Cybersecurity Specialist III

LG Energy Solution Michigan, Inc.Westborough, MA
$98,000 - $110,000Remote

About The Position

The Cybersecurity Specialist III is a senior individual contributor on the enterprise cybersecurity team at LG Energy Solution Vertech (LGESVT), reporting to the Lead Cybersecurity Engineer. The role carries day-to-day responsibility for security operations across LGESVT’s enterprise estate — incident triage and response, SIEM query development and tuning, vulnerability remediation, endpoint detection, cloud security in AWS, and identity and access management. The role spans the full breadth of enterprise security operations rather than a single specialized area, and carries meaningful autonomy within each domain. The Specialist III operates independently on day-to-day security operations and works closely with the Lead Cybersecurity Engineer on complex engineering and incident response work.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. Equivalent practical experience will be considered.
  • Minimum 4 years of hands-on experience in a security operations, security analyst, or cybersecurity specialist role.
  • Demonstrated experience performing incident response, including alert triage, investigation to root cause, and written documentation of findings.
  • Hands-on SIEM experience, including writing and tuning queries and working directly with log data (Microsoft Sentinel, Splunk, Elastic, or equivalent).
  • Practical vulnerability management experience, including risk-based prioritization and coordinating remediation with system owners.
  • Working experience with EDR platforms, including custom rule creation and analysis of endpoint telemetry.
  • Strong working knowledge of AWS services and core cloud security practices, including IAM, logging, monitoring, and posture management.
  • Applied understanding of identity and access management, including SSO, MFA, and least-privilege access models.
  • Experience performing or materially contributing to security risk assessments.
  • Clear technical writing — incident documentation, risk findings, and remediation guidance that a non-specialist owner can act on without translation.
  • Strong working knowledge of Windows and Linux, and the security controls associated with each.
  • Scripting and query ability for automation and data analysis (Python, PowerShell, KQL, or SPL).
  • Familiarity with risk management and control frameworks: NIST CSF, ISO 27001, SOC 2, and CIS Controls.
  • Sound judgment under time pressure, with the discipline to escalate appropriately when information is incomplete.

Nice To Haves

  • AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC (GSEC, GCIH, or GCIA), CompTIA CySA+ or Security+, or Microsoft SC-200.
  • Candidates actively working toward an advanced certification are encouraged to apply; certification support is available.
  • Experience in the energy, utilities, or industrial sectors, or exposure to OT/ICS environments.
  • Familiarity with battery energy storage, renewable energy, or grid-scale infrastructure.
  • Prior exposure to ISO 27001 or SOC 2 audit cycles as an evidence provider.
  • Hands-on experience with Microsoft Entra ID, Microsoft Defender, or Microsoft Purview.
  • Demonstrated interest in detection engineering, security automation, or infrastructure-as-code.

Responsibilities

  • Act as a first responder for security alerts across the enterprise estate, performing triage to establish severity, scope, and the required response path.
  • Investigate confirmed incidents completely to root cause using host, network, identity, and cloud log analysis.
  • Produce clear and complete incident documentation — timeline, indicators, actions taken, and findings — suitable for internal review, audit evidence, and customer notification where contractually required.
  • Execute containment and eradication steps under the direction of the Lead Cybersecurity Engineer and contribute to post-incident review and lessons learned.
  • Participate in the security on-call rotation.
  • Write, tune, and maintain SIEM queries and correlation rules across enterprise log sources.
  • Work directly with raw log data to validate parsing, identify coverage gaps, and confirm that detections fire as intended.
  • Tune alerts to reduce false positives while preserving detection coverage, documenting the rationale for each tuning decision.
  • Support the onboarding of new log sources, including field mapping, normalization, and validation.
  • Contribute detection content to the team’s MITRE ATT&CK-mapped detection library.
  • Operate the recurring vulnerability scanning cycle across servers, endpoints, and cloud workloads.
  • Prioritize findings using severity, exploitability, asset criticality, and actual exposure — not CVSS score alone.
  • Coordinate remediation with IT, Engineering, and system owners; track issues to closure and escalate where timelines slip.
  • Maintain exception records with documented compensating controls and defined review dates.
  • Report on vulnerability posture, remediation performance, and aging against defined service levels.
  • Administer and tune the EDR platform, including policy configuration, exclusion management, and agent health monitoring.
  • Create and maintain custom detection and logging rules to improve endpoint visibility.
  • Investigate EDR detections and use endpoint telemetry to support broader incident investigations.
  • Identify gaps in endpoint coverage and drive them to closure with IT and system owners.
  • Apply core cloud security practices across LGESVT’s AWS environment, including IAM policy review, logging and monitoring configuration, and security posture management.
  • Configure and monitor native AWS security services — CloudTrail, CloudWatch, GuardDuty, Security Hub, and Config — and integrate relevant findings into the SIEM.
  • Review AWS account and workload configuration against established baselines and CIS Benchmarks, tracking drift through to remediation.
  • Support secure design of new AWS workloads in partnership with Engineering and the DevSecOps Engineer.
  • Apply IAM best practices across enterprise and cloud identity, including least privilege, role-based access, and separation of duties.
  • Support administration of SSO, MFA, and conditional access policy in Microsoft Entra ID.
  • Conduct periodic access reviews and support certification campaigns, including evidence production for ISO 27001 and SOC 2.
  • Identify and help remediate standing privileged access, excessive entitlements, and orphaned or stale accounts.
  • Perform security risk assessments of systems, vendors, and proposed changes, documenting findings and recommended treatments.
  • Contribute to maintenance of the technology risk register, including tracking of open risks and mitigation status.
  • Support third-party risk assessments and customer security questionnaires with technical input and supporting evidence.
  • Provide technical evidence for ISO 27001, SOC 2, and CIS Controls audit and assessment activity.
  • Work closely with the Lead Cybersecurity Engineer on complex security engineering and incident response matters.
  • Collaborate with the DevSecOps Engineer, IT, Engineering, and Operations to deliver consistent security outcomes.
  • Partner with the Cybersecurity Manager on compliance, audit, and governance activity.
  • Contribute to security awareness content and provide practical guidance to the wider business.

Benefits

  • competitive salaries
  • generous benefits, including 100% employer sponsored medical, dental, vision, life and disability insurance.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service