RT²
Security Engineer
Rol remoto de Security Operations con fit claro de ubicación del candidato.
Publicado8 jun 2026
Países elegibles1 país aceptado
Señal de seniorityMiddle
Modelo de trabajoRemoto
Ubicaciones aceptadas para candidatos
Estados Unidos
Resumen del rol
Security Engineer
Requisitos y responsabilidades
Contenido del rol extraído en secciones para revisar más rápido.
Security Operations & Monitoring
- Monitor and triage alerts across Microsoft Defender, Sentinel, Huntress/MDR, Wiz, Datadog, Jira, and Slack channels.
- Validate alert severity, business impact, affected assets, containment status, and escalation requirements.
- Coordinate security events from initial triage through containment, documentation, closure, and post-incident follow-up.
- Support daily dashboard review, security ticket queues, alert quality checks, and operational reporting.
Detection Engineering & Tuning
- Develop, tune, and maintain detection logic in Huntress, Defender, KQL, and related tools.
- Reduce false positives and alert noise by reviewing recurring detections, suppression logic, enrichment opportunities, and escalation criteria.
- Help build and improve alert runbooks, investigation workflows, and playbooks for phishing, malware, suspicious sign-ins, cloud exposure, endpoint events, and account compromise.
- Support basic SOAR/automation efforts using Logic Apps, playbooks, webhooks, or other workflow tools.
Incident Response & Production Security
- Assist with incident response for endpoint, identity, cloud, email, and suspicious activity events.
- Coordinate containment actions such as endpoint isolation, identity reset, access revocation, escalation to Tier 2/Tier 3 SOC, and follow-up remediation.
- Maintain incident timelines, evidence, RCA notes, lessons learned, and closure documentation.
- Help ensure P1/P2 incidents have clear communication, structured Slack threads, linked Jira tickets, and documented executive summaries when needed.
Cloud, Identity & Endpoint Security
- Support security operations across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Azure, endpoint protection, and cloud risk tools.
- Help review suspicious sign-ins, MFA/SSO issues, risky users, privileged account activity, and access control gaps.
- Assist with cloud exposure triage from Wiz or similar tools, including severity validation, ticket routing, and remediation tracking.
- Support least-privilege reviews, conditional access validation, endpoint security posture, and security control checks.
Production Readiness & Change Support
- Support the Day 0 / Day 1 / Day 2 operating model by helping confirm that new systems and changes are ready for production from a security operations perspective.
- Review or help prepare monitoring requirements, alert runbooks, support escalation paths, rollback considerations, security validation evidence, and operational handoff materials.
- Work with architecture, engineering, and operations teams to ensure production changes are documented, traceable, and supportable.
- Help maintain CMDB/Jira asset relationships, monitoring links, runbook references, and security control mappings where needed. Realtime’s configuration management materials specifically call out CMDB accuracy, monitoring coverage, alert routing, runbook linkage, support RACI, SLA/SLO mapping, and operational acceptance as part of Day 2 readiness.
- Documentation, Metrics & Continuous Improvement
- Create and maintain security runbooks, knowledge base articles, investigation guides, escalation procedures, and incident templates.
- Track and report operational metrics such as alert volume, false positives, SLA breaches, time to acknowledge, time to isolate, time to contain, and closure quality.
- Identify recurring issues and recommend improvements to detections, workflows, tooling, dashboards, and team processes.
- Help mentor the Junior Analyst by reviewing tickets, improving triage quality, and sharing investigation techniques.
Required Qualifications
- 3–5 years of experience in SOC operations, security operations, production support, security engineering, or a similar hands-on cybersecurity role.
- Experience with Microsoft security tools such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft 365 security, or Azure security services.
- Ability to investigate alerts using SIEM/EDR data, KQL, logs, endpoint telemetry, identity logs, and cloud signals.
- Experience with incident triage, phishing investigations, malware alerts, suspicious sign-ins, endpoint events, and escalation workflows.
- Basic understanding of cloud security, identity security, MFA, SSO, conditional access, endpoint protection, and vulnerability/cloud exposure management.
- Ability to write clear documentation, incident notes, runbooks, ticket updates, and executive-ready summaries.
- Comfortable working in a small team where priorities change, and the person may need to support operations, engineering, documentation, and coordination.
- Strong communication skills and ability to work across Slack, Jira, Teams, security tools, managed SOC providers, engineers, and business stakeholders.
Preferred Qualifications:
- Experience with Identity management, Defender, KQL, Logic Apps, SOAR/playbook automation, or detection tuning.
- Experience with tools such as Huntress, Wiz, Datadog, Jira Service Management, Slack, OpenIAM
- Security+, Microsoft SC-200, CySA+, GCIH, Microsoft AZ-500, CCSP, CISSP, or similar certifications.
- Exposure to ITIL, change management, ARB/CAB processes, CMDB, production readiness, or operational handoff.
- Basic scripting or automation experience with PowerShell, Python, Logic Apps, APIs, or workflow automation.
- Experience working in an MSSP, MDR, SOC, or 24/7 operations environment.
What We Offer:
- A unique opportunity to shape the journey of realtime
What We Offer:
- Working within a rapidly growing, game-changing business
What We Offer:
- Remote, flexible working options
What We Offer:
- Competitive compensation
What We Offer:
- Generous STI and LTI provisions
What We Offer:
- Health, Dental and Vision Insurance
What We Offer:
- Paid Annual Leave
What We Offer:
- Paid Sick Leave
What We Offer:
- 401K, and more
Roles similares
Mantén una lista de respaldo.
Stack
Usa estas tags para comparar roles remotos similares.
Elegibilidad de ubicación
Candidatos deberían aplicar solo cuando el país del perfil aparece aquí.
Tu perfilPaís no definidoInicia sesión para comparar tu país con este rol.
Flujo de contratación
WithMira muestra el rol y luego envía candidatos a la aplicación de la empresa.
1Revisa fit del rol, stack y elegibilidad de ubicación en WithMira.
2Abre la página de aplicación de la empresa desde el link rastreado.
3Guarda el rol o suscríbete a oportunidades similares antes de salir.