Monitor, investigate, and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, firewall, cloud, identity, and endpoint security platforms
Perform incident response and threat hunting activities, including alert triage, investigation, root cause analysis, containment recommendations, documentation, and follow-up actions
Use SIEM and related security tools to correlate events, analyze log data, tune detections, reduce false positives, improve alert fidelity, and identify visibility gaps
Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise, credential misuse, lateral movement, persistence, and other suspicious behavior
Advise on vulnerability management by reviewing findings, assessing technical risk, prioritizing remediation, validating closure, and helping system owners understand exposure and business impact
Provide practical security guidance on system hardening, secure configuration, platform tuning, and control improvement based on CIS Benchmarks, vendor guidance, and organizational standards
Play an active role in the design and execution of infrastructure initiatives and participate in technical and non-technical projects to ensure an evolving adherence to industry best practices and compliance with corporate security policies and customer standards
Perform other duties as assigned
Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers
Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit
Lift others up - We lead with empathy and strive to improve the lives of those around us
Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact
Raise the bar - We don’t settle for industry standards, we redefine them