SOC Engineer
full-time
mid
Posted 2 weeks ago
Before you apply
Build my evidence-backed draft — free Apply on company site →Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.
About this role
ABOUT HAPPYROBOT
HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide.
Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto. https://www.happyrobot.ai/blog/manifesto
ROLE OVERVIEW
We are looking for a SOC Engineer to join our team. You will build and own our detection and response capability from the ground up — bringing the engineering depth and operational discipline to establish real monitoring across our cloud and identity stack, reduce mean-time-to-detect on security events, and set a foundation that scales into whatever SOC model we choose.
This is not an analyst role. Your deepest strength is detection engineering: designing high-signal detections mapped to ATT&CK, managing the tuning loop that keeps false positive rates in check, and building the log pipeline that makes everything else possible. That said, you operate end-to-end — you investigate alerts yourself, write runbooks an analyst can execute without hand-holding, and automate the repetitive work out of existence.
What You'll Do
- Detection Engineering Design, write, and tune detections mapped to MITRE ATT&CK techniques. Own the false-positive loop — track noise per detection, tune aggressively, and grow coverage across prioritized techniques quarter over quarter. Detections should be high-signal from the start, not high-volume problems to manage later.
- Log Pipeline Engineering Onboard, parse, and normalize log sources into the SIEM reliably. Get all tier-1 sources live within the first two quarters and keep the pipeline clean as new sources are added. Deep familiarity with cloud and identity logs — CloudTrail, GuardDuty, Kubernetes audit logs, Okta — is the foundation this work is built on.
- Incident Triage & Response Investigate alerts end-to-end. Escalate with clear severity reasoning, complete timeline, and actionable context. Don't hand off half-investigated alerts — own the triage process through to a clear disposition.
- Automation Script enrichment, response actions, and repetitive SOC tasks in Python or Go. If something is done manually more than twice, it should be automated. Reduce toil systematically rather than absorbing it.
- Runbooks & Documentation Write triage runbooks for all high and critical alert types — documented well enough that an analyst can execute them without asking for clarification. Keep runbooks current as detections and infrastructure evolve.
- SOC Foundation Build the monitoring capability that positions us to make an informed in-house vs. hybrid SOC decision by end of September. The architecture, coverage, and process you establish now directly shapes what that model looks like.
Must Have
- 3–5 years in detection engineering, SOC engineering, or blue team roles.
- Hands-on experience building detections in a modern SIEM — RunReveal, Panther, Elastic, Splunk, Sentinel, or similar — not just operating one.
- Deep familiarity with cloud and identity log sources: CloudTrail, GuardDuty, Kubernetes audit logs, and IdP/Okta logs.
- Scripting and automation proficiency in Python or Go.
- Experience mapping detections to MITRE ATT&CK.
- English B2+ (professional working proficiency).
Nice to Have
- Detections-as-code with detection content managed in Git and deployed via CI/CD.
- EDR experience with SentinelOne or CrowdStrike.
- Incident response experience beyond triage.
- CNAPP exposure (Wiz or similar) and cloud security fundamentals.
- Certifications: GCIA, GCDA, GCIH, or BTL2.
- Prior experience at a SaaS or tech startup building monitoring from scratch.
WHY JOIN US?
- Join a world-class team of engineers and builders.
- Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.
- Have ownership and autonomy of projects and are encouraged to ship.
- Comprehensive Benefits including healthcare, dental, vision coverage.
- Competitive salary + equity in a high-growth startup.
Our Operating Principles
Extreme Ownership
We take full responsibility for our work, outcomes, and team success. No excuses, no blame-shifting — if something needs fixing, we own it and make it better. This means stepping up, even when it’s not “your job.” If a ball is dropped, we pick it up. If a customer is unhappy, we fix it. If a process is broken, we r
Similar Jobs
Related searches:
Get jobs like this delivered weekly
Free AI jobs newsletter. No spam.