Security Operations Engineer
Charlotte, NC - USA
Job Summary
Great company. Great people. Great opportunities.
If youd like the chance to make your mark with the worlds largest equipment rental provider come build your future with United Rentals!
Serve as a senior technical operator in the Security Operations Center (SOC) responsible for leading response to Critical-level and complex multi-stage incidents performing proactive threat hunting and engineering improvements to the organizations detection and response capabilities. Act as the escalation point for SecOps Technicians on high-complexity events and take ownership of incidents that require advanced forensic analysis cross-team coordination or executive-level communication. This is a handson defense role focused on reducing attacker dwell time improving detection fidelity closing coverage gaps and ensuring the SOC continuously matures its capabilities.
What youll do:
Incident Response and Threat Hunting
Lead investigation and containment of Critical-level and complex multi-stage security incidents across the full lifecycle from preparation through lessons learned ensuring incidents are scoped contained eradicated and recovered with clear handoffs at each phase;
Act as the escalation point for SecOps Technicians on incidents that exceed standard runbook procedures providing guidance on investigation direction and containment strategy;
Perform proactive threat hunting using hypothesis-driven searches across SIEM EDR and network data mapping findings to known adversary behaviors and techniques;
Conduct deep-dive analysis of advanced threats including targeted attacks persistent access mechanisms credential abuse chains and supply chain compromise indicators;
Coordinate containment and recovery actions across teams during Critical incidents including working with Infrastructure GRC and business stakeholders on impact assessment and communication;
Produce clear incident narratives for leadership and executive communication translating technical findings into stage-based summaries suitable for non-technical audiences;
Lead tabletop exercises and after-action reviews identifying detection gaps and driving remediation
Detection Engineering and Operations
Maintain and optimize SIEM detection rules correlation logic notable event configurations threat intelligence feed integrations and behavioral analytics content;
Engineer enhancements to alert response workflows through SOAR playbooks scripting or automation to reduce mean time to respond;
Integrate new log sources and data feeds into the SIEM ensuring proper field parsing field extraction and baseline coverage;
Tune detection content to improve signal-to-noise ratio documenting suppression logic and false positive reduction decisions;
Evaluate detection coverage against known adversary techniques and prioritize investment recommendations based on the value and persistence of threat indicators;
Monitor tool efficacy and performance across the security stack coordination with vendors on escalations patches and feature requests;
Train and mentor SecOps Technicians on investigation methodology incident handling techniques and tool usage;
Create and maintain advanced technical playbooks forensic procedures and knowledge base articles;
Participate in a rotating on-call schedule for Critical incident response;
Maintain current high-level technical skills in detection response and security engineering technologies the organization uses or may adopt;
Requirements:
Bachelors degree in cybersecurity information technology or comparable work experience
3 years of hands-on experience in a SOC blue team or incident response role;
Strong expertise with at least two of the following: SIEM content development EDR investigation and response firewall and IPS policy management email security operations log correlation and analysis;
Demonstrated ability to investigate and contain complex attacks including targeted intrusions lateral movement campaigns and credential abuse chains;
Strong understanding of adversary behaviors and techniques with the ability to map detections and investigations to structured threat models;
Ability to write clear incident timelines investigative findings and executive-facing narratives;
Experience prioritizing detection investments based on the value and persistence of threat indicators;
Advanced organizational skills ability to successfully manage multiple tasks/incidents simultaneously;
CySA GCIH GCIA GSOM Cisco Cyber Professional or equivalent technical certifications;
Experience with Splunk (including ES/SOAR) Trend Micro Cisco security platforms or similar enterprise tools;
Familiarity with scripting (Python PowerShell) for automation data enrichment or log analysis;
Experience contributing to maturity assessments or improving programs in a SOC environment;
Knowledge of packet capture and network traffic analysis techniques;
ITIL Incident Management certification preferred
We dont just talk the talk! Were an award-winning company (recently named a Glassdoor Best Place to Work in 2026) that truly cares about our people - Thats why we offer best-in-class benefits and perks that will support you and your addition to our health and financial plans we also offer:
Paid Parental Leave
Employee Discount Program
Career Development & Promotional Opportunities
Additional Vacation Buy Up Program (US Only)
Early Wage Access through Payactiv (US Hourly Only)
Paid Sick Leave
An inclusive and welcoming culture
Explore our comprehensive U.S. benefit offerings
For Canadian benefits click here
United Rentals Inc. is an Equal Opportunity Employer and makes employment decisions regardless of race color religion sex national origin age genetic information citizenship status veteran status sexual orientation gender identity disability or any other status protected by law. If you need a reasonable accommodation at any point of the application process please email for assistance.
At United Rentals we proudly hire active duty members veterans reservists and their families. The values that define your serviceleadership discipline integrity and teamworkare the same values that drive our success. With many veterans already part of our team were ready to help you transition into a rewardingcareer.
United Rentals consists of a wide variety of roles with different duties and responsibilities. The actual pay rate offered to candidates varies depending upon a wide range of factors including specific position location education training experience skills and ability.
Required Experience:
IC