
Cybersecurity Specialist III
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Massachusetts.
• Act as the primary responder to enterprise security alerts and conduct triage.
• Examine confirmed incidents to determine the root cause through analysis of host, network, identity, and cloud logs.
• Generate incident documentation that includes timelines, indicators, actions taken, and findings.
• Implement containment and eradication measures, and engage in post-incident reviews.
• Participate in the security on-call rotation.
• Write, refine, and maintain SIEM queries and correlation rules.
• Assess raw log parsing, identify gaps in coverage, and adjust alerts to minimize false positives.
• Assist in the onboarding of new log sources and contribute to detection content mapped to MITRE ATT&CK.
• Conduct vulnerability scans across servers, endpoints, and cloud workloads.
• Prioritize findings, coordinate remediation efforts, track issues to resolution, and report on vulnerability status.
• Manage and optimize the EDR platform, including policies, exclusions, agent health, detections, and endpoint coverage.
• Implement AWS cloud security practices focusing on IAM, logging, monitoring, and security posture management.
• Configure and oversee CloudTrail, CloudWatch, GuardDuty, Security Hub, and Config, integrating findings into the SIEM.
• Review AWS configurations against established baselines and CIS Benchmarks, supporting secure workload design.
• Aid in SSO, MFA, conditional access, access reviews, certification campaigns, and privileged-access remediation in Microsoft Entra ID.
• Conduct security risk assessments and contribute to the technology risk register.
• Assist with third-party risk assessments, customer security questionnaires, and audits for ISO 27001, SOC 2, and CIS Controls.
• Collaborate with the Lead Cybersecurity Engineer, DevSecOps Engineer, IT, Engineering, Operations, and Cybersecurity Manager.
• Help produce security awareness content and offer practical guidance to the broader business.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field; equivalent practical experience is also acceptable.
• At least 4 years of practical experience in a security operations, security analyst, or cybersecurity specialist capacity.
• Proven experience in incident response, including alert triage, root cause investigation, and documentation of findings.
• Hands-on experience with SIEM, including query writing and tuning, as well as direct interaction with log data.
• Practical experience in vulnerability management, encompassing risk-based prioritization and coordinating remediation with system owners.
• Familiarity with EDR platforms, including the creation of custom rules and analysis of endpoint telemetry.
• Strong understanding of AWS services and fundamental cloud security practices, including IAM, logging, monitoring, and posture management.
• Applied knowledge of identity and access management, including SSO, MFA, and least-privilege access models.
• Experience conducting or significantly contributing to security risk assessments.
• Proficiency in technical writing.
• In-depth knowledge of Windows and Linux operating systems and their associated security controls.
• Scripting and querying skills using Python, PowerShell, KQL, or SPL.
• Familiarity with NIST CSF, ISO 27001, SOC 2, and CIS Controls.
• Preferred certifications include AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC (GSEC, GCIH, or GCIA), CompTIA CySA+ or Security+, or Microsoft SC-200.
• Preferred experience in sectors such as energy, utilities, industrial, OT/ICS, battery energy storage, renewable energy, or grid-scale infrastructure.
• Familiarity with Microsoft Entra ID, Microsoft Defender, or Microsoft Purview is preferred.
• 100% employer-sponsored medical, dental, vision, life, and disability insurance.
• Competitive salary packages.
• Generous benefits offerings.
• Support for obtaining certifications is available.
• Up to 10% travel, including periodic visits to LGESVT offices, data center facilities, and headquarters as necessary.
Leidos
Cisco
RELX
TASQ Staffing Solutions
Get handpicked remote jobs straight to your inbox weekly.