SOC Engineer - US
About Us
inforcer is a leading provider of innovative solutions in the cybersecurity sector and dedicated to enhancing efficiency, improving security and driving success for our clients. We focus on providing MSPs with fundamental tools and technology they need to manage Microsoft Security policies for multiple tenants in a simple and effective way. Our mission is to be inforced in every MSP!
About the Role
We are seeking a SOC Engineer to play a critical role in monitoring, investigating, and responding to security threats across our environment. There are two key parts to the role.
Firstly, you will act as the front line of our security operations; reviewing alerts, identifying suspicious activity, and conducting hands‑on investigations using our SIEM, EDR, and threat intelligence tools. This is an operational role with real ownership, ideal for someone who thrives in a fast‑paced environment, enjoys digging into logs, and can bring clarity to complex behaviours across our network, endpoints, and cloud platforms. As part of this, you will take part in regular out‑of‑hours work, which is a natural component of a 24/7 security operation and compensated as overtime.
Secondly, you will help strengthen our detection and response capabilities by improving playbooks, enhancing alert quality, and contributing insights that increase our overall readiness. As our environment grows, you’ll play a pivotal role in reducing noise, closing detection gaps, and ensuring incidents are handled quickly, consistently, and with high quality. Your work will directly support our ability to remain secure, resilient, and able to operate without interruption.
What you’ll be doing
Monitor SIEM, EDR/XDR, and security tooling for real‑time alerts and suspicious activity.
Triage, investigate, and document security incidents following established playbooks.
Perform log analysis across network, endpoint, cloud, and identity systems to identify potential threats.
Escalate incidents as needed and collaborate with Security Engineering, IT, and Incident Response teams.
Support containment and remediation efforts, including isolating endpoints, collecting forensic artifacts, and validating indicators of compromise (IOCs).
Contribute to improving detection content by identifying gaps, false positives, and tuning opportunities.
Participate in threat hunting exercises and proactive investigations into anomalous behaviour.
Maintain accurate incident records, timelines, and post‑incident reporting.
Assist with onboarding and operationalizing new security tools and processes.
Stay current with emerging threats, attack techniques, and security best practices.
What We Can Offer You
Competitive Compensation: Attractive salary, Pension contribution scheme through Nest, Competitive annual leave allowance
Work-Life Balance: Flexible working hours and hybrid/remote working options to support a healthy work-life balance
Regular Team Socials: We celebrate our team, our milestones, and our new businesses with social events every month
Investing in Your Future: We encourage a growth mindset through proactive development opportunities. Such as continuous learning opportunities, professional training programs, and career advancement paths
Inclusive Environment: A supportive and inclusive workplace that values diversity and encourages collaboration and innovation
Employee Recognition: Programs to recognise and reward employees for their contributions and achievements
Skills We Need for This Role
Core Technical Skills
Hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, LogRhythm).
Familiarity with EDR/XDR tools such as CrowdStrike, Microsoft Defender, SentinelOne, or Cortex.
Ability to analyze logs from servers, endpoints, firewalls, IDS/IPS, and cloud environments.
Understanding of common attack frameworks (MITRE ATT&CK) and threat actor behaviours.
Basic knowledge of network security, TCP/IP, authentication flows, and identity logs.
Experience responding to security incidents in a SOC or cyber operations environment.
Exposure to scripting or automation (Python, PowerShell) is a plus.
Soft Skills & Behaviours
Strong analytical mindset with the ability to spot patterns and anomalies.
Clear written communication for incident documentation and escalation.
Ability to stay calm and focused during high‑pressure security events.
Comfortable working in a fast‑paced, alert‑driven operational environment.
Collaborative, curious, and proactive about learning new threat vectors and tools.
Qualifications
Relevant certifications are helpful (Security+, CySA+, GSEC, GCIA, GCIH, CEH) but not required if experience is equivalent.
Don’t quite have all of these skills? Why not apply and our team can review your experience and fit for the role. We’d love to hear from you!
inforcer is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees
- Department
- Internal IT & Security
- Location
- US Office
- Remote status
- Hybrid