JOB SUMMARY: The IS Cyber SOC Engineer III is a highly skilled senior role responsible for the design, deployment, and optimization of our security detection and response infrastructure in support of a 24/7 SOC to support its operational efficiency. This role will ensure the defensive stack, including SIEM, SOAR, EDR, NDR, and DLP, is functioning at peak performance across a hybrid environment consisting of cloud workloads and on-premises locations. This role focuses on ensuring the organization's detection stack is automated, scalable, and resilient against modern adversaries. This position will work closely with the Security Platform Operations Team, Cloud Security Engineering, Network Engineering, and Cloud and Enterprise Architecture Teams to maintain the efficiency and effectiveness of the SOC's tools and environment and serve as a liaison during product evaluations, implementations, and technology refresh projects. This position is responsible for representing the needs of the SOC to ensure effective operational continuity and serves as the escalation contact for product support. Additionally, the role provides direct assistance to the SOC during security incidents. This position plays a vital role in establishing and maintaining a corporate-wide information security engineering and architecture program to ensure information assets are adequately protected and that a framework is implemented which upholds current standard operating procedures for technology platforms and processes. Additionally, this position provides leadership in the definition, implementation, evaluation, and maintenance of controls to protect systems and applications in accordance with security requirements. The SOC Engineer III holds key responsibility for providing feedback to the Security Operations Center (SOC) Manager regarding the security architecture framework to ensure systems lifecycle activities remain secure through development, acquisition, certification, and accreditation processes for all information assets. The position requires staying current on security threats, trends, and technologies while managing and supporting existing security solutions, evaluating, designing, and implementing new security controls, and helping the organization meet security objectives.
ESSENTIAL DUTIES AND RESPONSIBILITIES- Subject matter expert in their field, driving resource allocations, accountability for deliverables, and exception management documentation.
- Monitor and assist in maintaining a hybrid visibility architecture.
- Support SOC monitoring personnel in building and optimizing detection logic for threat hunting and SOAR playbooks to automate repetitive tasks.
- Oversee the health and tuning of SOC tools.
- Serve as a technical leader and escalation point for SOC tool failures and provide product SME support during incident investigations.
- Participate in writing and implementing security policies, standards, and procedures; continuously improve the effectiveness of the corporate security program.
- Participate in on-call and shift work supporting SOC operations, including incident response.
- Monitor regulatory and legislative changes impacting the protection of regulated data (SOX, GLBA, etc.).
- Govern security metrics demonstrating security program effectiveness, reduced incidents, positive audit outcomes, and program cost reductions.
- Support research and development of mitigation strategies against emerging threats.
- Lead technical and non-technical projects, including tracking, issue management, and follow-up.
- Provide short-, medium-, and long-term analysis of internal and external threat, protection, and response data.
- Monitor and validate implementation of security practices required to comply with GLBA, PCI-DSS, HIPAA, SOX, and other regulations.
- Provide leadership support in planning, designing, and evaluating privacy and security-related projects.
- Adhere to all applicable federal and state laws and regulations, including anti-money laundering requirements (Bank Secrecy Act, USA PATRIOT Act, etc.).
- Adhere to Bank policies and procedures and complete required training.
- Identify and report suspicious activity.
Education
- Bachelor's degree in Cybersecurity, Computer Science, Computer Information Systems, Information Security Management, or related field preferred.
- Equivalent experience: 4 additional years of professional engineering experience (10-12 years total) in lieu of a degree.
Experience
- 8+ years of experience in information technology and information security (IT/IS).
- 5+ years in Security Engineering, Network Engineering, SOC, TOC, and/or NOC Operations.
- 3+ years managing security policies within cloud and on-premises environments preferred.
- Experience with SOC automation workflows and AI tools.
- Experience with Detection Engineering.
- Experience with cloud platforms, IAM, and VPC security.
- Experience with digital forensics and incident response.
- Experience with Active Directory/Entra ID, Group Policy, and network security.
- Experience with SIEM and EDR platforms.
- Experience with Wiz, Netskope, or equivalent CSPM solutions.
- Experience with firewalls, WAFs, and proxy/VPN technologies.
- Experience creating technical diagrams.
- Experience creating and maintaining runbooks and playbooks.
- Experience with policy management.
- Experience curating threat intelligence feeds.
- Experience with log analysis.
- Experience with threat hunting.
- Proficiency in PowerShell, YAML, Python, and Infrastructure as Code tools preferred.
- Experience using Snowflake or equivalent security data lake technologies preferred.
- Experience with container security (e.g., Kubernetes) preferred.
- Experience leading projects preferred.
- Experience within a financial institution preferred.
Licenses and Certifications
Preferred certifications include:
- CISSP
- CCSP
- CISA
- CISM
- GCDA
- OSCP
- Advanced security, cloud, network, or platform-related certifications
Knowledge, Skills, and Abilities
- Ability to understand long-term organizational strategies and incorporate security vision into planning.
- Ability to formulate recommendations, present solutions, and develop implementation plans.
- Strategic thinking with the ability to translate strategy into action.
- Ability to initiate, lead, and manage risk management, compliance, and security governance activities.
- Strong technical troubleshooting skills.
- Broad understanding of IAM, cybersecurity, governance, risk, compliance, security operations, and business processes.
- Current knowledge of cybersecurity threats, trends, and technologies.
- Ability to influence and manage expectations with senior leadership.
- High degree of initiative and dependability.
- Ability to effectively collaborate across business and technical teams.
- Strong written, verbal, and presentation communication skills.
- Strong teamwork and cross-functional collaboration skills.
- Strong project management and leadership abilities.
- Strong organizational, prioritization, and detail orientation skills.
- Working knowledge of Microsoft Word, Excel, PowerPoint, and Visio.
- Advanced knowledge of information security architecture, technologies, design and implementation, policy development, risk assessments, internet security, and networking.
Additional Information
- Candidates residing within BankUnited's geographic footprint may be given preference.
