THE TEAM YOU WILL BE JOINING
- Established enterprise organization continuing to invest in and expand its Information Security function
- Growing security team that is creating clearer specialization across Security Engineering, Security Operations, and Governance, Risk & Compliance
- Collaborative environment working alongside internal security engineers and a dedicated 24/7 Security Operations team
- Opportunity to join a team that is actively modernizing its security operations capabilities, detection strategy, and automation
- Highly visible role with direct impact on how the organization detects, investigates, and responds to cybersecurity threats
WHAT THEY OFFER YOU
- Direct-hire opportunity with a growing Information Security organization
- Ability to take meaningful ownership of the organization's SIEM and security operations environment
- Opportunity to build and improve detection content rather than simply monitor alerts
- Significant exposure to security automation, orchestration, incident response, and threat detection
- Ability to influence the future direction of the organization's security technology stack
- Opportunity to serve as a senior technical resource while partnering with a broader 24/7 SOC operation
WHAT YOU WILL DO
- Own the day-to-day management, health, tuning, and advancement of the organization's SIEM platform
- Develop, tune, and maintain detection rules across identity, endpoint, cloud, network, and other security telemetry
- Serve as a senior escalation resource for complex or high-severity cybersecurity incidents
- Conduct technical investigations, root-cause analysis, and forensic review as needed
- Design and build SOAR playbooks that automate repetitive response activities and improve detection and response times
- Develop automation and enrichment workflows using tools such as PowerShell, Python, or similar scripting languages
- Evaluate and onboard new log sources, integrations, data connectors, and threat intelligence feeds
- Partner with identity, endpoint, infrastructure, and network teams to maintain appropriate security visibility
- Review security alerts and identify opportunities to improve detection quality, reduce false positives, and strengthen response processes
- Maintain documentation for detection logic, incident response procedures, automation, and security operations workflows
- Provide technical guidance and mentorship to Tier 1 and Tier 2 security analysts
- Participate in incident response activities and an on-call rotation when required
BACKGROUND PROFILE
- 4+ years of cybersecurity experience with meaningful Security Operations or Incident Response exposure
- 2+ years of hands-on experience working with an enterprise SIEM platform
- Strong experience developing and tuning SIEM analytics rules, alerts, and detection content
- Experience operating as a senior engineer, Tier 3 escalation resource, or advanced SOC analyst
- Practical experience designing or maintaining SOAR playbooks
- Strong understanding of incident response, investigations, evidence collection, and documentation
- Scripting and automation experience using PowerShell, Python, or similar technologies
- Experience integrating technologies such as endpoint security, identity, email security, and network telemetry into a SIEM
- Working understanding of the MITRE ATT&CK framework and common threat tactics and techniques
- Microsoft security ecosystem experience is valuable; the current environment includes Microsoft Sentinel
- Exposure to tools such as SentinelOne, Red Canary, Proofpoint, or comparable security technologies is beneficial
- Relevant cybersecurity certification such as Security+, CySA+, GCIH, GCIA, or comparable certification preferred
LOCATION
- Fort Mill, SC
- Onsite



