Sr. SOC Engineer
Dallas, IA - USA
Job Summary
Zimperium is the world leader in mobile security purpose-built to protect the modern mobile enterprise. Trusted by leading organizations and governments our AI-driven platform delivers real-time on-device protection for mobile applications and devices. We help organizations stay ahead with proactive defense against evolving threatsincluding mobile-targeted phishing (mishing) malware app vulnerabilities and zero-day exploits. Our mission is to empower organizations to operate securely and confidently in todays dynamic digital environment.
We are looking for a Sr. SOC Engineer to own and operate our Google SecOps platform end-to-end. You will architect log ingestion author threat detection rules design agentic AI-powered triage and response automation integrate our CNAPP platform with security operations workflows and lead investigative response to high-severity incidents. This is a hands-on engineering role: you will execute the work yourself not manage others execution. You will own the detection strategy platform architecture automation design and incident response quality. You will be the person your team calls when a new log source needs to be ingested and routed when detection rules arent firing or when a complex incident demands technical leadership.
You will own the outcomes and drive how the SOC operates. You will work in close collaboration with our DevOps Cloud Security and Product Security teams. You are expected to operate independently make architectural decisions and have the judgment to act without direction. Your technical and strategic decisions will drive Zimperiums security posture directly.
Location: Dallas TX preferred
8 years in security operations threat detection or incident response with at least 4 years in a SIEM/SOC engineering or detection engineering role.
Deep hands-on experience with at least one major SIEM platform (Splunk ELK Chronicle/Google SecOps Sentinel Sumo Logic). Production experience with detection authoring and tuning.
Strong understanding of log types and sourcesOS logs application logs network flow DNS proxy endpoint telemetry CNAPP/runtime security events. Ability to interpret and normalize heterogeneous data.
Experience building or tuning threat detection rules and correlation logic. Working knowledge of attack frameworks (MITRE ATT&CK) and how to operationalize them.
Proficiency in at least one scripting/programming language (Python Go Bash) sufficient to build and maintain automation not just modify examples.
Experience integrating security toolsAPIs webhooks orchestration platforms (Zapier Make native SOAR). Comfortable debugging API calls and data flow.
Hands-on incident investigation experienceevidence collection root cause analysis timeline reconstruction scope determination.
Familiarity with mobile threat detection CNAPP or endpoint threat detection. Understanding of how mobile/app security signals differ from infrastructure security.
Strong written and verbal communicationability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.
Proven ability to operate independently take ownership and make decisions with sound judgment to non-technical stakeholders and brief executives on incidents and trends.
Proven ability to operate independently take ownership and make decisions with sound judgment.
Strong written and verbal communicationability to explain technical findings to non-technical stakeholders and brief executives on incidents and trends.
CNAPP & SecOps Integration. Orchestrate data flow from Zimperiums CNAPP platform into Google SecOps and other security tools. Build and own integrations to coordinate threat notifications ensure consistent severity assignment and enable unified response across mobile and cloud/infrastructure security.
Google SecOps Platform Engineering. Own and maintain Google SecOps as the operational hubSOAR workflows alert routing logic case management automation rules integrations with ticketing systems (Jira) notification channels and escalation procedures. You make architectural decisions on how alerts flow through the system and how the team works.
Investigative Leadership. Lead investigations into high-severity and complex incidents. Conduct root cause analysis determine scope and impact coordinate containment and remediation and produce clear post-incident reports. You own the investigative strategy and mentor junior analysts on tradecraft.
SOC Automation & Tooling. Write or adapt tools and scripts (Python Go Bash) to automate SOC workflowsbulk event analysis data enrichment response actions reporting. Integrate third-party tools and APIs into Google SecOps workflows. You own the efficiency and scale of the SOCs technical operations.
Metrics & Reporting. Define instrument and own SOC KPIsdetection latency mean time to respond (MTTR) investigation duration false positive rate automation coverage. Build dashboards and reports for leadership. You are accountable for continuous improvement in SOC performance.
On-Call & Incident Response. Serve as incident commander or key investigator for high-priority events. Drive incidents to root cause not just closure. You own the incident response quality.
Compliance & Audit Support. Generate evidence and documentation for security audits (ISO 27001 FedRAMP). Translate technical findings into auditor-readable format.
Prior experience with Google Chronicle Google SecOps or similar cloud-native SIEM platforms.
Experience with AI/ML-based alert triage anomaly detection or automated incident response.
Experience operating in regulated or compliance-heavy environmentsFedRAMP DoD PCI-DSS HIPAA.
Hands-on experience with mobile threat detection mobile app security or container/Kubernetes runtime security.
Experience with threat modeling vulnerability disclosure coordination or security research.
Relevant certifications (GCIH ECIH OSINT GIAC certifications or vendor-specific: Google Cloud Security AWS Security etc.).
Prior DevSecOps security engineering or cloud security experience. A background in building systems shows a level of thinking we value.
Zimperium is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex including sexual orientation and gender identity national origin disability protected veteran status or any other characteristic protected by applicable federal state or local law.
Required Experience:
Senior IC
About Company
Zimperium is the only mobile security platform purpose-built for enterprise, securing both mobile devices and applications so they can securely access data.