Cybersecurity Specialist III

Posted 5 days ago

This is a fully remote position, open to applicants in Massachusetts.

📋 Description

• Act as the primary responder to enterprise security alerts and conduct triage.

• Examine confirmed incidents to determine the root cause through analysis of host, network, identity, and cloud logs.

• Generate incident documentation that includes timelines, indicators, actions taken, and findings.

• Implement containment and eradication measures, and engage in post-incident reviews.

• Participate in the security on-call rotation.

• Write, refine, and maintain SIEM queries and correlation rules.

• Assess raw log parsing, identify gaps in coverage, and adjust alerts to minimize false positives.

• Assist in the onboarding of new log sources and contribute to detection content mapped to MITRE ATT&CK.

• Conduct vulnerability scans across servers, endpoints, and cloud workloads.

• Prioritize findings, coordinate remediation efforts, track issues to resolution, and report on vulnerability status.

• Manage and optimize the EDR platform, including policies, exclusions, agent health, detections, and endpoint coverage.

• Implement AWS cloud security practices focusing on IAM, logging, monitoring, and security posture management.

• Configure and oversee CloudTrail, CloudWatch, GuardDuty, Security Hub, and Config, integrating findings into the SIEM.

• Review AWS configurations against established baselines and CIS Benchmarks, supporting secure workload design.

• Aid in SSO, MFA, conditional access, access reviews, certification campaigns, and privileged-access remediation in Microsoft Entra ID.

• Conduct security risk assessments and contribute to the technology risk register.

• Assist with third-party risk assessments, customer security questionnaires, and audits for ISO 27001, SOC 2, and CIS Controls.

• Collaborate with the Lead Cybersecurity Engineer, DevSecOps Engineer, IT, Engineering, Operations, and Cybersecurity Manager.

• Help produce security awareness content and offer practical guidance to the broader business.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field; equivalent practical experience is also acceptable.

• At least 4 years of practical experience in a security operations, security analyst, or cybersecurity specialist capacity.

• Proven experience in incident response, including alert triage, root cause investigation, and documentation of findings.

• Hands-on experience with SIEM, including query writing and tuning, as well as direct interaction with log data.

• Practical experience in vulnerability management, encompassing risk-based prioritization and coordinating remediation with system owners.

• Familiarity with EDR platforms, including the creation of custom rules and analysis of endpoint telemetry.

• Strong understanding of AWS services and fundamental cloud security practices, including IAM, logging, monitoring, and posture management.

• Applied knowledge of identity and access management, including SSO, MFA, and least-privilege access models.

• Experience conducting or significantly contributing to security risk assessments.

• Proficiency in technical writing.

• In-depth knowledge of Windows and Linux operating systems and their associated security controls.

• Scripting and querying skills using Python, PowerShell, KQL, or SPL.

• Familiarity with NIST CSF, ISO 27001, SOC 2, and CIS Controls.

• Preferred certifications include AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC (GSEC, GCIH, or GCIA), CompTIA CySA+ or Security+, or Microsoft SC-200.

• Preferred experience in sectors such as energy, utilities, industrial, OT/ICS, battery energy storage, renewable energy, or grid-scale infrastructure.

• Familiarity with Microsoft Entra ID, Microsoft Defender, or Microsoft Purview is preferred.


🏝️ Benefits

• 100% employer-sponsored medical, dental, vision, life, and disability insurance.

• Competitive salary packages.

• Generous benefits offerings.

• Support for obtaining certifications is available.

• Up to 10% travel, including periodic visits to LGESVT offices, data center facilities, and headquarters as necessary.

People also viewed

Leidos1 day ago

Senior Information Systems Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$107.9k – $195.1k/year
ApplyView job
Cisco2 days ago

Security Engineer

US flagColorado, +2 more statesFull-timeCybersecurity / Security Engineer$139.3k – $203.6k/year
ApplyView job
RELX2 days ago

Senior Security Engineer – Sec Ops

US flagNew Jersey, +4 more statesFull-timeCybersecurity / Security Engineer$78.8k – $131.3k/year
ApplyView job
TASQ Staffing Solutions2 days ago

Senior Cloud Security Engineer

PH flagPhilippines OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
MRO2 days ago

Information Security Assurance Advisor

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$104k – $140k/year
ApplyView job
AgelessRx2 days ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$155k – $170k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers