- Advise on and help build SOC analyst training programs; provide cross-functional training as needed.
- Stay current on emerging threats, risks, and exploits, and translate that knowledge into updated SIEM detection rulesets.
- Support service delivery with pre-production reviews for newly onboarded SIEM and EDR customers.
- Participate in an on-call rotation for after-hours support.
- Work in alignment with 11:11's Code of Business Ethics and Company Values, including responsible data handling and completion of required compliance training.
Qualifications
- 5+ years in information security, including 3+ years in information technology.
- 3+ years' experience with SIEM, EDR, SOAR, and/or vulnerability scanning tools (focus on Azure Sentinel, Cortex XDR, and Tenable).
- Analyst-level experience in the telecom and/or enterprise cybersecurity industry.
- 1+ years' experience with Python scripting or development.
- 1+ years' experience with Linux administration and troubleshooting.
- Strong understanding of TCP/UDP/IP networking, packet analysis, and networking protocols.
- Experience with enterprise security architecture, detection, and response.
- Mature understanding of industry-standard incident response practices and SOC operations.
- Experience building Azure Sentinel use cases, analytics rules, and workbooks, including KQL query development.
- Experience with Kubernetes.
- Experience with Palo Alto products (Cortex XDR, Panorama, next-gen firewalls).
- Experience with ThreatX or similar WAF platforms.
- Active certifications such as Security+, CySA+, CASP+, CISSP, and/or GCIH.
- Working knowledge of security frameworks (ISO, NIST, CIS, etc.).
- Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and/or MITRE ATT&CK.
- Up-to-date knowledge of attacker tactics, techniques, and procedures.
- Excellent communication, problem-solving, and interpersonal skills for customer- and team-facing work.
- Must be a US Citizen and legally eligible to work in the US without visa sponsorship.
To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions.