Senior Security Engineer
Core
Tier 3 escalation point for active security incidents, operating and improving the gShield security stack across client environments.
Role type
Senior Security Engineer (Incident Response & Tool Operations)
Builds
Incident response outcomes, security stack effectiveness, client remediation, internal security posture improvements
Domain
Cybersecurity / Managed Security Services (MSSP)
Deliverable
client delivery
Required skills
incident response, threat detection, log analysis, containment and eradication, SIEM operations, vulnerability management, Microsoft 365 security, endpoint security, security documentation
Preferred skills
MSP/MSSP environment experience, Intune/AppLocker/ThreatLocker scripting, CIS benchmarks, vulnerability remediation, security certifications (Security+, CySA+, SC-200, SC-300, AZ-500, GCIH, GCIA)
Technologies
Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, Intune, Defender, ThreatLocker, AppLocker, RMM
Responsibilities
Lead technical analysis during incident response and war room events; Operate daily within the gShield toolstack including alert triage and scan issue resolution; Execute containment and eradication actions such as endpoint isolation and credential resets; Support SIEM operations including query development and rule tuning; Execute technical remediation items identified through MRMMs and vulnerability reviews; Write and maintain security engineering SOPs, runbooks, and detection playbooks
Seniority
Senior, hands-on IC