Staff SOC Engineer - Security Telemetry & Detection Platforms

Posted Yesterday
Hiring Remotely in Missouri, USA
Remote or Hybrid
127K-189K Annually
Senior level
Insurance
The Role
Build, operate, and improve enterprise security telemetry and detection platforms across hybrid, cloud, and on-premises environments. Engineer SIEM, EDR, SOAR, and log pipelines; develop detection content; implement access controls, integrations, validation, and observability; troubleshoot visibility gaps; and support incident response. The role also documents architectures, evaluates emerging technologies, contributes to AI monitoring, and partners across security, infrastructure, architecture, and product teams.
Summary Generated by Built In

You desire impactful work.
 

You’re RGA ready

RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.

The Staff SOC Engineer - Security Telemetry & Detection Platforms is a hands-on security engineering role responsible for building, operating, and continuously improving enterprise security telemetry and detection platforms. This role ensures high-quality visibility and detection are embedded throughout operations and delivery lifecycles - applying secure by design principles to data collection, transformation, storage, and alerting across hybrid, cloud native, and on premises environments. The Staff SOC Engineer proactively anticipates telemetry gaps, translates detection requirements into actionable engineering work, and operationalizes controls that are scalable, resilient, and measurable. Through close collaboration with security operations, architecture, infrastructure, and product teams, this role advances SOC maturity and enables adaptive defenses that support business growth and regulatory compliance.

Principle Duties

  • Administer and engineer improvements to enterprise security telemetry and detection platforms- including SIEM, EDR, SOAR, and data pipeline solutions - ensuring reliability, performance, and cost efficiency.
  • Implement secure by default telemetry patterns and logging standards across operating systems, cloud, and network data sources.
  • Design, build, and maintain data pipelines (Routes, Pipelines, Packs) for secure, cost managed, and high throughput log routing, enrichment, filtering, and transformation into SIEM, archive, and other destinations.
  • Engineer SIEM content (SPL searches, correlation rules, alerts, dashboards, data models, CIM mapping, RBA where applicable) with an emphasis on signal quality, performance, and SLO/KPI driven cost control
  • Define and maintain role-based access controls (RBAC), least privilege models, and user provisioning across telemetry and detection platforms to enable auditable operations.
  • Contribute to integration and automation across SOC tooling and enterprise systems (e.g., Tines, cloud native logging in AWS/Azure/GCP, threat intel feeds, ticketing/ITSM) to streamline detection, enrichment, and response workflows.
  • Author and maintain explicit documentation - including system design documents, reference implementations, runbooks, and technical decision records capturing rationale, architecture, and operational procedures.
  • Apply tacit understanding of SIEM/EDR behavior, data schemas, and pipeline constraints to troubleshoot complex issues, reduce noise, and close visibility gaps.
  • Participate in incident response by developing targeted searches, conducting log analysis, identifying root causes, and providing platform/tooling expertise during high severity events.
  • Implement and continuously improve control validation (data quality checks, parsing/field extraction tests, content regression tests) and observability (health monitors, capacity, latency, backlog, and error metrics).
  • Evaluate emerging telemetry sources, detection approaches, and vendor capabilities; build proofs of concept to assess fit, security posture, and operational impact.
  • Support identity, access, and privilege strategies within SOC platforms (API tokens, service accounts, secrets management, SSO/SAML/OIDC) aligned to enterprise guardrails.
  • Collaborate in post incident reviews and resilience improvements, translating findings into backlog items for pipeline hardening, new log sources, or content tuning.
  • Contribute to responsible logging and monitoring for AI enabled applications and platforms (e.g., model/service telemetry, prompt/audit logs), integrating risks and controls into detection strategy.
  • Serve as the security telemetry and detection engineering representative for Global Security Office in technical forums, ensuring platform considerations are aligned with enterprise strategies and governance.
  • Perform other duties as assigned.

Qualifications

Education:

  • Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience – Required
  • Master’s degree in Arts/Sciences (MA/MS) or professional industry certification Preferred

Work Experience:

  • 6+ years of progressive experience in security/infrastructure engineering or SOC engineering focused on SIEM/EDR, telemetry pipelines, and detection content
  • Demonstrated success deploying and operating SIEM, EDR, SOAR, and data pipeline solutions at enterprise scale, including RBAC, API integrations, and platform hygiene
  • Hands‑on experience engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources
  • Strong technical background and tacit understanding of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning to reduce ingest volume and improve signal to noise

Licenses & Certifications:

  • Relevant platform certifications (e.g., Splunk Core/Cloud, Cribl Certified Observability Engineer, CrowdStrike CCFA/CCFR) – Preferred
  • Security certifications (e.g., CISSP, GSEC, GCDA, Cloud+) – Preferred

Skills & Abilities

  • Proven ability to collaborate across security operations, architecture, infrastructure, and product teams; strong stakeholder communication and documentation skills – Required
  • Ability to map and document complex systems and processes, including data lineage and schema/field mappings – Required
  • Familiarity with NIST frameworks, MITRE ATT&CK, and secure by design practices; experience with control validation and metrics/KPIs for continuous improvement – Required
  • Experience supporting 24/7 SOC operations, including on call participation and multi region ingestion scenarios – Required
  • Advanced analytical and problem-solving skills; competency with analysis and diagramming tools (e.g., Lucidcharts, Visio, Excel) – Required
  • Experience integrating security telemetry into CI/CD pipelines and applying version control, testing, and staged releases for detections and pipeline changes – Preferred
  • Proficiency in automation and scripting (e.g., Python, PowerShell) and experience with SOAR (e.g., Tines) and infrastructure as code (e.g., Terraform) - Preferred

#LI-HYBRID #LI-MC1

What you can expect from RGA:

  • Gain valuable knowledge from and experience with diverse, caring colleagues around the world.

  • Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.

  • Join the bright and creative minds of RGA, and experience vast, endless career potential.

We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.

Compensation Range:

$126,710.00 - $188,840.00 Annual

Base pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits.

RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.

Skills Required

  • Bachelor's degree in arts/sciences or equivalent experience
  • 6+ years of progressive experience in security engineering, infrastructure engineering, or SOC engineering focused on SIEM, EDR, telemetry pipelines, and detection content
  • Experience deploying and operating SIEM, EDR, SOAR, and data pipeline solutions at enterprise scale
  • Experience with RBAC, API integrations, and platform hygiene
  • Hands-on experience engineering data ingestion pipelines and normalizing logs from operating systems, AWS, Azure, and network sources
  • Technical knowledge of detection engineering, OCSF modeling, SPL optimization, CIM mapping, and content tuning
  • Ability to collaborate across security operations, architecture, infrastructure, and product teams
  • Strong stakeholder communication and documentation skills
  • Ability to map and document complex systems and processes, including data lineage and schema or field mappings
  • Familiarity with NIST frameworks, MITRE ATT&CK, secure by design practices, control validation, and continuous-improvement metrics
  • Experience supporting 24/7 SOC operations, including on-call participation and multiregion ingestion scenarios
  • Advanced analytical and problem-solving skills
  • Competency with analysis and diagramming tools such as Lucidcharts, Visio, and Excel
  • Master's degree in arts/sciences or professional industry certification
  • Relevant platform certifications such as Splunk Core or Cloud, Cribl Certified Observability Engineer, or CrowdStrike CCFA or CCFR
  • Security certifications such as CISSP, GSEC, GCDA, or Cloud+
  • Experience integrating security telemetry into CI/CD pipelines and applying version control, testing, and staged releases
  • Proficiency in automation and scripting, such as Python or PowerShell
  • Experience with SOAR, such as Tines, and infrastructure as code, such as Terraform
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chesterfield, MO
3,164 Employees
Year Founded: 1973

What We Do

Reinsurance Group of America, Incorporated (RGA), a Fortune 500 company, is among the leading global providers of life reinsurance and financial solutions, with approximately $3.5 trillion of life reinsurance in force and assets of $92.2 billion as of December 31, 2021. Founded in 1973, RGA today is recognized for its deep technical expertise in risk and capital management, innovative solutions, and commitment to serving its clients. With headquarters in St. Louis, Missouri, and operations around the world, RGA delivers expert solutions in individual life reinsurance, individual living benefits reinsurance, group reinsurance, health reinsurance, facultative underwriting, product development, and financial solutions. To learn more about RGA and its businesses, visit our website at www.rgare.com.

Similar Jobs

General Motors Logo General Motors

Automation Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

Buick GMC District Manager, Parts and Service - North Central Region

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
106K-141K Annually
Easy Apply
Remote
United States
900 Employees
225K-240K Annually

Motive Logo Motive

Artificial Intelligence Engineer

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
Remote
United States
4000 Employees
140K-160K Annually

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account