3-5 years of hands-on experience in cybersecurity engineering or security operations.
Proficient with Rapid7 (InsightVM and/or InsightIDR) or similar platforms.
Experience administering SentinelOne or comparable EDR solutions.
Familiarity with Barracuda or similar email security gateways and email authentication protocols.
Strong knowledge of the Microsoft ecosystem including Active Directory and Microsoft 365.
Solid understanding of networking concepts and common attack techniques.
Scripting skills in PowerShell; Python is a plus.
Bachelor's degree in cybersecurity, computer science, or related field.
Responsibilities
Run and tune Rapid7 InsightVM scans and maintain asset coverage.
Prioritize findings by risk and track remediation with IT owners.
Investigate and respond to alerts from various security tools.
Build and tune detection rules to improve alert fidelity.
Lead incident response efforts including containment and recovery.
Administer the SentinelOne console and investigate threats.
Manage email security policies and investigate phishing incidents.
Strengthen Microsoft environment security and improve compliance.
Benefits
Support for professional development and certifications.
Flexible work arrangements and potential remote work options.
Participation in an on-call rotation for security incidents.
Opportunities to work with cutting-edge security technologies.
Full Job Description
What You'll Do
Vulnerability and Exposure Management
Run and tune Rapid7 InsightVM scans, maintain asset coverage and scan schedules, and keep credentialed scanning healthy.
Prioritize findings by risk and exploitability, track remediation with IT owners, and report on SLA performance.
Validate patches and configuration fixes, and manage exceptions through a documented risk-acceptance process.
Detection and Response
Investigate and respond to alerts from Rapid7 InsightIDR, SentinelOne and Microsoft Defender.
Build and tune detection rules, alert thresholds and automated response actions to reduce noise and improve fidelity.
Lead or support incident response: scoping, containment, eradication, recovery and post-incident review.
Perform threat hunting using endpoint telemetry, identity logs and network data.
Endpoint Security
Administer the SentinelOne console: policies, exclusions, device groups, agent deployment and upgrade health.
Investigate threats with SentinelOne Deep Visibility and Storyline data, and perform remediation and rollback when needed.
Coordinate endpoint policy with Intune and Defender to avoid gaps and conflicts.
Email Security
Administer Barracuda Email Protection: filtering policies, quarantine management, impersonation and phishing protection, and allow/block lists.
Investigate reported phishing and suspicious messages, and remove malicious email from affected mailboxes.
Tune Barracuda and Microsoft 365 email controls together (SPF, DKIM, DMARC, Defender for Office 365) to cut false positives without opening gaps.
Support security awareness efforts with phishing trends and simulation results.
Microsoft Environment Hardening
Strengthen Entra ID and Active Directory security: Conditional Access, MFA, privileged access and identity protection.
Improve Microsoft Secure Score and apply CIS benchmarks across Windows, Microsoft 365 and Azure.
Protect Microsoft 365 data with DLP and sensitivity labels.
Partner with infrastructure teams on secure configuration of servers, Group Policy and cloud workloads.
Program and Documentation
Write and maintain runbooks, incident playbooks, standards and architecture documentation.
Support audits and compliance requests with evidence collection and control testing.
Produce metrics and clear status reports for IT leadership.
Participate in an on-call rotation for security incidents.
What You Bring
3-5 years of hands-on experience in cybersecurity engineering, security operations or a closely related IT security role.
Working experience with Rapid7 (InsightVM and/or InsightIDR) or a comparable vulnerability management or SIEM platform.
Hands-on administration of SentinelOne or another enterprise EDR such as CrowdStrike or Defender for Endpoint.
Experience with Barracuda or another email security gateway such as Checkpoint, Proofpoint or Mimecast, plus email authentication (SPF, DKIM, DMARC).
Strong knowledge of the Microsoft ecosystem: Active Directory, Entra ID, Microsoft 365, Intune and Windows Server.
Solid understanding of networking (TCP/IP, DNS, firewalls, VPN) and common attack techniques mapped to MITRE ATT&CK.
Experience investigating incidents and documenting findings clearly for technical and non-technical audiences.
Scripting ability in PowerShell; Python is a plus.
Bachelor's degree in cybersecurity, computer science, IT or a related field, or equivalent experience.
Nice to Have
Familiarity with NERC CIP requirements or other critical-infrastructure compliance frameworks.
Exposure to OT/ICS environments and how securing them differs from enterprise IT.
Familiarity with AI governance frameworks such as the NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001 or the EU AI Act, and experience helping write AI acceptable-use policies.
Understanding of AI and LLM security risks, including prompt injection, data leakage, insecure plugins and model misuse, using references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS.
Experience securing enterprise AI tools such as Microsoft 365 Copilot, Claude Enterprise and Azure OpenAI, including data access permissions, sensitivity labels and Microsoft Purview controls for AI usage.
Experience finding and managing unsanctioned AI apps (shadow AI) with tools such as Microsoft Defender for Cloud Apps, and assessing the security of AI vendors and AI features in third-party products.
Experience with Microsoft Sentinel, KQL or SOAR automation.
Knowledge of NIST CSF, NIST 800-53 or CIS Controls.
Certifications such as Security+, CySA+, GCIH, GSEC, SC-200, AZ-500 or CISSP (or progress toward one).