onsite
US LBM Engineer - Cybersecurity Operations - US LBM Holdings
Security Engineer
We're looking for a Security Engineer focused on streamlining processes and driving operational efficiency. This mid level role requires 3+ years of relevant experience.
About the role
- Monitor, investigate, and respond to cybersecurity alerts, incidents, and threats across enterprise and cloud environments.
- Administer and optimize Microsoft Sentinel, including log collections, integrations, connectors, analytics rules, watchlists, threat intelligence integrations, and dashboards.
- Working with the Cyber Solutions team, support and maintain Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
- Develop and tune detections, alerts, and KQL queries to improve visibility and reduce false positives.
- Perform threat hunting and security investigations using Defender XDR and Sentinel.
- Coach and mentor junior cybersecurity analysts by providing guidance on investigations, threat hunting, detection engineering, Microsoft security technologies, and incident response best practices.
- Implement and maintain automation using Sentinel Automation Rules and Logic Apps.
- Manage, monitor, and maintain health of Microsoft Defender for Endpoint, and cyber related agents Support and collaborate in the establishment and maintenance of server and workstation security baselines, including QA check on server builds.
- Optimize Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules and endpoint hardening.
- Support security controls, governance, and monitoring for Microsoft 365 Copilot and AI-enabled technologies.
- Coordinate penetration testing engagements and track remediation activities.
- Support purple team exercises and validate the effectiveness of security detections and response capabilities.
- Collaborate with infrastructure, cloud, identity, and application teams to improve security posture.
- Develop and maintain operational procedures, runbooks, and technical documentation.
- Perform other duties as assigned.
- Comply with all policies and standards.
- Adhere to Company's commitment to workplace safety.
- Participate in and complete assigned trainings.
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 3+ years of experience in cybersecurity operations, security engineering, or incident response.
- Hands-on experience with Microsoft Defender XDR technologies.
- Experience with Microsoft Sentinel.
- Experience investigating security incidents involving endpoints, identities, phishing, malware, and cloud services.
- Experience writing KQL queries for threat hunting, investigations, and detection engineering.
- Experience implementing and managing Microsoft Attack Surface Reduction (ASR) rules.
- Strong understanding of security operations, threat hunting, detection engineering, and incident response.