SOC Specialist

Other Jobs To Apply

No other job posts for this day.

<h1>SOC Specialist</h1><p><strong>Location:</strong> Greenwich, CT</p><p><strong>Department:</strong> Technology</p><div><p></p> <h3>Company Overview</h3> <p>Interactive Brokers Group, Inc. (Nasdaq: IBKR) is a global financial services company headquartered in Greenwich, CT, USA, with offices in over 15 countries. We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technology and client commitment.</p> <p>IBKR affiliates provide global electronic brokerage services around the clock on stocks, options, futures, currencies, bonds, and funds to clients in over 200 countries and territories. We serve individual investors and institutions, including financial advisors, hedge funds and introducing brokers. Our advanced technology, competitive pricing, and global market help our clients to make the most of their investments.</p> <p>Barrons has recognized Interactive Brokers as the #1 online broker for six consecutive years. Join our dynamic, multi-national team and be a part of a company that simplifies and enhances financial opportunities using state-of-the-art technology.</p> <p></p></div><p></p> <p><span><strong>This is a hybrid role (3 days in office / 2 days remote).</strong></span></p> <p><span><strong>About your team:</strong></span></p> <p><span></span></p> <p><span>We are seeking an experienced SOC Specialist to help strengthen, modernize, and optimize our Security Operations capabilities. This role sits at the intersection of security operations, detection engineering, security automation, and incident response.</span></p> <p><span>The ideal candidate is passionate about improving SOC effectiveness through better detection logic, SIEM/XDR optimization, automation, threat detection engineering, and operational process improvements. You will play a key role in reducing alert fatigue, improving signal-to-noise ratio, accelerating response times, and enhancing overall security visibility across the enterprise.</span></p> <p><span>This position requires hands-on experience with enterprise security technologies, log analytics, threat detection, incident investigations, and security automation platforms.</span></p> <p><span><strong>What will be your responsibilities within IBKR:</strong></span></p> <ul> <li><span></span> <h3><span>Security Monitoring & Incident Response</span></h3> <ul> <li><span>Monitor, analyze, investigate, and respond to security alerts and incidents across enterprise environments.</span></li> <li><span>Perform triage and escalation of security events in accordance with incident response procedures.</span></li> <li><span>Conduct root cause analysis and document findings, containment actions, and remediation recommendations.</span></li> <li><span>Participate in incident response activities, including malware investigations, insider threat investigations, and account compromise incidents.</span></li> <li><span>Support threat hunting and proactive detection activities.</span></li> </ul> <h3><span>Detection Engineering</span></h3> <ul> <li><span>Develop, tune, and optimize SIEM detection rules, correlation searches, analytics, and alerting mechanisms.</span></li> <li><span>Create and maintain high-fidelity detections mapped to MITRE ATT&CK techniques and adversary behaviors.</span></li> <li><span>Continuously improve detection coverage across endpoints, cloud platforms, identity systems, networks, and applications.</span></li> <li><span>Measure and improve detection effectiveness through detection engineering metrics and validation exercises.</span></li> <li><span>Reduce false positives and improve alert quality through continuous tuning and optimization.</span></li> </ul> <h3><span>SIEM, XDR & Security Platform Management</span></h3> <ul> <li><span>Administer and optimize security monitoring platforms including SIEM, XDR, EDR, NDR, and cloud security tooling.</span></li> <li><span>Maintain log ingestion pipelines, data normalization, parsing, enrichment, and retention strategies.</span></li> <li><span>Validate health, performance, and scalability of security monitoring infrastructure.</span></li> <li><span>Collaborate with infrastructure, cloud, and application teams to onboard new log sources and security telemetry.</span></li> </ul> <h3><span>Security Automation & SOAR</span></h3> <ul> <li><span>Design, develop, and maintain SOAR playbooks and automated response workflows.</span></li> <li><span>Automate repetitive SOC tasks to improve analyst efficiency and reduce response times.</span></li> <li><span>Integrate security tools using APIs, scripting, and workflow orchestration platforms.</span></li> <li><span>Develop automated enrichment, containment, and investigation processes.</span></li> </ul> <h3><span>Threat Intelligence & Threat Hunting</span></h3> <ul> <li><span>Leverage threat intelligence feeds and indicators of compromise (IOCs) to improve detection capabilities.</span></li> <li><span>Conduct threat hunting activities using endpoint, network, cloud, and identity telemetry.</span></li> <li><span>Research emerging threats, attacker techniques, and vulnerabilities affecting the organization.</span></li> <li><span>Assist with purple team exercises and detection validation efforts.</span></li> </ul> <h3><span>Security Operations Improvement</span></h3> <ul> <li><span>Identify opportunities to improve SOC processes, workflows, runbooks, and operational metrics.</span></li> <li><span>Develop and maintain SOC documentation, playbooks, and standard operating procedures.</span></li> <li><span>Support vulnerability management initiatives and risk-based remediation efforts.</span></li> <li><span>Contribute to SOC maturity improvements aligned with industry frameworks and best practices.</span></li> </ul> <hr /> <h3><span>Security Operations</span></h3> <ul> <li><span>Overall 8+ years of experience of which 3+ years of experience in a Security Operations Center (SOC), Detection Engineering, Incident Response, or Cyber Defense role.</span></li> <li><span>Strong understanding of incident detection, triage, investigation, containment, and response processes.</span></li> <li><span>Experience analyzing security events from multiple data sources including endpoints, network devices, cloud platforms, and identity providers.</span></li> </ul> <h3><span>SIEM & Security Monitoring</span></h3> <p><span>Hands-on experience with one or more SIEM platforms:</span></p> <ul> <li><span>Splunk Enterprise Security</span></li> <li><span>Sentinel One Singularity Data Lake</span></li> <li><span>Microsoft Sentinel</span></li> <li><span>QRadar</span></li> <li><span>LogRhythm</span></li> <li><span>Elastic Security</span></li> <li><span>Google Chronicl</span></li> </ul> <span></span></li> </ul> <p><span><strong>Which skills are required:</strong></span></p> <ul> <li><span></span> <ul> <li><span>Palo Alto Networks</span></li> <li><span>Cisco Security products</span></li> <li><span>Fortinet</span></li> <li><span>Check Point</span></li> <li><span>Zscaler</span></li> </ul> <h3><span>Cloud Security</span></h3> <p><span>Experience monitoring and securing cloud environments:</span></p> <ul> <li><span>AWS</span></li> <li><span>Microsoft Azure</span></li> <li><span>Google Cloud Platform (GCP)</span></li> </ul> <p><span>Understanding of:</span></p> <ul> <li><span>Cloud-native security controls</span></li> <li><span>IAM</span></li> <li><span>Cloud logging and monitoring</span></li> <li><span>Cloud threat detection</span></li> </ul> <h3><span>Operating Systems</span></h3> <p><span>Strong working knowledge of:</span></p> <ul> <li><span>Windows Server</span></li> <li><span>Active Directory</span></li> <li><span>Microsoft Entra ID (Azure AD)</span></li> <li><span>Linux administration and security</span></li> </ul> <h3><span>Scripting & Automation</span></h3> <p><span>Experience developing automation using:</span></p> <ul> <li><span>Python</span></li> <li><span>PowerShell</span></li> <li><span>Bash</span></li> <li><span>C#</span></li> </ul> <p><span>Ability to:</span></p> <ul> <li><span>Consume APIs</span></li> <li><span>Automate security workflows</span></li> <li><span>Build integrations between security platforms</span></li> </ul> <h3><span>Security Frameworks & Methodologies</span></h3> <p><span>Knowledge of:</span></p> <ul> <li><span>MITRE ATT&CK</span></li> <li><span>Cyber Kill Chain</span></li> <li><span>NIST Cybersecurity Framework</span></li> <li><span>Incident Response Lifecycle</span></li> <li><span>Detection Engineering principles</span></li> </ul> <span></span></li> </ul> <p><span></span></p> <h1><span>Preferred Qualifications (Nice to Have)</span></h1> <ul> <li><span>Experience building and maintaining SOAR platforms such as:</span> <ul> <li><span>Cortex XSOAR</span></li> <li><span>Splunk SOAR</span></li> <li><span>Microsoft Sentinel Automation</span></li> <li><span>Tines</span></li> <li><span>Swimlane</span></li> </ul> </li> <li><span>Experience with threat hunting methodologies and purple team exercises.</span></li> <li><span>Experience with adversary emulation and detection validation tools.</span></li> <li><span>Familiarity with:</span> <ul> <li><span>AttackIQ</span></li> <li><span>SCYTHE</span></li> <li><span>Atomic Red Team</span></li> <li><span>Caldera</span></li> </ul> </li> <li><span>Experience supporting:</span> <ul> <li><span>Vulnerability management programs</span></li> <li><span>Exposure management initiatives</span></li> <li><span>Security control validation</span></li> </ul> </li> <li><span>Experience with cloud security tooling:</span> <ul> <li><span>Microsoft Defender for Cloud</span></li> <li><span>Wiz</span></li> <li><span>Orca</span></li> <li><span>Prisma Cloud</span></li> <li><span>Lacework</span></li> </ul> </li> <li><span>Familiarity with Identity Threat Detection and Response (ITDR) technologies.</span></li> <li><span>Experience supporting zero trust security initiatives.</span></li> <li><span>Exposure to DevSecOps, CI/CD security, and container security technologies.</span></li> <li><span>Knowledge of Kubernetes, Docker, and modern application security concepts.</span></li> <li><span>Experience working within regulated industries such as financial services, healthcare, or critical infrastructure.</span></li> </ul> <hr /> <h1><span>Certifications</span></h1> <p><span>Preferred certifications include:</span></p> <ul> <li><span>CompTIA Security+</span></li> <li><span>CySA+</span></li> <li><span>GCIH</span></li> <li><span>GCIA</span></li> <li><span>GCFA</span></li> <li><span>GMON</span></li> <li><span>CISSP</span></li> <li><span>SC-200 (Microsoft Security Operations Analyst)</span></li> <li><span>SC-100 (Microsoft Cybersecurity Architect)</span></li> <li><span>Splunk Certified Cybersecurity Defense Analyst</span></li> <li><span>CrowdStrike Certified Falcon Administrator</span></li> </ul> <hr /> <h1><span>Education</span></h1> <p><span>Bachelors degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.</span></p> <p><span></span></p> <p><span><strong>To be successful in this position, you will have the following:</strong></span></p> <ul> <li><span>Self-motivated and able to handle tasks with minimal supervision</span></li> <li><span>Superb analytical and problem-solving skills</span></li> <li><span>Excellent collaboration and communication (verbal and written) skills</span></li> <li><span>Outstanding organizational and time management skills</span></li> </ul> <p><span><strong>Company Benefits & Perks</strong></span></p> <ul> <li><span>Competitive salary, annual performance-based bonus, and stock grant</span></li> <li><span>Retirement plan 401(k) with competitive company match</span></li> <li><span>Excellent health and wellness benefits, including medical, dental, and vision benefits, and a company-paid medical healthcare premium</span></li> <li><span>Wellness screenings and assessments, health coaches, and counseling services through an Employee Assistance Program (EAP)</span></li> <li><span>Paid time off and a generous parental leave policy</span></li> <li><span>Daily company lunch allowance provided, and a fully stocked kitchen with healthy options for breakfast and snacks</span></li> <li><span>Corporate events, including team outings, dinners, volunteer activities, and company sports teams</span></li> <li><span>Education reimbursement and learning opportunities</span></li> <li><span>Modern offices with multi-monitor setups</span></li> </ul> <p> </p>

Back to blog

Other Jobs To Apply

Data Entry Clerk Work From Home - Part-Time Focus Group Participants (Up To $750/Week)

Remote Typing Jobs No Experience

Start ASAP | No Experience Needed | Remote Work From Home Opportunity

Entry-Level Data Entry Clerk - Part-Time / Full-Time (Remote)

Operations Manager - Santa Clarita, CA

RN Externship Summer 2018

Customer Service Representative Agent Work From Home - Part Time Focus Group Panelists

Cashier Assistant (Front End)

Full Time Sales Professional - Las Vegas Caesars Palace

Remote Sales Advisor

Remote Registered Nurse (Remote Patient Monitoring & Chronic Care Management)

amazon warehouse associate $15+/ Hour (Sign on Bonus)!

Certified Pharmacy Technician, Amazon Pharmacy

Start ASAP | No Experience Needed | Remote Work From Home Opportunity

Amazon Fulfillment Associate

Product Tester USA Based

Mom's Spaghetti Cook/Cashier

Entry-Level Data Entry Clerk (Remote)$45 per Hour

Remote Data Entry Clerk - Part Time - (Remote)

Product Specialist [3rd shift - 11p-8a] - REMOTE

Warehouse Associate - Loader/Unloader - 2nd Shift

REMOTE Client Representative – Work From Anywhere

United Airlines Reservations Representative (Remote)

Warehouse Lead - Outbound (Shipping)

Forklift Driver

Now Hiring: School Cafeteria Workers - Arlington, TX

Part-Time Center Associate 7462

Night Warehouse Associate (Entry Level)

Cashier Assistant (Front End) - Full-time / Part-time

Remote Service Desk Analyst or IT Technical Support Analyst

Area Maintenance Manager

Dallas Open Interviews | Call Center Representative | Hiring Immediately

Virtual Reader Services - Atlanta, GA

amazon warehouse associate $15+/ Hour (Sign on Bonus)!

Delivery Station Warehouse Associate

Delivery Driver (Amazon DSP)

flex driver

Retail Cashier/Customer Service

Food Service Assistant

EHS Specialist

Email Chat Support Jobs - No Prior Experience Required, Earn $25-$35 an Hour

Software Development Engineer, Prime Video on Fire TV

Part Time Customer Service Representative/Call Center Rep (Remote)

Dock Associate in Tracy, California ($20.00)

Clinical Quality PM, One Medical Senior Health

Weekend Remote Chat Support Jobs – Work Saturdays & Sundays Only | $25–$35/hr

Remote Customer Service Representative - Call Center | Kansas

Warehouse/Distribution: FT Order Filler/Associate/Fulfillment

Sr. Product Manager, Virtual Private Cloud, VPC

Airport Passenger Service Supervisor - JFK-AeroMex

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...