Engineer, Cybersecurity Operations

NRECAArlington, VA
Hybrid

About The Position

NRECA is a unique national trade association providing advocacy, financial services and business support services to over 900 consumer owned electric cooperatives across the country. NRECA employees are united by our mission, inclusive culture, collaborative workplace and commitment to service excellence. As a “best place to work” employer, we operate with integrity, transparency and a spirit of innovation. Join IT at NRECA where we are more than a team, we are a community. Guided by the core tenets of Simplicity, Security, Continuity, Transparency, and Flexibility, we strive to deliver business value through collaboration, ideation, and innovation. Become an integral part of a community driven to continuously improve our processes and transform how we work – in partnership with our colleagues and in service to our members. Position Summary: The person in this role supports the Cybersecurity Operations and Engineering team by applying operational security practices, standards, technologies, and internal NRECA processes. They will coordinate security operations activities, including implementation of effective processes and deployment of security applications and infrastructure. They will monitor critical applications and systems, investigate security events, and respond to potential malicious activity, security exploits, or data breaches. This position is eligible for NRECA’s hybrid schedule which allows flexibility to work from home up to 2 days per/week.

Requirements

  • 3+ years of experience defining, implementing, and maintaining complex security infrastructure applications, including:
  • Using ServiceNow IT Service Management (ITSM) or similar ticketing workflows to document, track, and resolve security-related work.
  • Collaborating with internal and external stakeholders to validate detections, coordinate response actions, and support remediation efforts.
  • CompTIA Security+ or equivalent

Nice To Haves

  • GIAC Security Essentials (GSEC), GIAC Security Incident Handler (GCIH), or CompTIA CySA+ (Cybersecurity Analyst)

Responsibilities

  • Monitors, triages, and investigates security tools, critical applications, and systems for suspicious activity, potential malicious behavior, security exploits, and data breaches.
  • Provides backup and rotational 24/7 on-call support for security monitoring and incident response activities to meet response-time service levels and support real-time monitoring when required.
  • Reviews, classifies, correlates, and analyzes security alerts and logs from SIEM platforms, servers, applications, endpoints, file systems, and network devices to identify threats and determine risk, severity, and appropriate response actions.
  • Escalates and responds to security events according to risk and established response procedures.
  • Configures, maintains, and tunes security monitoring, alerting, and operational security tools, including SIEM, EDR, cloud security, and other monitoring platforms.
  • Deploys, tests, evaluates, and implements security solutions and infrastructure in partnership with internal technology teams, external vendors, and suppliers.
  • Ability to report to the office when required

Benefits

  • hybrid schedule which allows flexibility to work from home up to 2 days per/week
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service