About SANS
Founded in 1989, SANS Institute (SANS) began as a cooperative research and education organization. Over the next 25 years, it grew to become the most trusted and widely recognized provider of information security training and certification in the world. Today, SANS has served more than 300,000 cybersecurity professionals around the world, with more than 60,000 earning Global Information Assurance Certification (GIAC) security certifications—the leading certification that provides assurance to employers that their people and prospective hires can do the job.
At the heart of SANS is a community of practitioners, from auditors and network administrators to CISOs, who share their lessons learned and collaborate on solutions to the challenges they face. These experts, working across corporations, government agencies, and universities, come together to support and strengthen the global information security community.
Why SANS?
At SANS, our culture is defined by three pillars: Mission, Brand, and People.
- Our Mission is to hire people who understand the importance fighting against cybersecurity threats.
- Our Brand reflects a commitment to delivering the highest quality training.
- Our People are grounded in a culture of fairness, honesty, customer focus, and a pragmatic approach.
What You’ll Achieve at SANS
We are seeking a Senior SOC Engineer - Agentic to join our Security team. This role is a dual-focus security engineering role. On one side, this engineer owns the design and buildout of our agentic SOC — building the detection engineering, automation, and AI agent infrastructure that allows a lean security team to operate at the scope of a much larger one.
On the other, they serve as a hands-on security engineer across the full breadth of the program: vulnerability management, cloud security, identity and access management, application security, architecture reviews, and compliance support.
Initially the role will split roughly evenly between these two tracks. As the Agentic SOC matures and AI agents absorb more of the operational workload, the balance will shift — but the security engineering work never goes away. This is a role for someone who wants to do real security engineering today while building the systems that redefine what security engineering looks like tomorrow.
As a Senior SOC Engineer - Agentic, you will:
-
- Agentic SOC Buildout
- Design the architecture of the agentic SOC. Define how data flows through the detection and response pipeline, how agents are structured and orchestrated, where human-in-the-loop checkpoints belong, and how the overall system evolves as we expand agent autonomy.
- Build and own detection engineering. Write, tune, and maintain detections across our internal SIEM environment. Treat detection content as code — version-controlled, peer-reviewed, tested, measured. Establish the lifecycle of design → deploy → measure → tune → improve.
- Translate SOC operations into automation. Identify the alert triage, investigation, and response work that is ripe for agent augmentation, and define what good looks like for each workflow before it gets handed to an agent.
- Build automations and integrations across our stack. Connect our MSSP, EDR, SIEM, cloud infrastructure, and identity platforms through integrations, scripts, and playbooks — both deterministic automation where that is the right tool, and agent-driven workflows where it is not.
- Partner with AI Engineering to build and govern the agent stack. Co-design the MCP servers and tool integrations that let agents work with security systems. Contribute to prompt design, evaluation harnesses, and feedback loops — and own the audit trails and checkpoints that keep agent actions safe and accountable.
- Operate and improve. Monitor agent performance, investigate failures, tune behavior, and feed real-world outcomes back into the system. The job does not end when something ships.
- Security Engineering
- Vulnerability management. Own the vulnerability identification, prioritization, and remediation tracking program. Work with engineering and infrastructure teams to drive risk reduction across the environment.
- Cloud security. Assess and improve cloud security posture across AWS and Azure — identity and access management (IAM) policy review, configuration hardening, cloud-native detection, and ongoing posture monitoring.
- Identity and access management. Partner with IT and engineering on identity architecture, access reviews, privilege management, and authentication standards.
- Application security. Conduct code reviews, threat models, and security assessments for internal applications and integrations. Partner with development teams to shift security left.
- Security architecture reviews. Evaluate new technologies, integrations, and infrastructure changes for security risk. Provide pragmatic, risk-based guidance.
- Compliance and audit support. Support security compliance activities, evidence collection, and audit engagements as needed.
- Respond to incidents. When something real happens, you are part of the response. The agents help; they do not replace you.
- Perform other related duties as assigned.
What We’re Looking For
Every SANS employee brings something unique. For this role, we’re looking for candidates with:
- 7+ years in security operations, detection engineering, or security automation, with enough depth to lead engineering efforts independently — and enough intellectual curiosity to be genuinely excited about rebuilding how a SOC works from the ground up.
-
- First-hand experience with what a well-run SOC looks like — alert triage workflows, escalation paths, investigation patterns, incident response lifecycle.
- Detection engineering experience: writing and tuning detections, measuring efficacy, managing false positives. Expert-level command of at least one detection query language (KQL, SPL, Lucene, Sigma, or equivalent).
- MITRE ATT&CK fluency as a working tool, not a reference.
- Hands-on experience with EDR and SIEM platforms in production environments.
- Ability to design end-to-end security operations pipelines — from log ingestion and detection through enrichment, triage, investigation, and response — with a clear understanding of where automation fits at each stage.
- Systems thinking: comfortable reasoning about data flows, dependencies, failure modes, and the operational implications of architectural decisions before they are built.
- Experience designing for scale and maintainability — architectures that a small team can operate, extend, and recover when things break.
- Exposure to threat modeling concepts applied to security infrastructure — you do not need to have owned this, but you should be ready to grow into it.
- Comfort thinking through architectural tradeoffs and documenting your reasoning — this is a skill we will develop together, not a prerequisite.
- Strong Python — production-quality code with testing, version control, code review discipline.
- Comfortable building integrations against REST APIs across heterogeneous security tools.
- Experience with SOAR platforms, security automation frameworks, or equivalent home-grown tooling.
- Git-based workflows; as-code mindset for detections, automations, and infrastructure.
- Working knowledge of AWS; experience with Azure or GCP is a plus.
- Curiosity about how LLM-based agents differ from traditional automation, and where each fits.
- Willingness to learn agent frameworks, MCP, and prompt engineering on the job, working alongside our AI Engineering team.
- Side projects, reading, courses, or hobby experiments with LLMs or agents are a real plus — not because we need expertise, but because we need engagement.
- Comfortable working with JSON and Markdown — the connective tissue of modern agent tooling, API integrations, MCP server schemas, and documentation.
- Calibrated skepticism about over-automation — willing to say this should be a script, not an agent, or we should not automate this at all.
- Operator empathy. A small security team will live with what you build. If you cannot sit with them and understand the work, you will build the wrong things.
- Comfort with ambiguity. This program is being built, not maintained.
- Unrestricted authorization to work in the USA; visa sponsorship is not available.
Preferred qualifications include:
- Experience with MSSP-managed detection and response environments.
- Detection-as-code experience: CI/CD pipelines for detection content, automated testing, content packaging.
- Prior experience building SOAR playbooks (Tines, Torq, Cortex XSOAR, Splunk SOAR, or equivalent).
- Incident response experience beyond Tier 1 — you have owned investigations end to end.
- Cloud detection and response experience: audit logging, threat detection services, cloud security posture.
- Identity-focused detection experience (Entra, Okta, Active Directory, or similar).
- Any hands-on experience with LLM tooling: building with LLM APIs, agent frameworks (LangGraph, CrewAI, etc.), or MCP servers — even hobby-level.
- Familiarity with agentic development workflows — CLAUDE.md, Claude Code, GitHub Copilot/Codex, or similar AI-assisted engineering tools.
- Prompt injection and LLM adversarial thinking — particularly relevant since security agents constantly read attacker-controlled data.
Benefits and Perks of Working at SANS
We’re committed to fair and equitable compensation. The expected salary range for this position is $155,000 to $205,000 which is comprised of base salary and bonus, depending on geographic location, skills, and experience. At SANS, pay equity and transparency are priorities.
We offer a comprehensive benefits package that supports your total well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Financial Benefits: Competitive base salary, bonus opportunities, and a 401(k) plan with company match.
- Health & Wellness: Robust medical, dental, and vision plans; company-provided short term disability; optional long-term disability, supplemental life and AD&D insurance for employees and dependents; voluntary benefits including accident insurance and identity theft protection; fitness and wellness programs; and a company paid employee assistance program (EAP).
- Time Off & Flexibility: Generous paid time off, including volunteer time.
- Learning & Development: Access to professional development and SANS training opportunities.
Flexibility and Balance at SANS
We support our colleagues with the tools and flexibility they need to thrive, both professionally and personally. As a primarily remote work environment, we are committed to maintaining strong connections, collaboration, and a vibrant culture across virtual teams. While most roles operate remotely, some positions may require occasional in-person presence depending on role-specific or business needs.
SANS is an Equal Employment Opportunity Employer
SANS is proud to be an Equal Opportunity Employer. We do not discriminate based on race, color, sex, age, national origin, religion, sexual orientation, gender identity, veteran status, disability, or any other federal, state, or local protected class.
If, because of a medical condition or disability, you require a reasonable accommodation during the application process, or to perform the essential functions of a position, please contact SANS Human Resources.
US Job Seekers: Click here to view the “Know Your Rights” poster.
S
ANS complies with all applicable state and local laws regarding the consideration of applicants with arrest or conviction records. For positions governed by federal and/or state banking regulations, SANS will adhere to relevant requirements when evaluating candidates with criminal histories.
Employment eligibility in the United States is required. SANS does not provide visa sponsorship for this position.