SOC Engineer / Detection Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Portugal
Remote
Entry level
Other
The Role
Detect, investigate, and respond to security incidents across endpoint, network, cloud, and log sources. Engineer and tune SIEM detection rules, correlation logic, dashboards, and alerting while reducing false positives and closing detection gaps. Lead post-incident reviews, root-cause analyses, and documentation. Collaborate with engineering and security teams on remediation, improve SOC workflows and playbooks, and support log-source onboarding and SIEM troubleshooting.
Summary Generated by Built In

As a SOC Engineer / Detection Engineer, you will be responsible for detecting, investigating, and responding to security incidents across our environment, while continuously improving how we detect and handle threats. You will work hands-on with our SIEM and incident response processes, and act as a key point of contact between the SOC and other engineering/security teams.


Depending on your profile, some of your responsibilities can include:


  - Incident Response: Lead and support the end-to-end response to security incidents, from detection through containment, eradication, and recovery.

  - Security Investigation: Conduct in-depth investigations into suspicious activity and alerts, correlating data across logs, endpoints, network, and cloud sources to determine root cause and impact.

  - Post-Mortems & RCAs: Drive post-incident reviews and root cause analyses (RCAs), documenting timelines, findings, and actionable follow-ups.

  - SIEM Engineering: Implement, tune, and maintain SIEM use cases, detection rules, correlation logic, and alerting to reduce false positives and close detection gaps.

  - SIEM Support: Provide ongoing support for the SIEM platform, including onboarding new log sources, troubleshooting data ingestion, and maintaining dashboards/reports.

  - Cross-Team Collaboration: Partner with Engineering, IT, and other Security teams to remediate findings, validate fixes, and share threat context.

  - Process Improvement: Identify gaps in detection, response, and documentation, and drive improvements to playbooks, runbooks, and SOC workflows.


**Must have:**


  - Incident Response: Hands-on experience handling security incidents, including triage, containment, and coordination across teams.

  - Investigation Skills: Strong analytical ability to investigate alerts and logs (SIEM, EDR, network, cloud) and determine root cause.

  - SIEM Expertise: Practical experience implementing and tuning detection rules/use cases in a SIEM (e.g., Splunk, Sentinel, Elastic, QRadar).

  - RCA & Documentation: Proven ability to write clear post-mortems, RCAs, and incident reports for both technical and non-technical audiences.

  - Communication: Ability to work cross-functionally with engineering and other security teams, translating findings into clear remediation steps.

  - Process Mindset: Track record of identifying and driving improvements to detection and response processes.

  - Linux/Unix proficiency and comfort working across cloud (e.g., AWS) log sources.


**Nice to have:**


  - Experience with detection engineering frameworks (e.g., MITRE ATT&CK) to map and prioritize coverage.

  - Familiarity with scripting/automation (Python, etc.) for detection or response tasks.

  - Understanding of compliance frameworks (ISO 27001, NIST, SOC2) as they relate to incident response.

  - Relevant certifications (e.g., GCIH, GCFA, Security+, SC-200, or SIEM-specific certifications).

Talkdesk is pioneering a new era of Customer Experience Automation (CXA), redefining how the world’s most admired brands interact with their customers through AI. Our global team of courageous innovators is customer-obsessed, building AI-first solutions that put empathy, trust, and transparency at the center of every interaction. We foster an inclusive culture where diverse perspectives drive our success and every voice belongs. Combining the stability of a global leader with the agility of a disruptor, Talkdeskers are empowered with the autonomy to drive meaningful impact, while giving back to the communities and environment around us.

Talkdesk has been recognized as a Leader in the Gartner® Magic Quadrant™ for Contact Center as a Service (CCaaS) and in the G2 Overall Grid® Reports for AI Agents and Contact Center. With seven consecutive years on the Forbes Cloud 100 and multiple AI Breakthrough awards, there has never been a more exciting time to join us as we shape the future of customer experience automation!

Work Environment and Physical Requirements:

Primarily office-environment work, extended periods of sitting or standing, computer-based work. Limited lifting, and equipment usage limited to computer-related equipment (keyboards, mouse, etc.)

The Talkdesk story hinges on empathy and acceptance. It is the shared goal among all Talkdeskers to empower a new kind of customer hero through our innovative software solution, and we firmly believe that the best path to success for our mission is inclusivity, diversity, and genuine acceptance. To that end, we will hire, promote, work along, cheer for, bond with, and warmly welcome into the Talkdesk family all persons without regard to ethnic and racial identity, indigenous heritage, national origin, religion, gender, gender identity, gender expression, sexual orientation, age, disability, marital status, veteran status, genetic information, or any other legally protected status.

Skills Required

  • Hands-on experience handling security incidents, including triage, containment, and cross-team coordination
  • Strong analytical investigation skills across SIEM, EDR, network, and cloud logs
  • Practical experience implementing and tuning SIEM detection rules and use cases
  • Ability to write post-mortems, root-cause analyses, and incident reports for technical and non-technical audiences
  • Strong cross-functional communication and ability to translate findings into remediation steps
  • Experience identifying and driving detection and response process improvements
  • Linux and Unix proficiency
  • Experience working with cloud log sources such as AWS
  • Experience with detection engineering frameworks such as MITRE ATT&CK
  • Familiarity with scripting or automation, such as Python
  • Understanding of ISO 27001, NIST, or SOC 2 compliance frameworks
  • Relevant certifications such as GCIH, GCFA, Security+, SC-200, or SIEM-specific certifications

Talkdesk Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Talkdesk and has not been reviewed or approved by Talkdesk.

  • Leave & Time Off Breadth Time off is described as generous, with unlimited PTO, paid sick days, and dedicated volunteer time available. Vacation allowances of at least three weeks and an 'unlimited time off' approach are offered, provided work responsibilities are met.
  • Healthcare Strength Healthcare coverage includes medical, dental, and vision for employees and dependents, alongside disability and life insurance. Coverage depth is highlighted as a core strength within the package.
  • Flexible Benefits Flexibility is emphasized through a remote-work program and work-from-home options. Compensation elements and perks such as commuter benefits and fitness stipends provide configurable support for different needs.

Talkdesk Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
1,661 Employees
Year Founded: 2011

What We Do

Talkdesk is a global customer experience leader for customer-obsessed companies. Our contact center solution provides a better way for businesses and customers to engage with one another. Our speed of innovation and global footprint reflect our commitment to ensure businesses everywhere can deliver better customer experiences through any channel, resulting in higher customer satisfaction, cost savings and profitability. Talkdesk CX Cloud is an end-to-end customer experience solution that combines enterprise scale with consumer simplicity. Over 1,800 innovative companies around the world, including IBM, Acxiom, Trivago, and Fujitsu partner with Talkdesk to deliver a better way to great customer experience. Learn more and request a demo at www.talkdesk.com.

Similar Jobs

Pfizer Logo Pfizer

Feasibility Strategic Analytics Lead (FSAL) - Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
33 Locations
121990 Employees
116K-193K Annually

Datadog Logo Datadog

Solutions Architect

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
3 Locations
6500 Employees

Mondelēz International Logo Mondelēz International

Senior Director, Global Supply Chain Excellence Program & Focused Improvement Lead

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
29 Locations
90000 Employees
174K-287K Annually

Drata Logo Drata

Enterprise Account Executive

Security • Software • Cybersecurity • Automation
Remote
26 Locations
600 Employees
194K-273K Annually

Similar Companies Hiring

T-Mobile Thumbnail
Other • Utilities
Bellevue, WA
89016 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
OmniCable Thumbnail
Other
Houston, Texas
815 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account