United Rentals logo

Security Operations Engineer

United Rentals
  • Charlotte, North Carolina
    1 day ago

    Job Description

    Great company. Great people. Great opportunities.

    If you’d like the chance to make your mark with the world’s largest equipment rental provider, come build your future with United Rentals!

    Serve as a senior technical operator in the Security Operations Center (SOC), responsible for leading response to Critical-level and complex multi-stage incidents, performing proactive threat hunting, and engineering improvements to the organizations detection and response capabilities. Act as the escalation point for SecOps Technicians on high-complexity events and take ownership of incidents that require advanced forensic analysis, cross-team coordination, or executive-level communication. This is a handson defense role focused on reducing attacker dwell time, improving detection fidelity, closing coverage gaps, and ensuring the SOC continuously matures its capabilities.

    What you'll do:

    • Incident Response and Threat Hunting

      • Lead investigation and containment of Critical-level and complex multi-stage security incidents across the full lifecycle, from preparation through lessons learned, ensuring incidents are scoped, contained, eradicated, and recovered with clear handoffs at each phase;

      • Act as the escalation point for SecOps Technicians on incidents that exceed standard runbook procedures, providing guidance on investigation direction and containment strategy;

      • Perform proactive threat hunting using hypothesis-driven searches across SIEM, EDR, and network data, mapping findings to known adversary behaviors and techniques;

      • Conduct deep-dive analysis of advanced threats including targeted attacks, persistent access mechanisms, credential abuse chains, and supply chain compromise indicators;

      • Coordinate containment and recovery actions across teams during Critical incidents, including working with Infrastructure, GRC, and business stakeholders on impact assessment and communication;

      • Produce clear incident narratives for leadership and executive communication, translating technical findings into stage-based summaries suitable for non-technical audiences;

      • Lead tabletop exercises and after-action reviews, identifying detection gaps and driving remediation

    • Detection Engineering and Operations

      • Maintain and optimize SIEM detection rules, correlation logic, notable event configurations, threat intelligence feed integrations, and behavioral analytics content;

      • Engineer enhancements to alert response workflows through SOAR playbooks, scripting, or automation to reduce mean time to respond;

      • Integrate new log sources and data feeds into the SIEM, ensuring proper field parsing, field extraction, and baseline coverage;

      • Tune detection content to improve signal-to-noise ratio, documenting suppression logic and false positive reduction decisions;

      • Evaluate detection coverage against known adversary techniques and prioritize investment recommendations based on the value and persistence of threat indicators;

      • Monitor tool efficacy and performance across the security stack, coordination with vendors on escalations, patches, and feature requests;

      • Train and mentor SecOps Technicians on investigation methodology, incident handling techniques, and tool usage;

      • Create and maintain advanced technical playbooks, forensic procedures, and knowledge base articles;

      • Participate in a rotating on-call schedule for Critical incident response;

      • Maintain current, high-level technical skills in detection, response, and security engineering technologies the organization uses or may adopt;

    Requirements:

    • Bachelor’s degree in cybersecurity, information technology, or comparable work experience

    • 3+ years of hands-on experience in a SOC, blue team, or incident response role;

    • Strong expertise with at least two of the following: SIEM content development, EDR investigation and response, firewall and IPS policy management, email security operations, log correlation and analysis;

    • Demonstrated ability to investigate and contain complex attacks including targeted intrusions, lateral movement campaigns, and credential abuse chains;

    • Strong understanding of adversary behaviors and techniques, with the ability to map detections and investigations to structured threat models;

    • Ability to write clear incident timelines, investigative findings, and executive-facing narratives;

    • Experience prioritizing detection investments based on the value and persistence of threat indicators;

    • Advanced organizational skills, ability to successfully manage multiple tasks/incidents simultaneously;

    • CySA+, GCIH, GCIA, GSOM, Cisco Cyber Professional, or equivalent technical certifications;

    • Experience with Splunk (including ES/SOAR), Trend Micro, Cisco security platforms, or similar enterprise tools;

    • Familiarity with scripting (Python, PowerShell) for automation, data enrichment, or log analysis;

    • Experience contributing to maturity assessments or improving programs in a SOC environment;

    • Knowledge of packet capture and network traffic analysis techniques;

    • ITIL Incident Management certification preferred

    Why join us?

    We don’t just “talk the talk!” We’re an award-winning company (recently named a Glassdoor Best Place to Work in 2026) that truly cares about our people - That’s why we offer best-in-class benefits and perks that will support you and your family. In addition to our health and financial plans, we also offer:

    • Paid Parental Leave

    • United Compassion Fund

    • Employee Discount Program

    • Career Development & Promotional Opportunities

    • Additional Vacation Buy Up Program (US Only)

    • Early Wage Access through Payactiv (US Hourly Only)

    • Paid Sick Leave

    • An inclusive and welcoming culture

    Explore our comprehensive U.S. benefit offerings

    For Canadian benefits, click here

    United Rentals, Inc. is an Equal Opportunity Employer and makes employment decisions regardless of race, color, religion, sex, national origin, age, genetic information, citizenship status, veteran status, sexual orientation, gender identity, disability, or any other status protected by law. If you need a reasonable accommodation at any point of the application process, please email careers@ur.com for assistance.

    At United Rentals, we proudly hire active duty members, veterans, reservists, and their families. The values that define your service—leadership, discipline, integrity, and teamwork—are the same values that drive our success. With many veterans already part of our team, we’re ready to help you transition into a rewarding career.

    United Rentals consists of a wide variety of roles with different duties and responsibilities. The actual pay rate offered to candidates varies depending upon a wide range of factors including specific position, location, education, training, experience, skills, and ability.

    Numbers & Facts

    LocationCharlotte, North Carolina
    IndustryRental Services
    Company Size10,000 employees or more
    Websitehttp://www.unitedrentals.com

    About Company

    Founded in 1997, United Rentals is the largest equipment rental company in the world, with a store network nearly three times the size of any other provider, and locations in 49 states and 10 Canadian provinces. Building a better future is our commitment to the people and communities we serve. United Rentals, Inc. is the largest equipment rental company in the world. The company has an integrated network of 1,186 rental locations in North America and 11 in Europe. In North America, the company operates in 49 states and every Canadian province. The company’s approximately 18,500 employees serve construction and industrial customers, utilities, municipalities, homeowners and others. The company offers approximately 3,800 classes of equipment for rent with a total original cost of $14.18 billion. United Rentals is a member of the Standard & Poor’s 500 Index, the Barron’s 400 Index and the Russell 3000 Index® and is headquartered in Stamford, Conn. Additional information about United Rentals is available at unitedrentals.com. Our Customers Our diverse customer base includes construction and industrial companies, utilities, municipalities, government agencies and independent contractors. Most of our customers align with three categories: approximately 50% are non-construction, such as industrial; 46% are non-residential construction; and 4% are residential. We provide every customer with access to the best people, equipment and solutions in the industry. Our Mission Deploy the best people, equipment and solutions to enable our customers to safely build a better and stronger future. Our Values Safety First Act, and require others to act, in a manner that puts the safety of our employees, customers and communities first. A Passion For People Build a diverse workplace that challenges all employees to grow professionally and embrace teamwork. Visible Leadership Lead by example in every business decision and action, with a sense of humility and responsibility. Customer-Driven Support the best interests of our customers and develop better ways for them to succeed at their jobs. Absolute Integrity Always do the right thing, honor commitments and ensure appropriate corporate governance. Community-Minded Be an outstanding corporate citizen and a good neighbor in every sense by being helpful, respectful, law-abiding and friendly. Continuous Innovation Contribute to a culture of innovative thinking that empowers employees to improve quality, efficiency and customer service. Sustainability Engage in practices that lead to positive change by encouraging social accountability and environmental responsibility.

    Skills

    • Analysis Skillsunmatched
    • Automationunmatched
    • Business impact analysis (BIA)unmatched
    • Campaignsunmatched
    • Cisco Network Systemsunmatched
    • Computer Securityunmatched
    • Content Developmentunmatched
    • Data Mappingunmatched
    • Email Securityunmatched
    • Equipment Rentalsunmatched
    • Establish Prioritiesunmatched
    • Firewallsunmatched
    • Forensic Scienceunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Huntingunmatched
    • ITIL (IT Infrastructure Library)unmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Intrusion Prevention Systemsunmatched
    • Knowledge Baseunmatched
    • Leadershipunmatched
    • Mentoringunmatched
    • Multitaskingunmatched
    • Network Traffic Analysisunmatched
    • On Callunmatched
    • Organizational Development/Managementunmatched
    • Organizational Skillsunmatched
    • People Managementunmatched
    • Python Programming/Scripting Languageunmatched
    • Rentalsunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Software Patchesunmatched
    • Splunkunmatched
    • Supply Chainunmatched
    • Team Lead/Managerunmatched
    • Team Playerunmatched
    • Threat Modelingunmatched
    • Time Managementunmatched
    • Trend Micro Product Familyunmatched
    • Windows PowerShellunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder