Skip to main content
Applied Information Sciences

SOC/NOC Engineer - Lead - Shift Work

RemoteUnited States only
Published
Role
Security
Experience
Lead
$120k–$181k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Lead SOC/NOC engineer with 7+ years in security/infrastructure operations for Azure and Microsoft 365. Deep SIEM experience (Microsoft Sentinel), incident response, and Azure resource management required. Must be U.S. citizen able to pass client background checks and willing to work 24x7 shift/on-call schedules.

Core skills

Microsoft 365Microsoft SentinelAzure

Required skills

Microsoft AzureSIEMMicrosoft DefenderAzure MonitorARM (Infrastructure as Code)TerraformPowerShellKQLAzure subscriptions managementIaaSPaaSVMsAKS

Optional skills

SC-200AZ-500AZ-104CySA+advanced forensics skillsAzure AutomationAzure BackupAzure Security Center

What you'll do

  • Serve as the senior point of escalation for challenging and complex security and infrastructure issue resolution across Azure and Microsoft 365 environments.
  • Provide technical leadership, mentorship, and guidance to SOC and NOC engineers, and support their ongoing training and development.
  • Own the design, configuration, and maintenance of SIEM, monitoring, and alerting capabilities (e.g., Microsoft Sentinel, Microsoft Defender, Azure Monitor).
  • Build and refine comprehensive security and infrastructure dashboards, alerts, and monitoring tools to gauge operational security and health.
  • Lead incident response for high-severity security events and major infrastructure outages, coordinating across teams through resolution and post-incident review.
  • Develop and maintain runbooks, playbooks, procedures, and reporting templates, and establish feedback loops to continuously improve them.
  • Drive automation and innovation to improve the efficiency of security and infrastructure operations activities.
  • Participate in and lead audit, compliance, accreditation, and authority-to-operate (ATO) support activities, ensuring gaps in coverage are identified and remediated.
  • Partner with client stakeholders, vendors, and third parties to enhance overall security posture and operational maturity within the managed environment.
  • Establish and enforce operational best practices, including patching, backup and restore, disaster recovery, and change management processes.
  • Provide clear, thorough written documentation for the operational procedures of the environments we support.
  • Lead shift coverage planning and participate in an on-call rotation to ensure continuous 24x7 operational SLAs.

What they require

  • 7+ years of experience in security operations, network and infrastructure operations, and/or systems engineering, including operating Microsoft Azure and Microsoft 365 platforms.
  • Demonstrated experience leading or mentoring engineers within a SOC, NOC, or converged operations center.
  • Deep, hands-on experience with SIEM configuration and maintenance and a variety of SOC/NOC engineering and administration tools.
  • Strong experience managing Azure subscriptions and resources across compute, storage, networking, and identity.
  • Proven ability to lead incident response and resolve fast-moving threats such as malware, phishing, and active vulnerabilities.
  • Strong engineering analysis, troubleshooting, and communication skills, including client-facing consulting ability.
  • Willingness to serve as senior escalation, participate in an on-call rotation, and perform off-hours maintenance as needed.
  • CompTIA Security+ certification.
  • U.S. citizenship and the ability to pass client background checks.
  • Preferred: Advanced Microsoft security and cloud certifications such as SC-200, AZ-500, AZ-104, or CySA+.
  • Preferred: Advanced forensics skills to evaluate current malware and phishing threats.
  • Preferred: Deep familiarity with Microsoft Sentinel and the Microsoft Defender suite.
  • Preferred: Experience with operations tooling such as Azure Monitor, Azure Automation, Azure Backup, Azure Security Center, and Azure Update Manager, applied to IaaS and PaaS services.
  • Preferred: Experience with automation and Infrastructure as Code (ARM, Terraform) and scripting (PowerShell, KQL).
  • Preferred: Experience supporting security audits, accreditation, and ATO processes in regulated or government environments.
  • Preferred: Experience in a managed services provider (MSP) or 24/7 enterprise operations environment.

Benefits

  • Employee Ownership: share in company achievements.
  • Continuous Learning: access to resources, training, and mentorship to support professional growth.
  • Inclusive Culture: a workplace where diversity is celebrated.
  • Mission-Driven Work: engage in projects that make a meaningful difference for clients and communities.
  • Competitive and fair compensation reflective of skills, experience, certifications, and location.

When you join AIS, you’re joining a mission-driven team that’s passionate about making a difference. You’ll work on projects that matter, alongside industry-leading experts, in an environment that fosters innovation, driving client success, and empowering our team to make a lasting impact. As an employee-owned company, we value collaboration, inclusivity, continuous growth, and shared success.

Government / DefenseMid-size

Details

Visa sponsorshipNo
$120k–$181k/yr