We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security Operations Engineer

MultiPlan
$130,000 - $145,000
401(k)
United States, Virginia, McLean
7900 Tysons One Place (Show on map)
Sep 25, 2026

JOB SUMMARY:
The Security Engineer is responsible for protecting our organization's networks, systems, and data from evolving threats. In this role, you will design, implement, and operate various security tooling and continuously improve our detections, automation, and defensive posture. The engineer will also be an escalation point for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's technology environment. The engineer works closely with IT, infrastructure, cloud, and application teams to ensure security is embedded across our infrastructure and operations.

JOB ROLES AND RESPONSIBILITIES:
Security Monitoring & Detection
* Monitor, improve, and maintain security events and alerts across the enterprise using SIEM, EDR, and detection telemetry tools; triage and respond to potential incidents in a timely manner.
* Develop and manage detection rules, correlation logic, and automated playbooks (SOAR) to improve response times.
* Analyze and tune security tools to reduce false positives and improve detection fidelity.
* Design, deploy, and maintain security infrastructure, including networking, cloud tooling, endpoint protection, and email security gateways.
* Analyze and triage security alerts to determine legitimacy, severity, and business impact.
* Identify and implement detections for indicators of compromise (IOCs), suspicious behavior, and emerging threats.
* Perform continuous threat monitoring and situational awareness activities.
* Support penetration testing and red team exercises; validate and remediate identified findings.
* Develop and document security operating procedures, runbooks, and incident response plans.
* Stay current on emerging threats, attacker tactics/techniques/procedures (TTPs), and industry best practices (e.g., MITRE ATT&CK).
Incident Response
* Lead or support incident response efforts, including containment, eradication, recovery, and root-cause analysis.
* Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.
* Execute incident response procedures, best practices, and playbooks.
* Document findings, actions taken, and lessons learned for post mortems.
* Escalate significant incidents according to established procedures.
* Perform vulnerability assessments and coordinate remediation with system and application owners.
Threat Hunting & Intelligence
* Develop and refine detection use cases based on threat intelligence and incident trends.
* Conduct threat hunting activities to proactively identify indicators of compromise and advanced persistent threats.
* Utilize threat intelligence feeds and data analysis to enrich investigations.
* Research emerging threats, vulnerabilities, and attack techniques.
Security Operations
* Assist with security architecture reviews for new systems, applications, and cloud deployments.
* Collaborate with compliance teams to support audits and ensure adherence to relevant frameworks (NIST, ISO 27001, SOC 2, FedRAMP, HITRUST, PCI-DSS, etc.).
* Provide on-call support for security incidents outside of normal business hours as needed.
* And other duties as assigned.

REQUIREMENTS (Education, Experience, and Training):
* Bachelor's degree in computer science, Information Security, or related field, or equivalent practical experience
* 5+ years of experience in cybersecurity operations, security engineering, or a related role
* Strong understanding of networking fundamentals (TCP/IP, DNS, routing, firewalls) and operating systems (Windows, Linux)
* Hands-on experience managing SIEM platforms (e.g., Splunk, QRadar, Sentinel) and EDR/XDR tools (e.g., CrowdStrike, SentinelOne, Defender)
* Experience with incident response methodologies and digital forensics investigations
* Familiarity with scripting/automation (Python, PowerShell, Bash) for security tooling and response automation
* Knowledge of common attack techniques, malware behavior, and the MITRE ATT&CK framework
* Understanding of cloud security concepts (AWS, Azure, or Oracle OCI)
* Strong analytical, problem-solving, and communication skills
* Ability to work independently and manage competing priorities in a fast-paced environment
Preferred Qualifications:
* Relevant certifications such as GCIH, GCIA, GSEC, GCFA, CEH, CISSP, or OSCP
* Experience managing SIEM, SOAR, & EDR platforms and security tools
* Familiarity with managing detection lifecycles and tuning detections
* Experience with cloud-native security tools (e.g. External Attack Surface Management (EASM), Continuous Threat Exposure Management (CTEM), GenAI Control Towers, Data Detection, and Secure Email Gateways (SEG))
* Background in threat intelligence analysis
* Prior experience in a regulated industry (finance, healthcare, government, defense)

COMPENSATION:
The salary range for this position is $130k -145k. Specific offers take into account a candidate's education, experience and skills, as well as the candidate's work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

#LI-MZ1

Why Claritev?

Healthcare is complex. We help make it clearer.

At Claritev, you'll do work that matters. Together, we're helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you're looking for purpose, growth, and a team that succeeds together, you'll find it here.

What Guides Us

At Claritev, innovation, agility, and a focus on results drive our success. We embrace bold thinking, work as one team, take ownership, and strive for excellence in everything we do - creating meaningful impact for our clients, communities, and each other.

Applied = 0

(web-9db6c7984-hfltr)