SOC Specialist

<h1>SOC Specialist</h1><p><strong>Location:</strong> Greenwich, CT</p><p><strong>Department:</strong> Technology</p><div><p></p> <h3>Company Overview</h3> <p>Interactive Brokers Group, Inc. (Nasdaq: IBKR) is a global financial services company headquartered in Greenwich, CT, USA, with offices in over 15 countries. We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technology and client commitment.</p> <p>IBKR affiliates provide global electronic brokerage services around the clock on stocks, options, futures, currencies, bonds, and funds to clients in over 200 countries and territories. We serve individual investors and institutions, including financial advisors, hedge funds and introducing brokers. Our advanced technology, competitive pricing, and global market help our clients to make the most of their investments.</p> <p>Barrons has recognized Interactive Brokers as the #1 online broker for six consecutive years. Join our dynamic, multi-national team and be a part of a company that simplifies and enhances financial opportunities using state-of-the-art technology.</p> <p></p></div><p></p> <p><span><strong>This is a hybrid role (3 days in office / 2 days remote).</strong></span></p> <p><span><strong>About your team:</strong></span></p> <p><span></span></p> <p><span>We are seeking an experienced SOC Specialist to help strengthen, modernize, and optimize our Security Operations capabilities. This role sits at the intersection of security operations, detection engineering, security automation, and incident response.</span></p> <p><span>The ideal candidate is passionate about improving SOC effectiveness through better detection logic, SIEM/XDR optimization, automation, threat detection engineering, and operational process improvements. You will play a key role in reducing alert fatigue, improving signal-to-noise ratio, accelerating response times, and enhancing overall security visibility across the enterprise.</span></p> <p><span>This position requires hands-on experience with enterprise security technologies, log analytics, threat detection, incident investigations, and security automation platforms.</span></p> <p><span><strong>What will be your responsibilities within IBKR:</strong></span></p> <ul> <li><span></span> <h3><span>Security Monitoring & Incident Response</span></h3> <ul> <li><span>Monitor, analyze, investigate, and respond to security alerts and incidents across enterprise environments.</span></li> <li><span>Perform triage and escalation of security events in accordance with incident response procedures.</span></li> <li><span>Conduct root cause analysis and document findings, containment actions, and remediation recommendations.</span></li> <li><span>Participate in incident response activities, including malware investigations, insider threat investigations, and account compromise incidents.</span></li> <li><span>Support threat hunting and proactive detection activities.</span></li> </ul> <h3><span>Detection Engineering</span></h3> <ul> <li><span>Develop, tune, and optimize SIEM detection rules, correlation searches, analytics, and alerting mechanisms.</span></li> <li><span>Create and maintain high-fidelity detections mapped to MITRE ATT&CK techniques and adversary behaviors.</span></li> <li><span>Continuously improve detection coverage across endpoints, cloud platforms, identity systems, networks, and applications.</span></li> <li><span>Measure and improve detection effectiveness through detection engineering metrics and validation exercises.</span></li> <li><span>Reduce false positives and improve alert quality through continuous tuning and optimization.</span></li> </ul> <h3><span>SIEM, XDR & Security Platform Management</span></h3> <ul> <li><span>Administer and optimize security monitoring platforms including SIEM, XDR, EDR, NDR, and cloud security tooling.</span></li> <li><span>Maintain log ingestion pipelines, data normalization, parsing, enrichment, and retention strategies.</span></li> <li><span>Validate health, performance, and scalability of security monitoring infrastructure.</span></li> <li><span>Collaborate with infrastructure, cloud, and application teams to onboard new log sources and security telemetry.</span></li> </ul> <h3><span>Security Automation & SOAR</span></h3> <ul> <li><span>Design, develop, and maintain SOAR playbooks and automated response workflows.</span></li> <li><span>Automate repetitive SOC tasks to improve analyst efficiency and reduce response times.</span></li> <li><span>Integrate security tools using APIs, scripting, and workflow orchestration platforms.</span></li> <li><span>Develop automated enrichment, containment, and investigation processes.</span></li> </ul> <h3><span>Threat Intelligence & Threat Hunting</span></h3> <ul> <li><span>Leverage threat intelligence feeds and indicators of compromise (IOCs) to improve detection capabilities.</span></li> <li><span>Conduct threat hunting activities using endpoint, network, cloud, and identity telemetry.</span></li> <li><span>Research emerging threats, attacker techniques, and vulnerabilities affecting the organization.</span></li> <li><span>Assist with purple team exercises and detection validation efforts.</span></li> </ul> <h3><span>Security Operations Improvement</span></h3> <ul> <li><span>Identify opportunities to improve SOC processes, workflows, runbooks, and operational metrics.</span></li> <li><span>Develop and maintain SOC documentation, playbooks, and standard operating procedures.</span></li> <li><span>Support vulnerability management initiatives and risk-based remediation efforts.</span></li> <li><span>Contribute to SOC maturity improvements aligned with industry frameworks and best practices.</span></li> </ul> <hr /> <h3><span>Security Operations</span></h3> <ul> <li><span>Overall 8+ years of experience of which 3+ years of experience in a Security Operations Center (SOC), Detection Engineering, Incident Response, or Cyber Defense role.</span></li> <li><span>Strong understanding of incident detection, triage, investigation, containment, and response processes.</span></li> <li><span>Experience analyzing security events from multiple data sources including endpoints, network devices, cloud platforms, and identity providers.</span></li> </ul> <h3><span>SIEM & Security Monitoring</span></h3> <p><span>Hands-on experience with one or more SIEM platforms:</span></p> <ul> <li><span>Splunk Enterprise Security</span></li> <li><span>Sentinel One Singularity Data Lake</span></li> <li><span>Microsoft Sentinel</span></li> <li><span>QRadar</span></li> <li><span>LogRhythm</span></li> <li><span>Elastic Security</span></li> <li><span>Google Chronicl</span></li> </ul> <span></span></li> </ul> <p><span><strong>Which skills are required:</strong></span></p> <ul> <li><span></span> <ul> <li><span>Palo Alto Networks</span></li> <li><span>Cisco Security products</span></li> <li><span>Fortinet</span></li> <li><span>Check Point</span></li> <li><span>Zscaler</span></li> </ul> <h3><span>Cloud Security</span></h3> <p><span>Experience monitoring and securing cloud environments:</span></p> <ul> <li><span>AWS</span></li> <li><span>Microsoft Azure</span></li> <li><span>Google Cloud Platform (GCP)</span></li> </ul> <p><span>Understanding of:</span></p> <ul> <li><span>Cloud-native security controls</span></li> <li><span>IAM</span></li> <li><span>Cloud logging and monitoring</span></li> <li><span>Cloud threat detection</span></li> </ul> <h3><span>Operating Systems</span></h3> <p><span>Strong working knowledge of:</span></p> <ul> <li><span>Windows Server</span></li> <li><span>Active Directory</span></li> <li><span>Microsoft Entra ID (Azure AD)</span></li> <li><span>Linux administration and security</span></li> </ul> <h3><span>Scripting & Automation</span></h3> <p><span>Experience developing automation using:</span></p> <ul> <li><span>Python</span></li> <li><span>PowerShell</span></li> <li><span>Bash</span></li> <li><span>C#</span></li> </ul> <p><span>Ability to:</span></p> <ul> <li><span>Consume APIs</span></li> <li><span>Automate security workflows</span></li> <li><span>Build integrations between security platforms</span></li> </ul> <h3><span>Security Frameworks & Methodologies</span></h3> <p><span>Knowledge of:</span></p> <ul> <li><span>MITRE ATT&CK</span></li> <li><span>Cyber Kill Chain</span></li> <li><span>NIST Cybersecurity Framework</span></li> <li><span>Incident Response Lifecycle</span></li> <li><span>Detection Engineering principles</span></li> </ul> <span></span></li> </ul> <p><span></span></p> <h1><span>Preferred Qualifications (Nice to Have)</span></h1> <ul> <li><span>Experience building and maintaining SOAR platforms such as:</span> <ul> <li><span>Cortex XSOAR</span></li> <li><span>Splunk SOAR</span></li> <li><span>Microsoft Sentinel Automation</span></li> <li><span>Tines</span></li> <li><span>Swimlane</span></li> </ul> </li> <li><span>Experience with threat hunting methodologies and purple team exercises.</span></li> <li><span>Experience with adversary emulation and detection validation tools.</span></li> <li><span>Familiarity with:</span> <ul> <li><span>AttackIQ</span></li> <li><span>SCYTHE</span></li> <li><span>Atomic Red Team</span></li> <li><span>Caldera</span></li> </ul> </li> <li><span>Experience supporting:</span> <ul> <li><span>Vulnerability management programs</span></li> <li><span>Exposure management initiatives</span></li> <li><span>Security control validation</span></li> </ul> </li> <li><span>Experience with cloud security tooling:</span> <ul> <li><span>Microsoft Defender for Cloud</span></li> <li><span>Wiz</span></li> <li><span>Orca</span></li> <li><span>Prisma Cloud</span></li> <li><span>Lacework</span></li> </ul> </li> <li><span>Familiarity with Identity Threat Detection and Response (ITDR) technologies.</span></li> <li><span>Experience supporting zero trust security initiatives.</span></li> <li><span>Exposure to DevSecOps, CI/CD security, and container security technologies.</span></li> <li><span>Knowledge of Kubernetes, Docker, and modern application security concepts.</span></li> <li><span>Experience working within regulated industries such as financial services, healthcare, or critical infrastructure.</span></li> </ul> <hr /> <h1><span>Certifications</span></h1> <p><span>Preferred certifications include:</span></p> <ul> <li><span>CompTIA Security+</span></li> <li><span>CySA+</span></li> <li><span>GCIH</span></li> <li><span>GCIA</span></li> <li><span>GCFA</span></li> <li><span>GMON</span></li> <li><span>CISSP</span></li> <li><span>SC-200 (Microsoft Security Operations Analyst)</span></li> <li><span>SC-100 (Microsoft Cybersecurity Architect)</span></li> <li><span>Splunk Certified Cybersecurity Defense Analyst</span></li> <li><span>CrowdStrike Certified Falcon Administrator</span></li> </ul> <hr /> <h1><span>Education</span></h1> <p><span>Bachelors degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.</span></p> <p><span></span></p> <p><span><strong>To be successful in this position, you will have the following:</strong></span></p> <ul> <li><span>Self-motivated and able to handle tasks with minimal supervision</span></li> <li><span>Superb analytical and problem-solving skills</span></li> <li><span>Excellent collaboration and communication (verbal and written) skills</span></li> <li><span>Outstanding organizational and time management skills</span></li> </ul> <p><span><strong>Company Benefits & Perks</strong></span></p> <ul> <li><span>Competitive salary, annual performance-based bonus, and stock grant</span></li> <li><span>Retirement plan 401(k) with competitive company match</span></li> <li><span>Excellent health and wellness benefits, including medical, dental, and vision benefits, and a company-paid medical healthcare premium</span></li> <li><span>Wellness screenings and assessments, health coaches, and counseling services through an Employee Assistance Program (EAP)</span></li> <li><span>Paid time off and a generous parental leave policy</span></li> <li><span>Daily company lunch allowance provided, and a fully stocked kitchen with healthy options for breakfast and snacks</span></li> <li><span>Corporate events, including team outings, dinners, volunteer activities, and company sports teams</span></li> <li><span>Education reimbursement and learning opportunities</span></li> <li><span>Modern offices with multi-monitor setups</span></li> </ul> <p> </p>

Back to blog

Other Jobs To Apply

Casualty Coverage and Mass Tort - Complex Claims Director

Specialist, Customer Information Managment

Data Scientist for H Labs @ Chicago, Illinois, United States

Insurance Account Manager

Associate - Digital Technology

IT Vendor Financials and Contract Manager at Deloitte: 100% Remote (US)

Nessus Administrator

Federal Business Development Operations Manager - Remote

Proofread Early Chapter Book (140-160 pages)

Licensed Mental Heath Clinician(LCSW/LMHC) - 100% virtual in a group private practice in NY | Northeast Psychological Wellness | Handshake

Senior Director, Finance IT Enterprise Applications

Global Power Delivery Equipment Lead

Tele-Critical Care Clinical Coord FT

Medical Insurance Collector

Patient Relations Coordinator - Remote in Eugene, OR - 2251433

[Hiring] Medical Science Liaison, Immunology - Admilparant @Bristol Myers Squibb

Engineer, Software (East Moline, Illinois, US, 61244)

Building Automation and Digital Services Leader

TurboTax Product Expert (Work From Home)

Remote Marketing Ops Specialist - HubSpot & Data Quality

Customer Service Rep(07857) - 805 W. Whittier Blvd.

Coca - Cola Remote?o Experience $25/hr At Careermilard ( Remote )

Utilization Management Nurse Consultant - Medical Review (Remote)

Travel Consultant - Remote VIP

Technology Director, Head of Engineering

Oracle Fusion Techno-Functional Developer- Remote, US

[Remote] Senior Associate, Journey Builder (Adobe Experience Platform)

Work From Home Customer Service Rep

External Wholesaler – Independent Broker Dealer Channel

Senior Representative, Personal Line

Property Adjuster at Allstate: 100% Remote (TX)

Business Development Officer, Schwab Wealth Advisory (Central Division)

Korn Ferry Skillbridge Intern (remote)

Associate Client Advocate, Multiple Teams

Strategy Insights & Planning Associate Consultant - HEOR Evidence Generation

Associate Consultant Internship

Implementation - Procurement Associate

Analytics Intern – Analytics Services

Associate Director Private & Trusts Assurance

Senior Insurance Claims Forensics Specialist

Annuities Customer Support

Ingenium Software Developer [Technical Consultant]

Cybersecurity Analyst – Vulnerability Management (Tenable / Nessus / ACAS)

Varonis Engineer Role

CyberArk Architect

Account Executive, Mid-Market (North Central)

Remote Named Account Manager

Senior Remote Distributed Systems Engineer

Senior Director of Developer Relations – Community

Sr. Data Analyst (SAS, data warehouse) | REMOTE

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...