{"id":1197703,"url":"https://alion.io/job/tokio-marine-hcc-security-operations-engineer","title":"Security Operations Engineer","company":{"id":7638,"name":"Tokio Marine HCC","domain":"tmhcc.com","url":"https://alion.io/company/tmhcc","size_band":"1001-5000","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":86,"open_postings":16,"ghost_share":0,"stale_share":0.563,"repost_share":0,"time_to_fill_p50_days":48,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":83000,"max_usd":161000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":55},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Crowdstrike","optional":false},{"name":"Google Workspace","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"NIST CSF","optional":false},{"name":"SentinelOne","optional":false},{"name":"Sophos","optional":false}],"status":"live","first_seen_at":"2026-09-24T19:17:56Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-23T12:19:10Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Job Title: Security Operations Engineer\nLocation:Remote, USA (DFW based candidates preferred)\nReports to: Managing Director\nEmployment Type: Full time\nJob Req ID: 2026\nReq Begin Date: 7/1/2026\nAbout Vector3\nVector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group (CPLG). Vector3 specializes in responding to Business Email Compromise (BEC) and Ransomware incidents, helping insured organizations investigate, contain, and recover from cyber events.\nAbout TMHCC\nTokio Marine HCC (TMHCC) brings 50 years of service to the specialty insurance industry, today offering over 100 products to commercial customers in 180 countries around the world. Every policy we write is special, enabling our clients to do amazing things. From insuring the crops that feed us to the rock concerts that entertain us, to rescuing international travelers in trouble.\nOrganic growth and over 60 successful acquisitions have grown our 2023 Gross Written Premium (GWP) to over $7.5 Billion. Our workforce has grown to 4,300 worldwide … big, but not so big that you cannot make a difference. Our Good Company values, including integrity, empowerment, and commitment to customer service, and a culture of innovation, communication, and collaboration make TMHCC a great place to work.\nWhat We Offer\nCompetitive salary and employee benefit package\n\nStrong learning culture\n\nGrowth perspectives\n\n6% 401K match\n\n20 days of PTO and 2 Floating Days\n\nPaid parental leave\n\nAn opportunity to love what you do\n\nDFW based candidates preferred, Spanish bi-lingual encouraged to apply\nJob Summary\nThe Security Operations Engineer provides technical and operational support for Vector3's MDR customers. This role assists with incident follow-up, technical troubleshooting, remediation validation, compliance reviews, platform administration, and operational security initiatives.\nThe Security Operations Engineer serves as the technical backbone of the MDR team, allowing TAMs to focus on customer engagement, Cyber Hygiene strategy, and business growth while ensuring customers receive timely technical support and operational security guidance.\nKey Responsibilities\nRelying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities:\nIncident Investigation & Response Support\nReview and investigate MDR alerts requiring customer follow-up.\nSupport incident validation, scoping, and remediation activities.\nConduct log analysis and security investigations.\nAssist customers with containment and recovery validation.\nDocument investigative findings and recommendations.\nTechnical Operations & Platform Support\nSupport deployment and administration of Sophos MDR technologies.\nAssist with endpoint onboarding, integrations, and configuration activities.\nTroubleshoot technical issues involving MDR platforms.\nValidate policy configurations and security controls.\nMaintain technical documentation and operational runbooks.\nCompliance & Security Advisory Support\nSupport Cyber Hygiene assessments and compliance reviews.\nAssist with security maturity evaluations.\nReview customer environments for security improvement opportunities.\nProvide technical recommendations aligned to security best practices.\nCollaboration & Cross-Functional Alignment\nWork closely with TAMs on customer engagements.\nCoordinate with Sophos MDR teams during investigations.\nSupport DFIR personnel during escalated incidents.\nParticipate in service improvement initiatives.\nCompetencies\nPlanning\nPrioritize security investigations, technical support requests, and operational activities to meet customer service expectations.\nCoordinate investigative activities and remediation efforts across multiple customer environments.\nCommunication\nClearly communicate technical findings, investigation results, and remediation recommendations to customers and internal stakeholders.\nPrepare technical reports, investigation summaries, and operational documentation.\nTranslate complex cybersecurity concepts into actionable guidance for technical and non-technical audiences.\nTechnical Analysis\nAnalyze security events, endpoint telemetry, cloud audit logs, network traffic, and security platform data to identify threats and support customer investigations.\nApply analytical thinking to validate alerts, identify root causes, and recommend appropriate remediation actions.\nMaintain awareness of emerging threats, attack techniques, and evolving cybersecurity best practices.\nBusiness Controls and Policies\nComply with all corporate security policies, customer confidentiality requirements, and applicable regulatory obligations.\nFollow established investigation procedures, documentation standards, and operational workflows.\nContribute to the development and continuous improvement of operational processes and technical playbooks.\nCollaboration\nPartner with Technical Account Managers to deliver exceptional customer service and security outcomes.\nCoordinate with Sophos MDR personnel, internal engineering teams, and DFIR consultants during customer investigations and escalations.\nSupport knowledge sharing and continuous improvement across the Managed Services organization.\nEducation\nMinimum 4 Year Bachelors Degree in Cyber security, Computer Science, information Technology related degree.\nCertifications, Licenses, and Designations\nPreferred Security+, CySA+, SC-200, Sophos Engineer, or similar certifications a plus.\nExperience\n3+ years in security operations, cybersecurity engineering, SOC operations, incident response, or IT security.\nOther\nKnowledge of Microsoft 365, Google Workspace, endpoint security, network security technologies, log analysis, and security investigation methodologies.\nStrong troubleshooting and analytical skills.\nExperience supporting MSSP, MDR, or SOC environments.\nFamiliarity with NIST CSF, CIS Controls, and common compliance frameworks.\nExperience supporting Microsoft Defender, Sophos, CrowdStrike, SentinelOne, or similar platforms.\n Professional proficiency in Spanish (written and verbal) with the ability to communicate technical and security concepts to Spanish-speaking customers.\nStrong analytical and investigative mindset.\nExcellent technical troubleshooting skills.\nAbility to effectively communicate technical and security concepts to both technical and non-technical audiences in English; Spanish language proficiency is a plus.\nDetail-oriented and process-driven.\nCollaborative team player.\nPay Transparency\nThe pay range for this position is $104,340-$157,860 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate’s geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws.\nCalifornia → Use CA Fair Chance language.\nThe Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]\nAs an insurance company, we comply with certain federal, state and local laws such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e)), which restricts our ability to employ individuals with certain types of criminal convictions. Where not restricted by law and for criminal history not covered by this law, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law.\nYou do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if the Company is concerned about a conviction that is directly related to the job, you will be given the chance to explain the circumstances surrounding the conviction or challenge the accuracy of the background report. The Company will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state and local laws, such as the Violent Crime Control and Law Enforcement Act of 1994 (18 USC § 1033(e))(the “VCCLEA”), which restricts financial institutions and insurers such as TMHCC from employing individuals with certain types of criminal convictions. Where the hiring and employment of individuals is not restricted by the foregoing, the Company will consider qualified applicants with arrest or conviction history in compliance with applicable law such as the California Fair Chance Act, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance, the San Diego Fair Chance Ordinance, and the San Francisco Fair Chance Ordinance.]\nApplying our Mind Over Risk philosophy to writing insurance allows our customers to take on opportunity with confidence. That philosophy defines our way of thinking, unites us as a team, and differentiates us from our competitors. We are much more than just an insurance company; we are a good company.\nEqual Opportunity Employer\nTMHCC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.\n#LI-Hybrid","description_format":"text","description_chars":10710,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"Spanish","level":"Advanced (C1)","optional":true},{"language":"English","level":"All levels","optional":true}]},"benefits":["401k plan","Equity","Parental leave"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services","Insurance","Security Operations"],"lifecycle":[{"event":"open","at":"2026-09-24T19:17:56Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":48,"reasons":["conf:6","win:early"],"computed_at":"2026-09-25T01:29:02Z"},"pay":null,"html_url":"https://alion.io/job/tokio-marine-hcc-security-operations-engineer","json_url":"https://alion.io/job/tokio-marine-hcc-security-operations-engineer.json","meta":{"generated_at":"2026-09-25T01:29:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1496,"day_limit":5000,"remaining_today":3504,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}