Job Description
The Senior SOC Cloud Engineer is a SOC‑focused, cloud security engineer responsible for cloud‑native detection, incident response, and remediation across Azure and AWS. Reporting to the SOC Manager, this role owns the cloud incident response lifecycle and acts as an engineering extension of the SOC as the organization moves cloud‑first. This is a control and detection–focused role.
Day‑to‑Day
• Own and support cloud incident response from detection through containment, remediation, and lessons learned
• Enable high‑fidelity alerts for SOC analysts (this role is not alert‑triage heavy)
• Build, tune, and automate cloud‑native detections
• Route and optimize Defender and cloud security alerts into Splunk
• Support investigations involving identity compromise, ransomware, and cloud‑based threats
• Improve SOC readiness for real‑world cloud incidents
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
• 7+ years in cybersecurity with strong SOC and incident response experience
• Hands‑on experience securing Azure and AWS (mostly production)
• Deep experience with cloud‑native security tooling, including:
○ Microsoft Defender (E5 today, E7 exposure a plus)
○ AWS CloudTrail, GuardDuty, Security Data Lake
○ DNS logging (Route 53)
• Proven ability to identify, contain, and remediate threats
• Experience enabling SOC teams through better detections and telemetry
• Strong understanding of cloud attack paths and response actions
Nice to Have Skills & Experience
• Experience automating detections and response workflows
• SIEM integration experience (Splunk preferred)
• Exposure to ransomware or high‑severity cloud incidents
Experience supporting SOC maturity in cloud‑first environments
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.