Information Security Engineer

IntuitivePeachtree Corners, GA
$124,200 - $210,300Onsite

About The Position

This position operates within the IT Security organization and focuses on data loss prevention (DLP), endpoint detection and response (EDR), incident management orchestration, security automation, and zero trust network access (ZTNA). The analyst administers and tunes DLP policies, triages and responds to endpoint security events across Windows, macOS, and Linux, builds automated response workflows, and contributes to the continuous improvement of Intuitive’s security posture. Responsible for protecting company information, systems, and users from data exfiltration, unauthorized access, and threat exposure.

Requirements

  • Minimum of 2 years of experience.
  • Hands-on experience administering and tuning enterprise DLP and SASE/CASB solutions across endpoint, cloud, and network enforcement points.
  • Experience deploying, managing, and troubleshooting EDR platforms across Windows, macOS, and Linux environments.
  • Demonstrated competence in endpoint troubleshooting across Windows, macOS, and Linux, including agent lifecycle management, OS-level diagnostics, and policy conflict resolution.
  • Understanding of underlying operating system internals for Windows, macOS, and Linux, including file systems, process management, registry/plist configuration, logging subsystems, and kernel-level behaviors relevant to security tooling.
  • Working knowledge of ZTNA concepts and technologies, including identity-aware access controls, micro-segmentation, and least-privilege network policies.
  • Experience building security automation and orchestration workflows using SOAR platforms to streamline incident triage, enrichment, and response.
  • Familiarity with SIEM platforms and Elasticsearch for log analysis, alert correlation, and dashboard development.
  • Strong communication skills with the ability to convey technical findings to IT teams, engineering stakeholders, and business partners in a matrixed organization.
  • Demonstrated ability to handle sensitive and confidential information with discretion, including investigation findings, personnel data, and legal hold materials.
  • Investigative mindset: intellectual curiosity, attention to detail, methodical evidence handling, objectivity, and the ability to construct a factual narrative from disparate data sources.
  • Degree in a technical related field (or additional related experience)

Nice To Haves

  • Experience working within a SOC, incident response, or DLP operations function supporting enterprise-level environments.
  • SANS/GIAC certification(s) strongly preferred (e.g., GCFE, GCFA, GCED, GCIH, GCIA, GDSA, or GREM). Other certifications such as CISSP or CompTIA Security+ are a plus.
  • Experience operating across a mature enterprise security stack spanning EDR, DLP, SASE/CASB, SOAR, SIEM, ZTNA, next-generation firewalls, identity providers, and email security gateways.
  • Demonstrated experience developing automated playbooks for DLP incident handling, endpoint isolation, or threat enrichment workflows.
  • Understanding of insider threat detection methodologies, data classification frameworks, and regulatory requirements relevant to medical device or healthcare organizations (e.g., HIPAA, FDA).
  • Prior experience conducting or supporting workplace investigations, forensic examinations, or e-discovery processes in a corporate environment.
  • Familiarity with chain-of-custody procedures, legal hold requirements, and evidence preservation standards.
  • Prior systems administration experience across Windows, macOS, or Linux environments, with a working understanding of Active Directory, group policy, endpoint management, and OS-level security hardening.

Responsibilities

  • Administer, tune, and maintain DLP policies and rules within enterprise DLP and SASE/CASB platforms to prevent unauthorized data exfiltration across endpoints, cloud applications, and network egress points.
  • Deploy, configure, and troubleshoot EDR agents across Windows, macOS, and Linux endpoints, ensuring consistent sensor health, policy enforcement, and telemetry collection.
  • Build and maintain automated incident response and orchestration workflows using SOAR platforms to accelerate alert triage, enrichment, containment, and escalation across the security tooling stack.
  • Support ZTNA policy implementation and enforcement in coordination with Network Security, ensuring least-privilege access controls align with zero trust architecture principles.
  • Investigate and respond to DLP alerts, performing root cause analysis, classifying data at risk, coordinating with business stakeholders on policy exceptions, and documenting findings for compliance and audit purposes.
  • Triage and classify endpoint security events by severity and business impact, correlating telemetry from EDR, SIEM, and DLP platforms to identify threats and data exposure risks.
  • Perform endpoint troubleshooting across Windows, macOS, and Linux, including agent deployment issues, policy conflicts, OS-specific behavioral anomalies, and sensor communication failures.
  • Develop and refine operational metrics and dashboards in Elasticsearch to track DLP policy effectiveness, endpoint coverage gaps, automation ROI, and incident response performance.
  • Collaborate with Detection Engineering to create and tune SIEM detection rules that address DLP bypass techniques, EDR evasion, and insider threat indicators.
  • Partner with Incident Response and Investigations teams during escalated security events, providing endpoint forensic data, DLP event context, and automation support throughout the incident lifecycle.
  • Conduct and support internal security investigations, including insider threat cases, policy violations, and unauthorized data handling, using DLP, EDR, and SIEM platforms for evidence collection and forensic analysis.
  • Maintain strict confidentiality and discretion when handling sensitive investigation materials, personnel matters, and privileged findings throughout the investigative lifecycle.

Benefits

  • Market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service