Security Operations Engineer

Insight Global
Belmont, NC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Apple Mac Systems Microsoft Azure Bash Shell Microsoft Online Services Cloud Computing Security Cyber Security Linux Identity and Access Management Intrusion Detection and Prevention Windows PowerShell
+10 more
Role-Based Access Control Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Mitre Att&ck Cyber Threat Analysis Microsoft InTune Cybercrime Splunk SentinelOne Expertise

Job description

Insight Global is seeking a Security Operations Engineer to support a large Industrial Distribution client of ours of North Carolina. This candidate will be responsible for supporting and enhancing the organization’s security operations and engineering capabilities. Blending hands-on threat detection and incident response with security platform administration, automation, and continuous improvement. The position plays a critical role in maintaining the health and effectiveness of the enterprise security stack, strengthening identity and cloud security controls, and ensuring the organization’s ability to detect, respond to, and mitigate evolving cyber threats.

Responsibilities:

Support daily security operations through proactive threat hunting across endpoint, network, identity, email, and cloud environments.

Support investigation and response activities for high-confidence alerts using behavioral analytics, threat intelligence, and MITRE ATT&CK-aligned analysis.

Manage and maintain detection pipelines, correlation rules, and automated response workflows across SIEM, EDR/XDR, SOAR, and email security platforms.

Act as subject matter expert for the enterprise security stack, ensuring platform health, optimization, and continuous improvement.

Administer and support identity and access management (IAM) controls, including conditional access, role-based access control (RBAC), and Zero Trust enforcement across enterprise platforms.

Support the vulnerability management program through risk analysis, remediation coordination, validation of security fixes, and translation of findings into actionable guidance for infrastructure and development teams.

Collaborate with infrastructure, cloud, and development teams to improve security posture and remediate identified risks.

Enforce system baseline hardening standards across Windows, Linux, macOS, and Azure services.

Support compliance initiatives by maintaining documentation, gathering audit evidence, and contributing to alignment with applicable security frameworks.

Develop and maintain clear operational documentation, playbooks, and procedures to enhance response consistency and cross-team collaboration.

Continuously monitor the threat landscape and adjust detection and response capabilities accordingly.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

  • 2-4 years in a technical security role (SOC Tier 2/3, security engineering, incident response, or equivalent).

Hands-on experience with SIEM (e.g., Sentinel, Splunk), EDR/XDR (e.g., SentinelOne, Defender), and SOAR platforms.

Proficiency in PowerShell and Bash scripting with practical experience automating security and system administration tasks.

Experience administering Microsoft platforms (Microsoft 365, Windows 11, Active Directory, Azure, Intune, Entra, Defender, etc.).

Experience with threat detection engineering and mapping detections to MITRE ATT&CK.

Familiarity with secure baselining (CIS/NIST), access controls, and platform hardening.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all