安全运营中心工程师
Security Operations Center Engineer
我们是一个屡获殊荣的团队,因成就和文化而受到认可,包括最近获得的2026年《福布斯》美国最佳中型企业雇主奖!
职位概述:
Security Operations Center Engineer的主要职责是识别、调查并升级警报和事件,以在7x24x365环境中保护敏感信息免受未经授权的访问或恶意且可能造成损害的威胁。管理并配置安全监控工具。评估安全系统和措施的弱点及可能的改进。保持对IT安全行业的最新了解,包括对新或修订的安全解决方案的意识。必须具备职业道德、好奇心和细致的工作态度。
还需负责定义安全流程路线图和知识文章(KB),变更管理验证,用户/系统受影响的安全事件管理和解决;管理Security Operations Center拥有的工具,包括脚本编写、定制、报告构建、警报修改、自动化和维护;降低系统安全和公司基础设施业务中断的风险;积极参与灾难恢复和BCP事件。某些工作职能可能需要一些脚本编写、编码和/或技术证书,因此需要愿意扩展技术能力。
地区薪资信息
招聘过程中可能需要现场面试
该职位的州级薪资范围如下:
$83,670 至 $161,815(新泽西州、纽约州、华盛顿州、夏威夷州、阿拉斯加州、马里兰州、康涅狄格州、罗德岛州、马萨诸塞州)
$76,064 至 $147,104(内华达州、俄勒冈州、亚利桑那州、科罗拉多州、怀俄明州、德克萨斯州、北达科他州、明尼苏达州、密苏里州、伊利诺伊州、威斯康星州、佛罗里达州、佐治亚州、密歇根州、俄亥俄州、弗吉尼亚州、宾夕法尼亚州、特拉华州、佛蒙特州、新罕布什尔州、缅因州)
$68,457 至 $132,394(犹他州、爱达荷州、蒙大拿州、新墨西哥州、南达科他州、内布拉斯加州、堪萨斯州、俄克拉荷马州、爱荷华州、阿肯色州、路易斯安那州、密西西比州、阿拉巴马州、田纳西州、肯塔基州、印第安纳州、南卡罗来纳州、北卡罗来纳州、西弗吉尼亚州)
在加利福尼亚州:典型招聘范围为 $110,468 至 $153,428
此职位的预期基本薪资将根据多种因素有所不同,包括相关经验、技能和地点。
职责
核心工作职责:
- 监控安全工具与系统:分析日志、警报和数据以发现可疑活动。
- 调查潜在威胁:确定警报是否为真实事件并识别漏洞。
- 监督所有事件/安全问题,包括初步分类、故障排除和修复。
- 收集证据:收集并分析证据以了解事件的范围和影响。
- 限制影响
查看英文原文
Overview
Join an amazing team that is consistently recognized for our achievements and culture, including our most recent Forbes award of being one of America's Best Midsize Employers for 2026!
Position Summary:
The primary job function of the Security Operations Center Engineer is to identify, investigate, and escalate alerts and events to safeguard sensitive information from unauthorized access or breaches of malicious and potentially damaging intent in a 7x24x365 environment. Manages and configures security monitoring tools. Assess security systems and measures for weaknesses and possible improvements. Maintain up-to-date knowledge of the IT security industry including awareness of new or revised security solutions. Must be ethical, curious, and detail oriented.
Will also be responsible for definition of security process road maps and knowledge articles (KB), change management validations, user/system impacted security incident management and resolutions; Administration of Security Operations Center owned tools including scripting, customizations, report building, alert modifications, automations and maintenance; Minimize risk and exposure to system security and business interruptions of company's infrastructure; actively participate in disaster recovery and BCP events. Some scripting, coding and/or technical certificates may be needed to achieve certain job functions, so willingness to expand technical attributes will be expected.
Geo-Salary Information
An in-person interview may be required during the hiring process
State specific pay scales for this role are as follows:
$83,670 to $161,815 (NJ, NY, WA, HI, AK, MD, CT, RI, MA)
$76,064 to $147,104 (NV, OR, AZ, CO, WY, TX, ND, MN, MO, IL, WI, FL, GA, MI, OH, VA, PA, DE, VT, NH, ME)
$68,457 to $132,394 (UT, ID, MT, NM, SD, NE, KS, OK, IA, AR, LA, MS, AL, TN, KY, IN, SC, NC, WV)
In CA: Typical hiring range is $110,468 to $153,428
The expected base salary for this position will vary depending on a number of factors, including relevant experience, skills and location.
Responsibilities
Essential Job Functions:
- Monitor security tools & systems: Analyze logs, alerts, and data for suspicious activity.
- Investigate potential threats: Determine if alerts are real incidents and identify vulnerabilities.
- Supervise all Incident/Security issues, including preliminary triage, troubleshooting and remediation.
- Gather evidence: Collect and analyze evidence to understand incident scope and impact.
- Contain the threat and remediate vulnerabilities: Quickly contain the incident to minimize damage, and implement patching, configuration changes, or other measures to address the exploited vulnerabilities.
- Recover from the incident and report to management: Assist in restoring affected systems and data to their normal state, and keep management informed about security incidents and response efforts.
- Documentation: Document findings for future reference and improvement, including process roadmaps, change management validations, and user/system impacted incident management and resolutions.
- Administer SOC/NOC tools: Manage and administer all SOC/NOC Operations center owned tools, including scripting, customizations, report building, alert modifications, automations, and maintenance.
- Minimize risk and exposure to system security and business interruptions of the company's infrastructure.
- Participate in disaster recovery and BCP events: Actively participate in disaster recovery and Business Continuity Plan (BCP) events.e
Qualifications
Education:
Minimum:
· BS degree in Computer Science, Information Technology, related field; and/or equivalent combination of education or work experience
Preferred:
- GIAC Security Essentials Certification
- GIAC Security Leadership Certification
- ISACA Certified Information Security Manager
- Microsoft Certified Systems Engineer: Security
- (ISC)2 SCCP
- (ISC)2 CISSP
- (ISC)2 ISSAP
- CCSK4
Experience:
Minimum:
· 2-4 years of 24x7x365 Security Operations experience and related technologies
Preferred:
· 5 or more years of 24x7x365 Security Operations and related technologies
Skills & Abilities:
Enterprise Security Operations support experience
- Enterprise security document creation.
- Understanding of IT infrastructure and networking: This includes knowledge of operating systems, network protocols, and basic infrastructure components.
- Security principles and technologies: Familiarity with common security threats, vulnerabilities, and mitigation strategies like firewalls, intrusion detection/prevention systems (IDS/IPS), and SIEM tools.
- Scripting and automation: Ability to write basic scripts to automate tasks and generate reports.
- Incident response procedures: Understanding of established processes for handling security incidents, including containment, eradication, and recovery.
- Security tools and software: Proficiency in using the specific security tools and software typically employed by a security organization.
- Experience in using ExtraHop, Qradar, Splunk and/or any other security related tools for the visibility, monitoring, detection, alerting, response, and investigation of security related events.
- Communication: Clear and concise communication with technical and non-technical audiences, including reporting incidents to management and collaborating with other IT teams (including public speaking, critical business writing skills, process documentation and knowledge base article composure)
- Critical thinking and problem-solving: Ability to analyze complex security data, identify root causes of incidents, and develop effective solutions.
- Attention to detail: Meticulous focus on identifying subtle anomalies and potential threats within vast amounts of data.
- Decision-making under pressure: Making quick and informed decisions during critical security incidents.
Preferred:
- ServiceNow
- SIEM Solutions
- TrustWave
- Email Protection Solutions
- Endpoint Detection & Response Solutions
- Microsoft 365 Security Suite
- Incident Management Communication tools
- CV/CIRT Gov’t notification process
- Load balancers & Web Application Firewall Solutions
- Firewall/router/networking equipment
- Web Content Filtering (WSS)
- Secure Web Gateway Solutions
- ITIL Foundations certifications (V3 or V4)
About the Company
Why choose a career at Mercury?
At Mercury, we have been guided by our purpose to help people reduce risk and overcome unexpected events for more than 60 years. We are one team with a common goal to help others. Everyone needs insurance and we can’t imagine a world without it.
Our team will encourage you to grow, make time to have fun, and work together to make great things happen. We embrace the strengths and values of each team member. We believe in having diverse perspectives where everyone is included, to serve customers from all walks of life.
We care about our people, and we mean it. We reward our talented professionals with a competitive salary, bonus potential, and a variety of benefits to help our team members reach their health, retirement, and professional goals.
Learn more about us here:
Perks and Benefits
We offer many great benefits, including:
- Competitive compensation
- Flexibility to work from anywhere in the United States for most positions
- Paid time off (vacation time, sick time, 9 paid Company holidays, volunteer hours)
- Incentive bonus programs (potential for holiday bonus, referral bonus, and performance-based bonus)
- Medical, dental, vision, life, and pet insurance
- 401 (k) retirement savings plan with company match
- Engaging work environment
- Promotional opportunities
- Education assistance
- Professional and personal development opportunities
- Company recognition program
- Health and wellbeing resources, including free mental wellbeing therapy/coaching sessions, child and eldercare resources, and more
Mercury Insurance is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by federal, state, or local law.
Pay Range
USD $83,670.00 - USD $161,815.00 /Yr.Originally posted on Himalayas