About Emeritus
Emeritus is committed to teaching the skills of the future by making high-quality education accessible and affordable to individuals, companies, and governments around the world. It does this by collaborating with more than 80 top-tier universities across the United States, Europe, Latin America, Southeast Asia, India and China.
Emeritus’ short courses, degree programs, professional certificates, and senior executive programs help individuals learn new skills and transform their lives, companies and organizations. Its unique model of state-of-the-art technology, curriculum innovation, and hands-on instruction from senior faculty, mentors and coaches has educated more than 300,000 individuals across 80+ countries.
Founded in 2015, Emeritus, part of Eruditus Group, has more than 1,800 employees globally and offices in Mumbai, New Delhi, Shanghai, Singapore, Palo Alto, Mexico City, New York, Boston, London, and Dubai. The company is backed by prominent investors including Accel, SoftBank Vision Fund 2, the Chan Zuckerberg Initiative, Leeds Illuminate, Prosus Ventures, Sequoia Capital India, and Bertelsmann.
Job Description: SOC Engineer (Level 2)
Location: Remote
Experience Level: 3–5 Years (with 2+ years focused on Sentinel/ELK stacks)
Role Summary
The Level 2 SOC Engineer is responsible for the health, visibility, and detection capabilities of our security monitoring ecosystem. This role requires a versatile engineer who can navigate Azure Sentinel and the Elastic (ELK) Stack. You will be responsible for building complex queries, managing data pipelines, and ensuring that security logs are searchable, actionable, and mapped to industry frameworks.
Core Responsibilities
•Detection Engineering: Develop and tune KQL (Sentinel) and ES|QL or Lucene (Elastic) analytics rules. Focus on cross-platform visibility to ensure threats are detected regardless of where the data resides.
•Elastic Pipeline Management: Maintain and optimize Logstash configurations and Elasticsearch ingest pipelines. Ensure proper mapping via the Elastic Common Schema (ECS).
•Incident Escalation: Act as a technical bridge for the SOC. Investigate complex alerts by pivoting between Sentinel’s cloud-native data and Elastic’s deep-storage logs.
•Data Onboarding: * Sentinel: Configure data connectors for M365 and Azure resources.
oELK: Deploy and manage Beats (Filebeat, Winlogbeat) and Elastic Agents on on-prem and cloud endpoints.
•SOAR & Automation: Build automated response and use Elastic Actions/Connectors to trigger alerts into ticketing systems or communication channels (Slack/Teams).
•Visualization: Design unified dashboards using SIEM to provide a single-pane-of-glass view for the incident response team.
•Threat Hunting: Use KQL and Painless scripting to conduct hypothesis-based hunting, specifically looking for lateral movement and persistence.
Technical Skills & Qualifications
Query Languages -Advanced KQL (Kusto) and **Elasticsearch Query Language (ES
Platforms – Azure Sentinel, Microsoft Defender XDR, and Elasticsearch/Kibana.
Data Engineering – Experience with Logstash, Beats, and Cloud (GCP/AWS) Log Analytics.
Scripting – Proficiency in PowerShell or Python for API integrations and data transformation.
Frameworks – Mapping telemetry and alerts to the MITRE ATT&CK framework.
Experience – 3–5 years in SOC/Security Engineering, with dual exposure to Sentinel and ELK.
Certifications – SC-200 (Microsoft) or Elastic Certified Analyst preferred
Emeritus provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
In press:
