Tokio Marine Logo

Tokio Marine

Security Operations Engineer

Posted 5 Days Ago
Remote
Hiring Remotely in USA
104K-158K Annually
Mid level
Remote
Hiring Remotely in USA
104K-158K Annually
Mid level
Provide technical and operational support for MDR customers: investigate and validate alerts, perform log and endpoint analysis, assist containment and recovery, administer Sophos MDR platform, support compliance and cyber hygiene reviews, and coordinate with TAMs, DFIR and Sophos teams to improve service and security posture.
The summary above was generated by AI

Job Title: Security Operations Engineer
Location: Remote, USA (DFW based candidates preferred)
Reports to: Managing Director 
Employment Type: Full time 
Job Req ID: 2026  
Req Begin Date: 7/1/2026 

 
About Vector3 
Vector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group (CPLG). Vector3 specializes in responding to Business Email Compromise (BEC) and Ransomware incidents, helping insured organizations investigate, contain, and recover from cyber events. 

About TMHCC 
Tokio Marine HCC (TMHCC) brings 50 years of service to the specialty insurance industry, today offering over 100 products to commercial customers in 180 countries around the world. Every policy we write is special, enabling our clients to do amazing things. From insuring the crops that feed us to the rock concerts that entertain us, to rescuing international travelers in trouble. 
Organic growth and over 60 successful acquisitions have grown our 2023 Gross Written Premium (GWP) to over $7.5 Billion. Our workforce has grown to 4,300 worldwide … big, but not so big that you cannot make a difference. Our Good Company values, including integrity, empowerment, and commitment to customer service, and a culture of innovation, communication, and collaboration make TMHCC a great place to work. 

What We Offer 

  • Competitive salary and employee benefit package 

  • Strong learning culture 

  • Growth perspectives 

  • 6% 401K match 

  • 20 days of PTO and 2 Floating Days 

  • Paid parental leave 

  • An opportunity to love what you do 

DFW based candidates preferred, Spanish bi-lingual encouraged to apply

Job Summary

The Security Operations Engineer provides technical and operational support for Vector3's MDR customers. This role assists with incident follow-up, technical troubleshooting, remediation validation, compliance reviews, platform administration, and operational security initiatives.

The Security Operations Engineer serves as the technical backbone of the MDR team, allowing TAMs to focus on customer engagement, Cyber Hygiene strategy, and business growth while ensuring customers receive timely technical support and operational security guidance.

Key Responsibilities

Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities:

Incident Investigation & Response Support

  • Review and investigate MDR alerts requiring customer follow-up.
  • Support incident validation, scoping, and remediation activities.
  • Conduct log analysis and security investigations.
  • Assist customers with containment and recovery validation.
  • Document investigative findings and recommendations.

Technical Operations & Platform Support

  • Support deployment and administration of Sophos MDR technologies.
  • Assist with endpoint onboarding, integrations, and configuration activities.
  • Troubleshoot technical issues involving MDR platforms.
  • Validate policy configurations and security controls.
  • Maintain technical documentation and operational runbooks.

Compliance & Security Advisory Support

  • Support Cyber Hygiene assessments and compliance reviews.
  • Assist with security maturity evaluations.
  • Review customer environments for security improvement opportunities.
  • Provide technical recommendations aligned to security best practices.

Collaboration & Cross-Functional Alignment

  • Work closely with TAMs on customer engagements.
  • Coordinate with Sophos MDR teams during investigations.
  • Support DFIR personnel during escalated incidents.
  • Participate in service improvement initiatives.

Competencies

Planning

  • Prioritize security investigations, technical support requests, and operational activities to meet customer service expectations.
  • Coordinate investigative activities and remediation efforts across multiple customer environments.

Communication

  • Clearly communicate technical findings, investigation results, and remediation recommendations to customers and internal stakeholders.
  • Prepare technical reports, investigation summaries, and operational documentation.
  • Translate complex cybersecurity concepts into actionable guidance for technical and non-technical audiences.

Technical Analysis

  • Analyze security events, endpoint telemetry, cloud audit logs, network traffic, and security platform data to identify threats and support customer investigations.
  • Apply analytical thinking to validate alerts, identify root causes, and recommend appropriate remediation actions.
  • Maintain awareness of emerging threats, attack techniques, and evolving cybersecurity best practices.

Business Controls and Policies

  • Comply with all corporate security policies, customer confidentiality requirements, and applicable regulatory obligations.
  • Follow established investigation procedures, documentation standards, and operational workflows.
  • Contribute to the development and continuous improvement of operational processes and technical playbooks.

Collaboration

  • Partner with Technical Account Managers to deliver exceptional customer service and security outcomes.
  • Coordinate with Sophos MDR personnel, internal engineering teams, and DFIR consultants during customer investigations and escalations.
  • Support knowledge sharing and continuous improvement across the Managed Services organization.

Education

Minimum 4 Year Bachelors Degree in Cyber security, Computer Science, information Technology related degree.

Certifications, Licenses, and Designations

Preferred Security+, CySA+, SC-200, Sophos Engineer, or similar certifications a plus.

Experience

3+ years in security operations, cybersecurity engineering, SOC operations, incident response, or IT security.

Other

  • Knowledge of Microsoft 365, Google Workspace, endpoint security, network security technologies, log analysis, and security investigation methodologies.
  • Strong troubleshooting and analytical skills.
  • Experience supporting MSSP, MDR, or SOC environments.
  • Familiarity with NIST CSF, CIS Controls, and common compliance frameworks.
  • Experience supporting Microsoft Defender, Sophos, CrowdStrike, SentinelOne, or similar platforms.
  • Professional proficiency in Spanish (written and verbal) with the ability to communicate technical and security concepts to Spanish-speaking customers.
  • Strong analytical and investigative mindset.
  • Excellent technical troubleshooting skills.
  • Ability to effectively communicate technical and security concepts to both technical and non-technical audiences in English; Spanish language proficiency is a plus.
  • Detail-oriented and process-driven.
  • Collaborative team player.

 

Pay Transparency 

The pay range for this position is $104,340-$157,860 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate’s geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws. 

California → Use CA Fair Chance language. 

The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]  

As an insurance company, we comply with certain federal, state and local laws such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e)), which restricts our ability to employ individuals with certain types of criminal convictions. Where not restricted by law and for criminal history not covered by this law, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law. 

You do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if the Company is concerned about a conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction or challenge the accuracy of the background report. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.] 

Applying our Mind Over Risk philosophy to writing insurance allows our customers to take on opportunity with confidence. That philosophy defines our way of thinking, unites us as a team, and differentiates us from our competitors. We are much more than just an insurance company; we are a good company. 

Equal Opportunity Employer 

TMHCC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. 

 #LI-Hybrid  

#CPLG1 

#LI-VA 

 

Similar Jobs

2 Days Ago
Easy Apply
Remote or Hybrid
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Provides operational support for Zscaler security platforms, including policy configuration, tuning, monitoring, alert triage, DLP, CSPM, DSPM, and incident response. Maintains zero trust access controls, investigates user and application experience issues, documents procedures, and automates repetitive workflows. Requires five-plus years in security operations or related technical fields, hands-on ZIA or ZPA administration, cloud and networking knowledge, and U.S. citizenship.
Top Skills: Ai SecurityAWSCloud Security Posture Management (Cspm)Crowdstrike FalconData Loss Prevention (Dlp)Data Security Posture Management (Dspm)DevsecopsGoogle Cloud Platform (Gcp)LinuxmacOSAzureMtrNssPingSIEMSsl/TlsTcpdumpTracerouteWindowsWiresharkZero TrustZscaler Digital Experience (Zdx)Zscaler Internet Access (Zia)Zscaler Private Access (Zpa)
3 Days Ago
Remote
2 Locations
106K-146K Annually
Mid level
106K-146K Annually
Mid level
Healthtech • Pharmaceutical • Manufacturing
Support and secure Solventum’s Core Speech products through security patching, application coding, production deployments, maintenance, monitoring, alerting, capacity planning, and reliability improvements. Participate in an off-hours support rotation, respond to production alerts, and collaborate on projects improving system performance and architecture. The role is remote within the United States with occasional travel to Pittsburgh, Pennsylvania.
Top Skills: AnsibleAws CloudfrontAws DocumentdbAws Ec2Aws EfsAws EksAws RdsAws S3ContainerdDockerElasticsearchFilebeatGitGitGitlabGoGocdGrafanaJavaJythonKibanaKubernetesLogstashMongoDBPostgresPythonRedisShellSolrSQLTerraform
3 Days Ago
Remote
USA
128K-235K Annually
Senior level
128K-235K Annually
Senior level
Healthtech
Leads DLP security operations across endpoint, network, SaaS, and cloud environments. Responsibilities include deploying and tuning DLP controls, investigating data exfiltration incidents, developing data classification policies, automating alert response playbooks, threat hunting for anomalous data movement, managing incident remediation, and tracking DLP effectiveness metrics. The role also supports incident response and vulnerability management and partners with stakeholders to balance security, usability, and regulatory requirements.
Top Skills: Cloud Access Security Broker (Casb)Cloud SecurityCrowdstrikeData Loss Prevention (Dlp)Endpoint SecurityKqlMicrosoft SentinelNetwork SecurityPowershellPythonSaas SecuritySIEMSoarSplunkSQL

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account