Job Description
One of Insight Global’s customers is looking to onboard a Sr. Cybersecurity Engineer to their team. They will be focused primarily on day-to-day security operations, including monitoring alerts, investigating incidents, reviewing logs, triaging potential threats, and coordinating response efforts across IT, infrastructure, support, vendors, and business teams. They will be responsible for digging into alerts from tools like EDR, SIEM, email security, identity, cloud, and endpoint platforms to determine risk, document findings, and drive remediation. The role will also support incident response, forensic discovery, vulnerability follow-up, e-discovery requests, vetting of new software or applications, and ongoing improvements to security workflows, dashboards, playbooks, and documentation. While most of the focus is operational, this person will also work on incremental security improvements and projects that help mature the security operations function. This is a permanent role and must sit hybrid near one of the customer’s main offices.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
4–6+ years of experience in cybersecurity, security operations, incident response, IT operations, networking, or a related field
Strong incident response experience, including the ability to investigate alerts, dig through logs, perform forensic discovery, and determine next steps
Hands-on experience with Microsoft security technologies and Azure/cloud environments
Experience working with EDR, SIEM, endpoint, identity, vulnerability, email security, or similar security operations tools
Ability to multitask in a high-alert environment and weed through the noise to identify true risk
Strong understanding of infrastructure basics, including cloud, networking, endpoints, servers, and core security principles
Up to date on the current cybersecurity landscape, including cloud security, AI-related risks, modern threats, and evolving attack methods
Excellent documentation, reporting, and communication skills around incidents, investigations, findings, and remediation steps
Ability to explain technical issues in a simple, clear way to both technical and non-technical stakeholders
Nice to Have Skills & Experience
CrowdStrike experience
SIEM experience, including alert triage, tuning, dashboards, or investigations
Experience with Microsoft security stack
Experience supporting vulnerability response, tool improvements, automation, playbooks, or operational security maturity
Enterprise environment background preferred
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.