AL
Senior Security Operations Engineer
Artech LLC
- 🇺🇸 United States
- On-site
- Senior
- 6 hours ago
- Defender
- Incident Response
- Network Security
- triage
- Threat Intelligence
- Zscaler
- Wiz
- PagerDuty
- Jira
- Confluence
- IAM
- SIEM
- EDR
- Azure
- Incident Management
- PowerShell
- Python
- JSON
- Logic Apps
- DLP
- AI
- CISSP
- GCIH
- GCIA
- GCFA
6 hours ago
The opportunity
Scout Motors is carrying forward the heritage of an iconic American vehicle while building the next generation of all-electric trucks and rugged SUVs. The Senior Security Operations Engineer will be a hands-on technical leader within the Security Operations team, helping protect Scout personnel, enterprise technology, cloud services, applications, engineering environments, and business operations. This role is ideal for an experienced defender who can investigate deeply, communicate clearly, improve detections and automation, and take ownership when an incident becomes urgent.You will serve as a senior escalation point for security monitoring and incident response, work closely with Scout’s managed detection and response partner, and help mature the people, processes, and technology behind a growing SOC. The position combines day-to-day operations with program improvement across threat detection, incident response, digital forensics, security automation, exposure management, and operational reporting.
What you’ll do
Become part of an iconic brand that is set to revolutionize the all-electric pick-up truck and rugged SUV marketplace by achieving the following:- Lead complex security investigations from initial alert validation through scoping, containment recommendations, eradication, recovery validation, documentation, and lessons learned.
- Serve as a senior escalation point for Client Sentinel, Client Defender XDR, endpoint, identity, email, cloud, SaaS, and network security alerts.
- Coordinate with Scout’s managed detection and response provider to ensure 24/7 monitoring, high-quality triage, timely escalation, complete case documentation, and effective handoff to internal responders.
- Participate in the Security Operations on-call rotation and respond to high-priority events outside normal business hours, including nights, weekends, and holidays.
- Develop, tune, test, and maintain analytics rules, hunting queries, workbooks, watchlists, automation rules, and investigation content using Kusto Query Language (KQL).
- Build and improve SOAR and workflow automation that enriches incidents, reduces repetitive analyst work, accelerates containment, and maintains appropriate human oversight for high-impact actions.
- Perform threat hunting across endpoint, identity, email, cloud, network, and application telemetry using current threat intelligence, indicators of compromise, attacker behaviors, and incident trends.
- Administer and optimize core security operations capabilities, including Client Sentinel, Client Defender XDR, Client Defender for Endpoint, Defender for Office 365, Defender for Identity, Client Entra ID security signals, and related integrations.
- Investigate and coordinate response across complementary platforms such as Zscaler, Abnormal Security, Wiz, PagerDuty, Jira, Fresh service, and Scout’s managed security services.
- Create and maintain incident response playbooks, investigation procedures, escalation paths, evidence-handling guidance, threat-hunting content, and operational runbooks in Confluence.
- Collect, preserve, and analyze digital evidence when required; support endpoint and cloud forensic activities while maintaining clear documentation and chain-of-custody practices.
- Partner with IT Operations, IAM, Cloud and Platform Engineering, DevSec-Ops, GRC, Legal, Privacy, HR, Physical Security, Communications, business owners, and external responders during incidents and security improvement initiatives.
- Support high-profile and zero-day vulnerability response by assessing exposure, hunting for exploitation, coordinating remediation owners, tracking risk, and communicating status.
- Help operationalize exposure and cloud-security findings by correlating Wiz and other vulnerability data with asset context, active threats, and business impact.
- Produce clear incident updates, post-incident reports, operational metrics, and leadership-ready summaries that explain risk, impact, decisions, and recommended actions.
- Mentor analysts and partner teams, lead knowledge-sharing sessions, and raise the overall technical quality and consistency of Security Operations.
- Identify recurring failure patterns and convert lessons learned into improved detections, controls, playbooks, automation, logging, and response readiness.
- Participate in tabletop exercises, purple-team activities, detection validation, and other readiness exercises relevant to enterprise, cloud, manufacturing, supplier, and automotive environments.
What you’ll bring
We expect all Scouts to have integrity, curiosity, resourcefulness, and a growth mindset. You’ll be comfortable with change, able to operate in a fast-paced environment, and ready to collaborate across technical and business teams. Here’s what else you’ll bring:- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or related field, or equivalent professional experience.
- 5+ years of progressive experience in security operations, incident response, threat detection, digital forensics, security engineering, or a closely related discipline.
- Demonstrated ability to lead complex technical investigations and make sound decisions with incomplete or rapidly changing information.
- Hands-on experience with a modern SIEM and EDR/XDR platform. Strong Client Sentinel and Client Defender experience is preferred.
- Proficiency with KQL or a comparable security-query language, including log correlation, detection development, threat hunting, troubleshooting, and dashboard creation.
- Experience investigating identity, endpoint, email, cloud, SaaS, and network threats, including account compromise, phishing and social engineering, malware, ransomware, insider risk, data loss, and third-party compromise.
- Working knowledge of Client Entra ID, Client 365 security, Azure, and AWS security concepts and telemetry.
- Experience with incident management, case management, and collaboration platforms such as PagerDuty, Jira, Fresh service, Teams, and Confluence.
- Understanding security automation and orchestration, APIs, scripting, and repeatable workflow design. PowerShell, Python, JSON, or Logic Apps experience is valuable.
- Knowledge of vulnerability and exposure management, cloud security posture management, risk-based prioritization, and remediation coordination.
- Familiarity with forensic collection and analysis, evidence preservation, timeline reconstruction, and clear investigative reporting.
- Ability to communicate technical findings to engineers, business owners, legal and privacy partners, and senior leadership without overstating certainty.
- Strong documentation habits, attention to detail, and a bias toward repeatable, auditable processes.
- Ability and willingness to work in person in Charlotte, North Carolina and participate in a rotating on-call schedule that includes nights, weekends, and holidays.
- Experience in implementing agentic capabilities within the SOC environment.
Preferred qualifications
- Experience operating security capabilities in a high-growth, automotive, manufacturing, engineering, or technology organization.
- Experience working with an MDR/MXDR or MSSP and improving provider performance, escalation quality, and operational integration.
- Hands-on experience with Zscaler, Abnormal Security, Wiz, cloud workload protection, DLP, threat intelligence, or malware-analysis platforms.
- Experience building or tuning SOAR playbooks, Logic Apps, API integrations, and AI-assisted investigation workflows.
- Experience supporting tabletop exercises, major incidents, crisis-response bridges, and post-incident improvement programs.
- Relevant certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, SC-200, AZ-500, Security+, or equivalent demonstrated expertise.
Location and travel expectations
This is an in-person role based at Scout Motors headquarters in Charlotte, North Carolina.Regular on-site presence is required to support collaboration, incident readiness, and operational coordination. The role may require travel to other Scout locations, production or engineering sites, partner locations, training events, and incident-response activities from time to time.On-call and incident-response expectations
This position is part of a rotating Security Operations on-call schedule.The successful candidate must be able to receive and respond to urgent security escalations outside normal business hours, including nights, weekends, and company holidays. During significant incidents, the role may require extended response coverage, participation in incident bridges, clear status updates, and coordination with internal and external responders until an effective handoff or stabilization is achieved.How success will be measured
- Consistent, high-quality investigation and escalation of security incidents.
- Improved detection fidelity, logging coverage, automation, and response speed.
- Clear case documentation, incident communications, and post-incident follow-through.
- Effective partnership with the MDR provider and Scout technical teams.
- Measurable reductions in recurring alert noise, investigation friction, and operational gaps.
- Practical improvements to playbooks, detections, dashboards, integrations, and team readiness.
Scout values in action
You will help Scout move securely and confidently by leading with respect, figuring it out, stepping up, moving with intent, going together, and making the work matter. This role requires calm judgment, technical depth, curiosity, and a collaborative approach to protecting a company that is building something new.Senior Security Operations Engineer · Artech LLC