Senior Cyber Operation Engineer Iii positions focus on delivering results in their domain. This page aggregates open Senior Cyber Operation Engineer Iii roles and what employers typically expect.
As Sr. Cyber Operations Engineer III (NOC/SOC) , you’ll help strengthen the reliability and security of complex enterprise environments. You will bring together network operations, security operations, monitoring, automation, and incident response to improve situational awareness and operational resilience. We know that you can’t have great technology services without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers. If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below! What you’ll do: Integrated Operations: Support the design, implementation, and continuous improvement of integrated Network Operations Center (NOC) and Security Operations Center (SOC) capabilities that provide centralized visibility into enterprise infrastructure, networks, cloud environments, endpoints, applications, and cybersecurity events. Monitoring & Observability: Implement and optimize enterprise monitoring using Microsoft Sentinel, Azure Monitor, Log Analytics, Microsoft Defender, and other network and security monitoring platforms to provide real-time visibility into system health, availability, performance, and security. Security Monitoring & Threat Detection: Develop and tune security monitoring, correlation rules, alerts, dashboards, and threat detection capabilities to identify suspicious activity, vulnerabilities, indicators of compromise, and potential cybersecurity incidents. Network Operations: Monitor enterprise network availability, connectivity, utilization, latency, and performance while identifying and resolving issues affecting critical systems and services. Incident Management: Lead technical investigation, triage, escalation, coordination, and resolution of network, infrastructure, cloud, and cybersecurity incidents while ensuring incidents are appropriately documented and communicated. SIEM & Security Tooling: Configure and optimize Security Information and Event Management (SIEM), endpoint detection and response (EDR), network monitoring, vulnerability management, and security analytics platforms to improve operational awareness and threat detection. Automation & Orchestration: Develop automated workflows, scripts, playbooks, and Security Orchestration, Automation, and Response (SOAR) capabilities using PowerShell, Python, Azure Logic Apps, or similar technologies to accelerate detection, response, remediation, and operational workflows. Operational Processes: Develop and maintain NOC/SOC standard operating procedures, incident response playbooks, escalation procedures, operational runbooks, and knowledge management documentation. Performance & Reporting: Develop operational dashboards, KPIs, SLA metrics, incident trends, availability reports, and security metrics to measure NOC/SOC effectiveness and identify opportunities for continuous improvement. Stakeholder Collaboration: Work closely with client stakeholders, cybersecurity teams, network engineers, cloud engineers, system administrators, application teams, and leadership to maintain enterprise situational awareness and rapidly resolve operational and security issues. What you’ll need to succeed: Active Top Secret security clearance. Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline. 10+ years of experience in network operations, cybersecurity operations, infrastructure operations, systems engineering, or related technical roles. 5+ years of experience supporting enterprise NOC, SOC, or integrated network/security operations environments. Strong experience with Microsoft Sentinel, Microsoft Defender, Azure Monitor, Log Analytics, or comparable SIEM, security monitoring, and obs…