Apply with hirly
Senior SOC Engineer - Agentic
Sans
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
About SANS Founded in 1989, SANS Institute (SANS) began as a cooperative research and education organization. Over the next 25 years, it grew to become the most trusted and widely recognized provider of information security training and certification in the world. Today, SANS has served more than 300,000 cybersecurity professionals around the world, with more than 60,000 earning Global Information Assurance Certification (GIAC) security certifications—the leading certification that provides assurance to employers that their people and prospective hires can do the job. At the heart of SANS is a community of practitioners, from auditors and network administrators to CISOs, who share their lessons learned and collaborate on solutions to the challenges they face. These experts, working across corporations, government agencies, and universities, come together to support and strengthen the global information security community. Why SANS? At SANS, our culture is defined by three pillars: Mission, Brand, and People.
- Our Mission is to hire people who understand the importance fighting against cybersecurity threats.
- Our Brand reflects a commitment to delivering the highest quality training.
- Our People are grounded in a culture of fairness, honesty, customer focus, and a pragmatic approach. What You’ll Achieve at SANS We are seeking a Senior SOC Engineer
- Agentic to join our Security team. This role is a dual-focus security engineering role. On one side, this engineer owns the design and buildout of our agentic SOC — building the detection engineering, automation, and AI agent infrastructure that allows a lean security team to operate at the scope of a much larger one. On the other, they serve as a hands-on security engineer across the full breadth of the program: vulnerability management, cloud security, identity and access management, application security, architecture reviews, and compliance support. Initially the role will split roughly evenly between these two tracks. As the Agentic SOC matures and AI agents absorb more of the operational workload, the balance will shift — but the security engineering work never goes away. This is a role for someone who wants to do real security engineering today while building the systems that redefine what security engineering looks like tomorrow. As a Senior SOC Engineer
- Agentic , you will:
- Agentic SOC Buildout
- Design the architecture of the agentic SOC. Define how data flows through the detection and response pipeline, how agents are structured and orchestrated, where human-in-the-loop checkpoints belong, and how the overall system evolves as we expand agent autonomy.
- Build and own detection engineering. Write, tune, and maintain detections across our internal SIEM environment. Treat detection content as code — version-controlled, peer-reviewed, tested, measured. Establish the lifecycle of design → deploy → measure → tune → improve.
- Translate SOC operations into automation. Identify the alert triage, investigation, and response work that is ripe for agent augmentation, and define what good looks like for each workflow before it gets handed to an agent.
- Build automations and integrations across our stack. Connect our MSSP, EDR, SIEM, cloud infrastructure, and identity platforms through integrations, scripts, and playbooks — both deterministic automation where that is the right tool, and agent-driven workflows where it is not.
- Partner with AI Engineering to build and govern the agent stack. Co-design the MCP servers and tool integrations that let agents work with security systems. Contribute to prompt design, evaluation harnesses, and feedback loops — and own the audit trails and checkpoints that keep agent actions safe and accountable.
- Operate and improve. Monitor agent performance, investigate failures, tune behavior, and feed real-world outcomes back into the system. The job does not end when something ships.
- Security Engineering
- Vulnerability management. Own the vulnerability identification, prioritization, and remediation tracking program. Work with engineering and infrastructure teams to drive risk reduction across the environment.
- Cloud security. Assess and improve cloud security posture across AWS and Azure — identity and access management (IAM) policy review, configuration hardening, cloud-native detection, and ongoing posture monitoring.
- Identity and access management. Partner with IT and engineering on identity architecture, access reviews, privilege management, and authentication standards.
- Application security. Conduct code reviews, threat models, and security assessments for internal applications and integrations. Partner with development teams to shift security left.
- Security architecture reviews. Evaluate new technologies, integrations, and infrastructure changes for security risk. Provide pragmatic, risk-based guidance.
- Compliance and audit support. Support security compliance activities, evidence collection, and audit engagements as needed.
- Respond to incidents. When something real happens, you are part of the response. The agents help; they do not replace you.
- Perform other related duties as assigned. What We’re Looking For Every SANS employee brings something unique. For this role, we’re looking for candidates with:
- 7+ years in security operations, detection engineering, or security automation, with enough depth to lead engineering efforts independently — and enough intellectual curiosity to be genuinely excited about rebuilding how a SOC works from the ground up.
- First-hand experience with what a well-run SOC looks like — alert triage workflows, escalation paths, investigation patterns, incident response lifecycle.
- Detection engineering experience: writing and tuning detections, measuring efficacy, managing false positives. Expert-level command of at least one detection query language (KQL, SPL, Lucene, Sigma, or equivalent). •
Mitre Att&ck
fluency as a working tool, not a reference.
- Hands-on experience with EDR and SIEM platforms in production environments.
- Ability to design end-to-end security operations pipelines — from log ingestion and detection through enrichment, triage, investigation, and response — with a clear understanding of where automation fits at each stage.
- Systems thinking: comfortable reasoning about data flows, dependencies, failure modes, and the operational implications of architectural decisions before they are built.
- Experience designing for scale and maintainability — architectures that a small team can operate, extend, and recover when things break.
- Exposure to threat modeling concepts applied to security infrastructure — you do not need to have owned this, but you should be ready to grow into it.
- Comfort thinking through architectural tradeoffs and documenting your reasoning — this is a skill we will develop together, not a prerequisite.
- Strong Python — production-quality code with testing, version control, code review discipline.
- Comfortable building integrations against REST APIs across heterogeneous security tools.
- Experience with SOAR platforms, security automation frameworks, or equivalent home-grown tooling.
- Git-based workflows; as-code mindset for detections, automations, and infrastructure.
- Working knowledge of AWS; experience with Azure or GCP is a plus.
- Curiosity about how LLM-based agents differ from traditional automation, and where each fits.
- Willingness to learn agent frameworks, MCP, and prompt engineering on the job, working alongside our AI Engineering team.
- Side projects, reading, courses, or hobby experiments with LLMs or agents are a real plus — not because we need expertise, but because we need engagement.
- Comfortable working with JSON and Markdown — the connective tissue of modern agent tooling, API integrations, MCP server schemas, and documentation.
- Calibrated skepticism about over-automation — willing to say this should b