Security & IR Engineer (All Levels)
Hybrid - first 2 months
Who we are:
Our client is a rapidly expanding, award-winning technology solutions provider in the managed services space. Their vision is to be the North American leader in delivering and supporting technology solutions for small and mid-sized businesses. They are driven by their mission and core values to be a great place to work and a great company to work with.
What we are looking for:
We are seeking a hands-on security analyst and incident responder to provide dedicated after-hours coverage for escalated alerts, declared incidents, and overflow security operations work. The ideal candidate can independently investigate, contain, document, and transition work cleanly in a fast-moving managed services environment. This job description is designed to support multiple levels of hire, with core SOC and incident response expectations shared across roles and additional engineering or automation depth serving as a differentiator for more senior candidates.
1. Job Description & Daily Tasks
Job Summary
On-Shift (Steady State)
- Triage escalated alerts, validate severity, enrich with endpoint/identity/network/cloud context
- Document investigation notes and next steps
During Incidents / Surge
- Execute containment, collect/preserve evidence, log correlation for scope/impact
- Maintain eyes-on-glass continuity with clean shift handoffs
Overflow / Bench Support
- Detection tuning, playbook/runbook updates, baseline cleanup, config normalization, visibility improvements
2. Requirements & Target Profile
Experience & Capability
- Relevant SOC and/or incident response experience, generally aligned to level: approximately 3+ years for mid-level hires, 5+ years for senior hires, and 7+ years for lead hires
- Tier 2 capability: run investigations end-to-end with minimal oversight and sound escalation judgment
- Execution-oriented: able to perform containment, blocking, isolation, and basic remediation in small and mid-sized business environments
Environment & Access
- Windows and Microsoft-first environments, including Microsoft 365, Entra ID, Defender, and common firewalls such as WatchGuard and SonicWall
- Comfortable working across EDR, firewall administration, identity and email security consoles, ticketing systems, RMM tools, and security telemetry sources
Documentation & Handoffs
- Strong documentation discipline for investigative findings, decisions made, actions taken, and next steps
- Structured shift-change deliverables including current status, pending actions, risks, and recommendations
- Able to support 2nd/3rd shift schedules and maintain continuity during prolonged or multi-day incident response scenarios
Target Profile
- Hands-on responder who investigates ambiguous or unfamiliar signals independently
- Action-oriented and comfortable making containment decisions within defined guardrails
- Calm under pressure and able to sustain quality through multi-day or concurrent incidents
- Consistency-minded and interested in longer-term engagement within a dedicated team model
Coverage Goal
- Dependable dedicated 2nd and 3rd shift coverage, with optional 1st shift augmentation as operational needs evolve
Surge Capacity
- Multi-day incidents, concurrent incidents, zero-days impacting multiple customers
Technology Environment
- Identity & Security: Microsoft Entra ID, Microsoft Defender, Microsoft 365
- Operating Systems: Windows
- Endpoint Detection & Response (EDR): SentinelOne preferred; experience with leading platforms (e.g., CrowdStrike or equivalent) also valued
- SIEM / XDR & Monitoring: Microsoft-centric security stack and/or platforms such as LimaCharlie
- Network Security: Firewalls including WatchGuard and SonicWall
- Vulnerability Management: Tenable
- Incident Response & Forensics: Cyber Triage and related IR tooling
- Automation & SOAR: Tines or similar workflow automation tools
- Security Tooling & Integrations:
- Security awareness platforms (e.g., KnowBe4)
- Threat intelligence / dark web monitoring (e.g., Kaseya Dark WebID)
- Ticketing System: ConnectWise
3. Nice-to-Have
These capabilities are not required for success in the role, but they may distinguish stronger senior / lead candidates and expand the team's ability to support recovery, engineering, automation, and reporting needs.
- Infrastructure Recovery & IT Engineering
- Network, cloud, and endpoint recovery
- Firewall, VPN, and zero-trust environments
- Backup validation and isolated recovery environments
- Active Directory, virtual hosts, domain controllers, migrations, and secure system restoration
- Endpoint wipe-and-reload and related rebuild activities
- Automation, Orchestration & Advanced SOC Capability
- SOAR workflows in platforms such as Tines
- Alert triage optimization and reporting pipeline improvement
- AI-assisted detection and response workflows
- API or scripting-based integrations using tools such as Python and PowerShell
- Security Data, Reporting & Analytics
- Dashboards and operational reporting views
- Metrics and trend analysis
- Visualization in Power BI, Microsoft Fabric, or similar platforms