Preferred Certification:
• ServiceNow certifications relevant to the platform (e.g., Certified System Administrator)
Required Skills:
• Proven SOC experience (detection engineering, security engineering, or senior analyst capacity) with a demonstrable engineering mindset
• Hands-on experience administering the ServiceNow Security Incident Response (SIR) module: configuring security incident workflows, business rules, assignment logic, and SIEM/SOAR/API integrations, and maintaining the module in a production SOC environment (3-5+ years)
• Hands-on automation and scripting, primarily Python, and experience building or contributing to Detection-as-Code pipelines
• Strong grounding in MITRE ATT&CK, Pyramid of Pain, Cyber Kill Chain, and the incident response process and its phases
• Deep understanding of at least one of: endpoint security (macOS and Windows internals, telemetry, detection) or cloud infrastructure (cloud-native services, Kubernetes, runtime detection)
• Solid networking fundamentals, including DNS
• Working knowledge of IAM, SSO (SAML/OIDC), and Zero Trust architecture concepts
• Working knowledge of Data Loss Prevention concepts and detection use cases
• Understanding of AI Detection & Response: securing and monitoring AI/LLM usage in the enterprise
• Familiarity with agentic AI frameworks and applying AI to SOC operations and detection engineering workflows
Preferred Skills:
• Security Incident Response implementation experience
• CI/CD tooling (Git, GitHub Actions or similar) for security content deployment
• Experience integrating AI/LLM capabilities into SOC triage or detection pipelines
• Familiarity with Risk-Based Alerting concepts
• Our stack: CrowdStrike Falcon (EDR), Zscaler (network and DLP), Wiz (cloud and Kubernetes runtime detection), Mate Security (AI SOC), Sublime (email security), Akamai (WAF and CDN), Onyx (AI detection and response), Splunk Enterprise Security (SIEM), ServiceNow Security Incident Response (SOC case management)- 3-5+ years. Direct experience with these specific tools is a plus, but strong fundamentals and the ability to ramp quickly matter more
Duties:
• Administer and enhance the ServiceNow Security Incident Response (SIR) module: security incident workflows, assignment and escalation rules, SLA definitions, form and UI configuration, and integrations with SIEM, SOAR, and threat intelligence sources
• Design, build, and maintain the Detection-as-Code (DaC) pipeline: detection development, version control, CI/CD-based testing, and automated deployment
• Develop and tune detections across EDR, cloud, network, email, and DLP telemetry
• Build SOAR playbooks, API integrations, and automation to streamline SOC workflows
• Support administration and optimization of the SIEM/SOAR platform stack
• Contribute to AI SOC initiatives: investigation coverage expansion, alert triage automation, and integration health
• Apply MITRE ATT&CK mapping, FP-rate gating, and detection lifecycle standards to all deployed content
• Partner with SOC analysts and incident response to translate operational gaps into engineering solutions
Job Details:
Contractor supporting Detection & Platform Engineering within Threat Operations. The team owns the technology backbone of the SOC across SIEM and SOAR platform management, AI SOC, automation, and detection deployment.
This is an engineering role, not a pure analyst role. It combines detection engineering with hands-on ownership of the SOC's case management platform. We are looking for someone who builds pipelines, automates repetitive work, develops and enhances the detection-as-code pipeline, administers ServiceNow Security Incident Response, and applies AI to improve day-to-day SOC productivity.
- **Only those lawfully authorized to work in the designated country associated with the position will be considered.**
- **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**
I believe the best thing that Rose HR has going for it is the incredible responsiveness. Everyone is very quick to reply to any concerns, and contacts the contracted employees very quickly and efficiently.
Kevin, Consultant
You are customer service oriented. No matter whether it was the Recruiter or someone in Human Resources/Payroll, you were responsive. That to me is key!
Tonya, Consultant
Rose International has been great to me. I thank everyone there for all of their hard work; it has not gone unnoticed.
Melody, Consultant
My on-boarding with Rose was outstanding. The packets of information, the process, and great attention to detail each person gave me allowed me to get started quickly.I appreciated each person's friendly and helpful attitude.
Diana, Consultant
The interactions that I have had with your representatives have always been prompt and very professional. I am very pleased and impressed with your company and services.
Sioe, Consultant
EMPLOYEE COMMENTS