
Principal Security Operations Engineer
Digital Turbine, Inc.2 months ago
Responsibilities
- Serve as the primary technical authority for the SOC ecosystem and cloud threat detection strategy.
- Optimize and manage the relationship with a Managed Security Services Provider, including detection quality, response speed, and continuous tuning.
- Lead complex incident investigations across GCP, AWS, and containerized workloads, including triage, analysis, containment, and remediation.
- Design, maintain, and tune detection and automation use cases using SIEM, SOAR, and log management platforms.
- Operationalize CrowdStrike, Orca Security, and related security platforms to improve visibility and protection coverage.
- Develop and test incident-response playbooks and threat-hunting methodologies aligned with MITRE ATT&CK.
- Plan and execute tabletop exercises and business continuity and disaster recovery drills.
- Define SOC performance metrics such as MTTD and MTTR and communicate actionable insights to leadership and technical stakeholders.
- Collaborate with DevOps, application engineering, GRC, and legal teams on operational security and compliance.
- Contribute to vendor selection, tooling evaluation, and threat intelligence initiatives.
- Mentor peers and cross-functional partners on detection engineering, incident response, and cloud security.
Requirements
- 12+ years of cybersecurity experience with deep expertise in security operations, threat detection, or incident response in global enterprise or SaaS environments.
- Significant hands-on experience developing and managing SOC functions for GCP and AWS, including cloud logging, monitoring, and automation.
- Strong familiarity with MSSP models and measuring and improving security service quality through engineering insight and data.
- Proficiency with SOC tooling such as CrowdStrike, Orca, SIEM/SOAR platforms, and related telemetry and automation tools.
- Deep understanding of adversary tradecraft, cloud attack paths, and detection engineering frameworks.
- Experience supporting or interfacing with SOC 2, ISO 27001, or SOX compliance programs.
- Excellent analytical and communication skills, including presenting technical findings and risks to engineers and executives.
- Advanced security certifications such as CISSP, GCIH, GCFA, CISM, or CCFR are highly desirable.
- Google Cloud certifications such as Professional Cloud Security Engineer or Professional Cloud Architect are preferred.
Benefits
- Hybrid work environment; candidates must be local to the posting location.
- Bonus plan and equity plan.
- 401(k).
- Unlimited paid time off.