via Monster
$156K - 172K a year
Lead incident response, mentor analysts, and integrate security into software development lifecycle focusing on application and supply chain security.
7+ years SOC and incident response experience, proficiency with SIEM and EDR tools, deep understanding of software supply chain security, application security tools, cloud security, and ability to mentor and lead incident response.
Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Soc Security Engineer for a CONTRACT assignment with one of our premier Regulatory clients. This position is fully remote. We are seeking a highly skilled Senior SOC Security Engineer with expertise in Application Security to join our dynamic cybersecurity team. This role requires flexibility to support our 24x7x365 Security Operations Center, including regular off-hours coverage. This role is for Shift 3 (11pm-8am). This role blends real-time threat detection and response with proactive application security strategies to protect our digital assets and infrastructure. As a senior member of the SOC, you will lead incident response efforts, mentor junior analysts, and collaborate with development teams to embed security into the software development lifecycle (SDLC). You'll be instrumental in shaping our security posture across both operational and application layers. Responsibilities : • Design and implement security controls for third-party software dependencies and open-source components • Monitor, detect, and respond to security incidents • Develop and execute vulnerability management strategies with emphasis on exploitability and reachability analysis • Conduct deep-dive investigations into Software supply chain Security (SSCS) threats, compromised dependencies, and malicious packages • Perform threat hunting for emerging attack vectors • Assess and mitigate risks associated with software dependencies across enterprise systems and applications • Lead incident response efforts for identity-based attacks and supply chain compromises • Develop detection use cases and threat models specific to SSCS attack vectors • Establish security practices for evaluating and vetting third-party packages and libraries • Collaborate with DevOps and engineering teams to integrate security into CI/CD pipelines • Perform vulnerability analysis on 3rd party CVE's with in the FINRA context and work with engineering teams to fix the vulnerability. Required Skills : • Bachelor's or master's degree in computer science, Cybersecurity, Information Systems, or a related technical field • Equivalent experience may be considered in lieu of formal education for exceptional candidates • 7+ years of experience in SOC operations and incident response • Desired Certifications such as CISSP, CASE, OSCP, CSSLP, or GIAC • SIEM & EDR Tools: Proficiency with platforms like Splunk, Sentinel, QRadar, CrowdStrike • Deep understanding of SSCS attack vectors (dependency confusion, compromised packages, malicious commits, backdoors) • Strong knowledge of package managers (npm, PyPI, Maven, NuGet, etc.) and their security implications • Hands-on experience with artifact repository management tools • Application Security Tools: Experience with SAST, DAST, and SCA tools (e.g., Veracode, Burp Suite, SonarQube) • Secure Coding Practices: Deep understanding of OWASP Top 10, SANS 25, and remediation techniques • Cloud Security: Familiarity with AWS, Azure, or GCP security configurations and container security • Proficiency with software composition analysis (SCA) tools and vulnerability reachability concepts • Familiarity with cloud platforms (AWS, Azure, GCP) and container security • Experience integrating security into CI/CD pipelines • Familiarity with DevSecOps principles • Strong analytical thinking and attention to detail • Excellent communication skills for cross-functional collaboration • Ability to mentor junior analysts and lead incident response efforts SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at https://sgainc.com/ . SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company EEO page to request an accommodation or assistance regarding our policy.Salary:75-82.5 USD/Hour Remote Skills: Amazon Web Services (AWS), Analysis Skills, Applications Security, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, Computer Hacking, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, Customer Support/Service, Detail Oriented, DevOps, Enterprise Applications, GCP (Good Clinical Practices), GIAC - Global Information Assurance Certification, Genetics, Hunting, Incident Response, Information Technology & Information Systems, Internet Security, Management Strategy, Maven, Mentoring, Microsoft Windows Azure, Open Source, Problem Solving Skills, Regulations, Risk Analysis, Risk Management, Secure Coding, Security Analysis, Security Information and Event Management (SIEM), Security Software, Software Development Lifecycle (SDLC), Software Engineering, Splunk, Staff Development, Supply Chain, Team Player, Threat Modeling, Use Cases About the Company: SGA Inc.
This job posting was last updated on 7/9/2026