> Markdown version of [/jobs/ext/1893739-us-lbm-engineer-cybersecurity-operations](https://www.wearedevelopers.com/jobs/ext/1893739-us-lbm-engineer-cybersecurity-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # US LBM Engineer - Cybersecurity Operations - **Company:** US LBM Holdings, LLC. - **Location:** Boston, MA, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Intrusion Detection and Prevention, Microsoft Security Essentials, Microsoft Office, Azure Active Directory, Cloud Services, Phishing, Kusto Query Language, Runbook, Software Vulnerability Management, EndPointSecurity, Cloud Platform System, Microsoft Power Automate, Office365, Malware, Microsoft InTune, Azure Security Center, Information Technology, Cybercrime, Microsoft Sentinel, Purple Team (Cyber Security) - **Published:** July 31, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87896271/1 ## About the Role * Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field., * 3+ years of experience in cybersecurity operations, security engineering, or incident response. * Hands-on experience with Microsoft Defender XDR technologies. * Experience with Microsoft Sentinel. * Experience investigating security incidents involving endpoints, identities, phishing, malware, and cloud services. * Experience writing KQL queries for threat hunting, investigations, and detection engineering. * Experience implementing and managing Microsoft Attack Surface Reduction (ASR) rules. Skills and Abilities * Strong understanding of security operations, threat hunting, detection engineering, and incident response. * Working knowledge of Windows, Active Directory, Microsoft Entra ID, networking, and cloud security. * Strong analytical and problem-solving skills. * Experience with Microsoft Azure Cloud environment and typical hybrid environment preferred. * Experience with Microsoft Intune preferred. * Experiencing implementing automated desired state configuration, server baselines, and CIS benchmarking preferred. * Experience with Tenable products or other vulnerability management solutions preferred. * Experience with purple team exercises and security control validation preferred. Licenses and Certifications * SC-200, AZ-500, Security+, CISSP, or similar certifications preferred. Travel Requirements * 10% Travel. ## Description The US LBM Engineer - Cybersecurity Operations is a hands-on technical role responsible for monitoring, detecting, investigating, and responding to cyber threats across US LBM's Microsoft security environment. This position supports Microsoft Sentinel, Microsoft Defender XDR, Attack Surface Reduction (ASR), threat hunting, incident response, automation, and security for Microsoft 365 Copilot and AI technologies. Pay Rate: $100K - $120K annual salary What you will do * Monitor, investigate, and respond to cybersecurity alerts, incidents, and threats across enterprise and cloud environments. * Administer and optimize Microsoft Sentinel, including log collections, integrations, connectors, analytics rules, watchlists, threat intelligence integrations, and dashboards. * Working with the Cyber Solutions team, support and maintain Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. * Develop and tune detections, alerts, and KQL queries to improve visibility and reduce false positives. * Perform threat hunting and security investigations using Defender XDR and Sentinel. * Coach and mentor junior cybersecurity analysts by providing guidance on investigations, threat hunting, detection engineering, Microsoft security technologies, and incident response best practices. * Implement and maintain automation using Sentinel Automation Rules and Logic Apps. * Manage, monitor, and maintain health of Microsoft Defender for Endpoint, and cyber related agents Support and collaborate in the establishment and maintenance of server and workstation security baselines, including QA check on server builds. * Optimize Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules and endpoint hardening. * Support security controls, governance, and monitoring for Microsoft 365 Copilot and AI-enabled technologies. * Coordinate penetration testing engagements and track remediation activities. * Support purple team exercises and validate the effectiveness of security detections and response capabilities. * Collaborate with infrastructure, cloud, identity, and application teams to improve security posture. * Develop and maintain operational procedures, runbooks, and technical documentation. Required For All Jobs * Perform other duties as assigned. * Comply with all policies and standards. * Adhere to Company's commitment to workplace safety. * Participate in and complete assigned trainings. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)