Information Security Engineer II, SOC - Provo
Provo, Utah, United States
Qualtrics
The Qualtrics Platform and our specialized AI uncovers insights, prioritizes actions, and empowers everyone to improve customer & employee experiences.When you join one of our teams, you’ll be part of a nimble group that’s empowered to set aggressive goals and move fast to achieve them. Strategic risks are encouraged and complex problems are solved together, by passing the mic and iterating until the best solution comes to light. You won’t have to look to find growth opportunities—ready or not, they’ll find you. From retail to government to healthcare, we’re on a mission to bring humanity, connection, and empathy back to business. Join over 5,000 people across the globe who think that’s work worth doing. Information Security Engineer II, SOC - Provo Why We Have This Role Qualtrics is growing exponentially and that growth means constantly finding and eradicating threats to our systems. We must continuously evaluate how we secure systems, identify potential threats, and implement alerts and tooling necessary that will help us maintain a strong security posture at scale. We are looking for an experienced engineer to join our security operations center / incident response team who can work with others across the organization, react to alerts, hunt for threats, respond to incidents, and create and implement technical solutions that improve our ability to identify, stop, and eliminate potential threats. How You’ll Find Success
- Ability to respond to emergency calls during non-business hours, as needed.
- Possess the ability to react quickly, decisively, and deliberately.
- Excellent verbal and written communication skills.
- Proactive, self-managed, and able to interface well with interdisciplinary teams across the organization, including executive leadership.
- Your natural curiosity of discovering the unknown drives your success.
- You’ll increase your technical expertise by operating a wide range of technologies to solve modern security problems in a fast paced SaaS Environment.
- You’ll improve your security expertise by responding to real-world security threats across the Qualtrics enterprise and application.
- You’ll learn to reduce security risks by collaboratively partnering with a globally distributed team.
- You’ll gain expertise around the Qualtrics XM Platform.
- Performs Level 2/3 SOC/IR and shift lead duties as a part of a 24/7 security incident watch team in a multi-timezone follow-the-sun rotation.
- Provides leadership, mentoring, and training to SOC/IR team personnel and to other Qualtrics stakeholders and the Qualtrics Information Security Team.
- Provides onboarding training and coaching for junior SOC/IR Engineers.
- Performs network and endpoint forensics to establish attack scope and root cause analyses.
- Ensures communication and escalation of security activities to leadership.
- Performs additional analysis of escalations from SOC engineers and conducts incident review.
- Leads development of workflow automation to lower response time and eliminate lengthy response times
- Develop and improve attack remediation strategies, incident handling processes, standard operating procedures, playbooks, and automations.
- Identifies alerting gaps and develops strategies to increase threat detection coverage.
- Support FedRamp, ISO27001, SOC, HITRUST, and other audit activities for security operations and incident response.
- Minimum of a BS degree, preferably in IT Engineering, Computer Science, or any other IT-related field of study.
- 3-5 years of experience in the Information Security field.
- 2-5 years of prior SOC and/or Incident Response experience.
- Experience performing analysis utilizing IDS/AV/Firewall consoles.
- Experience performing analysis using EDR technologies.
- Experience with cloud computing and AWS services.
- Experience with Multiple Operating Systems with a System Administrator level skill set on MacOS and Linux.
- Strong understanding of networking and associated protocols.
- Development skills including scripting (e.g. Python, shell scripting).
- Experience with MITRE ATT&CK and Cyber Kill Chain, including Tactics, Techniques, and Procedures (TTPs).
- Knowledge of STIX/TAXII, SIGMA, DISA STIGs.
- In Qualtrics SOC, all team members know how to code - we don't have pure "Security Analyst" positions. We believe that through automation we can detect and respond to threats better than typical SOCs.
- Innovation at Our Core: Our Security Engineering team embraces change and thrives on solving complex challenges. We value experimentation, continuous learning, and push the boundaries of conventional security practices.
- Collaborative Environment: We believe in the power of teamwork and foster open communication across the team and the wider organization. Your ideas will be heard, and your collaboration will be essential.
- Data-Driven Approach: We rely on data-driven insights to inform our security strategies, measure effectiveness, and continuously improve our posture.
- Growth Mindset: We are committed to your professional development. You'll have opportunities to expand your expertise, contribute to high-visibility projects, and advance your career in cybersecurity.
- Work life integration is deeply important to us - we have frequent office events, team outings, and happy hours
- We take pride in our offices design aiming at cultivating creativity from our rooftop views to an open and collaborative work space
- On top of the standard benefits package (medical, dental, vision, life insurance, etc) we provide snacks, drinks, and free lunches in our office
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation AWS Cloud Computer Science Cyber Kill Chain DISA EDR FedRAMP Firewalls Forensics HITRUST IDS Incident response ISO 27001 Linux MacOS MITRE ATT&CK Polygraph Python SaaS Scripting SOC STIGs Threat detection TTPs
Perks/benefits: Career development Health care Insurance Medical leave Startup environment Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.