Back to jobs

SOC Specialist

Chicago, IL

Company Overview

Interactive Brokers Group, Inc. (Nasdaq: IBKR) is a global financial services company headquartered in Greenwich, CT, USA, with offices in over 15 countries. We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technology and client commitment.

IBKR affiliates provide global electronic brokerage services around the clock on stocks, options, futures, currencies, bonds, and funds to clients in over 200 countries and territories. We serve individual investors and institutions, including financial advisors, hedge funds and introducing brokers. Our advanced technology, competitive pricing, and global market help our clients to make the most of their investments.

Barron's has recognized Interactive Brokers as the #1 online broker for six consecutive years. Join our dynamic, multi-national team and be a part of a company that simplifies and enhances financial opportunities using state-of-the-art technology.

This is a hybrid role (3 days in office / 2 days remote).

About your team:

We are seeking an experienced SOC Specialist to help strengthen, modernize, and optimize our Security Operations capabilities. This role sits at the intersection of security operations, detection engineering, security automation, and incident response.

The ideal candidate is passionate about improving SOC effectiveness through better detection logic, SIEM/XDR optimization, automation, threat detection engineering, and operational process improvements. You will play a key role in reducing alert fatigue, improving signal-to-noise ratio, accelerating response times, and enhancing overall security visibility across the enterprise.

This position requires hands-on experience with enterprise security technologies, log analytics, threat detection, incident investigations, and security automation platforms.

What will be your responsibilities within IBKR:

  • Security Monitoring & Incident Response

    • Monitor, analyze, investigate, and respond to security alerts and incidents across enterprise environments.
    • Perform triage and escalation of security events in accordance with incident response procedures.
    • Conduct root cause analysis and document findings, containment actions, and remediation recommendations.
    • Participate in incident response activities, including malware investigations, insider threat investigations, and account compromise incidents.
    • Support threat hunting and proactive detection activities.

    Detection Engineering

    • Develop, tune, and optimize SIEM detection rules, correlation searches, analytics, and alerting mechanisms.
    • Create and maintain high-fidelity detections mapped to MITRE ATT&CK techniques and adversary behaviors.
    • Continuously improve detection coverage across endpoints, cloud platforms, identity systems, networks, and applications.
    • Measure and improve detection effectiveness through detection engineering metrics and validation exercises.
    • Reduce false positives and improve alert quality through continuous tuning and optimization.

    SIEM, XDR & Security Platform Management

    • Administer and optimize security monitoring platforms including SIEM, XDR, EDR, NDR, and cloud security tooling.
    • Maintain log ingestion pipelines, data normalization, parsing, enrichment, and retention strategies.
    • Validate health, performance, and scalability of security monitoring infrastructure.
    • Collaborate with infrastructure, cloud, and application teams to onboard new log sources and security telemetry.

    Security Automation & SOAR

    • Design, develop, and maintain SOAR playbooks and automated response workflows.
    • Automate repetitive SOC tasks to improve analyst efficiency and reduce response times.
    • Integrate security tools using APIs, scripting, and workflow orchestration platforms.
    • Develop automated enrichment, containment, and investigation processes.

    Threat Intelligence & Threat Hunting

    • Leverage threat intelligence feeds and indicators of compromise (IOCs) to improve detection capabilities.
    • Conduct threat hunting activities using endpoint, network, cloud, and identity telemetry.
    • Research emerging threats, attacker techniques, and vulnerabilities affecting the organization.
    • Assist with purple team exercises and detection validation efforts.

    Security Operations Improvement

    • Identify opportunities to improve SOC processes, workflows, runbooks, and operational metrics.
    • Develop and maintain SOC documentation, playbooks, and standard operating procedures.
    • Support vulnerability management initiatives and risk-based remediation efforts.
    • Contribute to SOC maturity improvements aligned with industry frameworks and best practices.

    Security Operations

    • Overall 8+ years of experience of which 3+ years of experience in a Security Operations Center (SOC), Detection Engineering, Incident Response, or Cyber Defense role.
    • Strong understanding of incident detection, triage, investigation, containment, and response processes.
    • Experience analyzing security events from multiple data sources including endpoints, network devices, cloud platforms, and identity providers.

    SIEM & Security Monitoring

    Hands-on experience with one or more SIEM platforms:

    • Splunk Enterprise Security
    • Sentinel One Singularity Data Lake
    • Microsoft Sentinel
    • QRadar
    • LogRhythm
    • Elastic Security
    • Google Chronicl

Which skills are required:

    • Palo Alto Networks
    • Cisco Security products
    • Fortinet
    • Check Point
    • Zscaler

    Cloud Security

    Experience monitoring and securing cloud environments:

    • AWS
    • Microsoft Azure
    • Google Cloud Platform (GCP)

    Understanding of:

    • Cloud-native security controls
    • IAM
    • Cloud logging and monitoring
    • Cloud threat detection

    Operating Systems

    Strong working knowledge of:

    • Windows Server
    • Active Directory
    • Microsoft Entra ID (Azure AD)
    • Linux administration and security

    Scripting & Automation

    Experience developing automation using:

    • Python
    • PowerShell
    • Bash
    • C#

    Ability to:

    • Consume APIs
    • Automate security workflows
    • Build integrations between security platforms

    Security Frameworks & Methodologies

    Knowledge of:

    • MITRE ATT&CK
    • Cyber Kill Chain
    • NIST Cybersecurity Framework
    • Incident Response Lifecycle
    • Detection Engineering principles

Preferred Qualifications (Nice to Have)

  • Experience building and maintaining SOAR platforms such as:
    • Cortex XSOAR
    • Splunk SOAR
    • Microsoft Sentinel Automation
    • Tines
    • Swimlane
  • Experience with threat hunting methodologies and purple team exercises.
  • Experience with adversary emulation and detection validation tools.
  • Familiarity with:
    • AttackIQ
    • SCYTHE
    • Atomic Red Team
    • Caldera
  • Experience supporting:
    • Vulnerability management programs
    • Exposure management initiatives
    • Security control validation
  • Experience with cloud security tooling:
    • Microsoft Defender for Cloud
    • Wiz
    • Orca
    • Prisma Cloud
    • Lacework
  • Familiarity with Identity Threat Detection and Response (ITDR) technologies.
  • Experience supporting zero trust security initiatives.
  • Exposure to DevSecOps, CI/CD security, and container security technologies.
  • Knowledge of Kubernetes, Docker, and modern application security concepts.
  • Experience working within regulated industries such as financial services, healthcare, or critical infrastructure.

Certifications

Preferred certifications include:

  • CompTIA Security+
  • CySA+
  • GCIH
  • GCIA
  • GCFA
  • GMON
  • CISSP
  • SC-200 (Microsoft Security Operations Analyst)
  • SC-100 (Microsoft Cybersecurity Architect)
  • Splunk Certified Cybersecurity Defense Analyst
  • CrowdStrike Certified Falcon Administrator

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent practical experience.

To be successful in this position, you will have the following:

  • Self-motivated and able to handle tasks with minimal supervision
  • Superb analytical and problem-solving skills
  • Excellent collaboration and communication (verbal and written) skills
  • Outstanding organizational and time management skills

Company Benefits & Perks

  • Competitive salary, annual performance-based bonus, and stock grant
  • Retirement plan 401(k) with competitive company match
  • Excellent health and wellness benefits, including medical, dental, and vision benefits, and a company-paid medical healthcare premium
  • Wellness screenings and assessments, health coaches, and counseling services through an Employee Assistance Program (EAP)
  • Paid time off and a generous parental leave policy
  • Daily company lunch allowance provided, and a fully stocked kitchen with healthy options for breakfast and snacks
  • Corporate events, including team outings, dinners, volunteer activities, and company sports teams
  • Education reimbursement and learning opportunities
  • Modern offices with multi-monitor setups

This role's anticipated base salary range is $110,000 to $140,000 annually, based on skills and experience. The offered salary is just part of the total compensation package. In addition to a competitive salary, the company offers both a discretionary cash bonus and a stock award, as well as a wide range of benefits, including health care, tuition reimbursement, and much more.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...

Privacy Disclosure *

Interactive Brokers (“IBKR”) is committed to protecting the privacy of its users. 1. Aggregate Information about Visitors. We collect information on a general and aggregate basis, such as IP addresses, in order to analyze the performance of our sites. This data is used completely anonymously in order to determine the number of people who visit our sites and the most frequently used sections of our sites. This enables us to continually update and refine our sites to ensure it provides you with a successful experience. 2. Information about Users. When registering you are requested to enter certain information about yourself. This information forms the basis for any job application. 3. Your online resume and job application. The details of your job application, covering letter, resume and academic results and any other information will not be viewed by anyone except IBKR and any third party service providers used by IBKR for its hiring processes. 4. Information Management. You can edit any information entered at any time before your job application is submitted. This includes contact details, email address, job application information and password. However, once a job application has been sent, that specific job application cannot be altered. You have certain rights to see and correct data held about you. Please refer to the IBKR Group Privacy Policy on our website. 5. Security. The security of our system is very important to us and we work hard on it. However, please note that no data transmission over the Internet is 100% secure.

Select...
Select...

For fresh graduates please mention 'NA'. 

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Interactive Brokers’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.