Senior Security Operations Engineer
Dispel
| Company | Dispel |
| Category | Engineering |
| Location | United States |
| Remote | Remote |
| Employment | Full-time |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 8 Apr 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (workable) |
Description
Location: Remote (US-based) About Dispel: Dispel is the fastest-growing cybersecurity company recognized in the 2025 Cybersecurity Excellence Awards. We deliver zero trust secure remote access and real-time data streaming for operational technology (OT) and industrial control systems (ICS). Our patented Moving Target Defense technology — referenced in NIST 800-172 — protects critical infrastructure for utilities serving 54 million+ people, manufacturers producing over 50% of US baby formula, and major defense contracts including a $950M IDIQ with the US Air Force. Why This Role Exists: Dispel is pursuing FedRAMP High authorization while simultaneously operating a commercial security program. We have a functioning SOC built on Google SecOps (Chronicle) and SentinelOne, but we need a senior IC who can take it from "stood up" to "operationally mature." You'll own the log ingestion pipeline end-to-end and drive material expansion of coverage across federal and commercial environments, including AWS, Azure, and Entra ID. This person will be the day-to-day technical owner of SOC operations, responsible for closing coverage gaps, building detections, maturing incident response, and providing senior technical direction to the existing SOC analyst. This is a hands-on-keyboard role with leadership expectations — you will not formally manage people, but you will set priorities, review deliverables, and drive execution across the SOC function. Requirements Key Responsibilities: SIEM/SOAR Operations (Google SecOps) Own the log ingestion pipeline end-to-end: identify gaps, build feeds, validate parsing, maintain coverage dashboards Close the federal logging gap and stand up commercial logging across AWS, Azure, Entra ID, and SaaS Activate and configure SecOps SOAR capabilities including Domain-Wide Delegation, marketplace integrations, and bidirectional response actions Build and maintain SOAR playbooks for major incident types such as phishing, malware, account compromise, lateral movement, and cloud-specific threats Develop and maintain operational dashboards for SOC metrics, alert volumes, MTTA/MTTR, and coverage status Manage Google SecOps RBAC Detection Engineering Build and deploy production detection rules mapped to MITRE ATT&CK within the first year Develop custom parsers for AWS-native security services including GuardDuty, Security Hub, Inspector, WAF, CloudTrail, and VPC Flow Logs Establish a detection lifecycle including proposal, testing, deployment, tuning, and retirement Conduct quarterly detection quality reviews to measure false positive rates, coverage gaps, and rule health Develop alert threshold optimization to reduce noise and analyst fatigue Endpoint Detection and Response (SentinelOne) Drive SentinelOne deployment across Azure VMs in commercial environments and all federal endpoints Configure and operationalize Cloud Funnel for log export into Google SecOps Build correlation rules between EDR alerts and SIEM detections Manage SentinelOne RBAC groups and policy configuration Coordinate with IT on agent deployment, health monitoring, and version management Incident Response Serve as senior escalation point for SOC incidents, ensuring investigations are thorough and reports include root cause, remediation actions, credential rotation plans, and follow-up timelines Improve MTTA and MTTR through process optimization, better tooling, and analyst development Lead quarterly tabletop exercises and after-action reviews Maintain and improve incident response runbooks for all major incident categories Integrate incident response workflows with Jira Service Management for tracking and escalation Vulnerability Management Operationalize monthly scanning cadence across all environments using tools such as Nessus, AWS Inspector, and Azure Defender Define and enforce remediation SLAs by severity: Critical