Logo for Quzara LLC

SOC Engineer

Role overview

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience.
  • 5+ years in IT infrastructure, cloud, or security engineering, including 3+ years hands-on with Microsoft Azure.
  • 2+ years with Microsoft Sentinel or a comparable enterprise SIEM, including data-source onboarding.
  • At least one current certification required: AZ-500 or SC-200.

Responsibilities

  • Lead technical onboarding of new customers, from discovery and requirements through configuration, validation, and handoff.
  • Configure and integrate Microsoft security services, including Microsoft Sentinel, Defender XDR, and Entra ID, with customer environments.
  • Onboard and validate security telemetry from identity, endpoint, network, SaaS, and multi-cloud sources.
  • Produce clear technical documentation and work directly with customer stakeholders to resolve onboarding blockers.

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • SOC Analyst
  • English

Hard skills

Other skills

  • Microsoft Windows
  • Communication

About the company

Quzara LLC logo

Quzara LLC

Cybersecurity

Quzara is a DC-Based Cybersecurity firm. We are US Government SBA 8(a) Certified, WOSB and GSA HAC SINS approved in every category. We provide FedRAMP Advisory services (FedRAMP ATO on AWS Program; Azure ATO & Rackspace Government Partner. We're also CMMC Registered Provider Organization (RPO).

Company details

Company typeStartup
IndustryCybersecurity
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Title: SOC Engineer

Pay Type: SALARIED EXEMPT 

Location: Remote (Must Work East Coast Hours)

Citizenship: U.S. Citizenship (Required)

Summary of Position Role/Responsibilities

Quzara is seeking a hands-on SOC Engineer to onboard customers into our managed security services and keep their security tooling and telemetry running reliably. The SOC Engineer works with customers and internal teams to integrate data sources, configure Microsoft security services, automate workflows, and resolve technical issues in federal and regulated environments.

Essential Functions of the Job

  • Lead technical onboarding of new customers, from discovery and requirements through configuration, validation, and handoff.
  • Configure and integrate Microsoft security services, including Microsoft Sentinel, Defender XDR, and Entra ID, with customer environments.
  • Onboard and validate security telemetry from identity, endpoint, network, SaaS, and multi-cloud sources, including Azure, AWS, and Google Workspace.
  • Integrate and troubleshoot log sources across multiple SIEM platforms, including Microsoft Sentinel, Splunk, SentinelOne, and IBM QRadar.
  • Troubleshoot ingestion and integration issues across cloud, identity, network, Windows, and Linux layers.
  • Build automation and scripts that make onboarding and operations repeatable.
  • Support customers operating under federal and regulated requirements, including FedRAMP, CMMC, and NIST frameworks.
  • Produce clear technical documentation and work directly with customer stakeholders to resolve onboarding blockers.

Marginal Functions of the Job

  • Other duties as assigned

Normal Work Schedule: 

This full-time role runs Monday to Friday, 8:30 AM–5:30 PM and requires flexibility to work remotely or on-site (if applicable per client RTO policies). On occasion additional hours may be necessary. 

Education, Training, and Experience

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience.
  • 5+ years in IT infrastructure, cloud, or security engineering, including 3+ years hands-on with Microsoft Azure.
  • 2+ years with Microsoft Sentinel or a comparable enterprise SIEM, including data-source onboarding.
  • Strong working knowledge of the Microsoft security stack (Sentinel, Defender XDR, Entra ID, Azure Monitor / Log Analytics) and multi-tenant delegated access (Azure Lighthouse, GDAP).
  • Hands-on experience onboarding a wide range of data sources (identity providers, endpoints, firewalls and network devices, SaaS applications, Syslog/CEF, API, and agent-based integrations) from Azure, AWS, and Google Workspace / Google Cloud.
  • Experience working across multiple SIEM platforms, such as Microsoft Sentinel, Splunk, SentinelOne, IBM QRadar, or similar.
  • Proficiency in KQL and scripting (PowerShell or Python), with solid troubleshooting skills across Windows, Linux, networking, and identity.
  • Strong written and customer-facing communication skills.
  • At least one current certification required: AZ-500 or SC-200.
  • Preferred: prior MSSP, MDR, or security consulting experience; experience supporting federal or defense-industrial-base customers, including GCC and GCC High environments; and experience with EDR/XDR platforms such as CrowdStrike or SentinelOne.

Preferred Certifications

  • Ideal: SC-100 (Microsoft Cybersecurity Architect Expert).
  • Microsoft: AZ-104 (Azure Administrator), AZ-305 (Azure Solutions Architect Expert), SC-300 (Identity and Access Administrator), SC-401 (Information Security Administrator), MS-102 (Microsoft 365 Administrator).
  • Cloud security: AWS Certified Security – Specialty, Google Professional Cloud Security Engineer.
  • SIEM / EDR: Splunk Enterprise Security Certified Admin, IBM QRadar SIEM, SentinelOne, or CrowdStrike Falcon (CCFA) certifications, or equivalent.
  • General security: CISSP, CCSP, CompTIA Security+ or CySA+, GIAC (GCDA, GCIH, or GCED).

EEO Statement

The Company is an Equal Employment Opportunity (EEO) employer and does not discriminate based on race, color, religion, sex, sexual orientation, national origin, age, marital status, disability, veteran's status, or any other basis protected by applicable discrimination laws.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

SOC Analyst Related jobs

Other jobs at Quzara LLC

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.