Infrastructure Engineer, Senior

Southland IndustriesCarrollton, TX
Hybrid

About The Position

Security Operations is a key part of Southland’s cybersecurity program, supporting the monitoring, response, tooling, workflows, and coordination that help protect the company from cyber threats. This role helps improve how Southland detects issues, responds to incidents, manages operational risk, and keeps security work moving across users, endpoints, servers, cloud services, and business systems. As an Infrastructure Engineer, Senior, you will work with cybersecurity, IT, infrastructure, support, vendors, and business teams to investigate alerts, respond to incidents, follow up on vulnerabilities, and improve operational workflows. This role is hands-on and helps turn security events into clear action, documentation, and remediation.

Requirements

  • Strong hands-on security operations, incident response, threat detection, or vulnerability experience.
  • Experience with EDR, SIEM, email security, identity security, vulnerability management, ITSM, or similar tools.
  • Solid understanding of alert triage, endpoint security, identity risk, cloud security, and response workflows.
  • Experience supporting investigations, incidents, vulnerabilities, tool tuning, or process improvement.
  • Ability to work well with both business stakeholders and technical teams.
  • Strong communication skills and a practical, straightforward approach.
  • Ability to sort through technical issues, make sound recommendations, and keep work moving.
  • Minimum 4 – 6 years of experience in cybersecurity, security operations, incident response, IT operations, networking, or related role.

Nice To Haves

  • Experience with MSSP coordination, incident playbooks, SIEM tuning, or automation is preferred.
  • Interest in tools that improve visibility, automation, reporting, and day-to-day execution.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field is preferred.

Responsibilities

  • Build strong working relationships with cybersecurity, IT operations, infrastructure, support, vendors, and business teams.
  • Serve as a hands-on resource for operations questions, escalations, incidents, and follow-up work.
  • Work with technical owners so investigation steps, impact, and next actions are clear.
  • Build trust by communicating clearly, following through, and staying close to the work.
  • Investigate alerts from EDR, SIEM, email, identity, vulnerability, cloud, and endpoint tools.
  • Review alert details, logs, user activity, endpoint data, and related context to determine risk.
  • Escalate issues clearly when an incident, containment action, or business decision is needed.
  • Document findings, decisions, and next steps so work can be tracked and reviewed.
  • Support incident response activities, including scoping, containment, remediation, and recovery follow-up.
  • Coordinate with IT, support, infrastructure, and business owners during response and remediation work.
  • Follow up on vulnerabilities, misconfigurations, exposure, and operational findings through closure.
  • Help reduce disruption by keeping response work organized, practical, and timely.
  • Use security operations tools such as EDR, SIEM, email security, identity security, vulnerability management, and ITSM platforms.
  • Support tuning, automation, dashboards, playbooks, and data quality improvements.
  • Help connect alerts, tickets, evidence, ownership, and remediation status across tools.
  • Improve visibility, alert quality, response speed, and reduction of manual work.
  • Support rollout of new security tools, monitoring practices, response processes, and operational standards.
  • Help analysts, engineers, support teams, and stakeholders understand what is changing.
  • Listen to feedback, identify issues early, and recommend practical adjustments.
  • Support testing, training, and readiness before new tools or processes go live.
  • Document investigations, incident notes, playbooks, runbooks, escalation paths, and decision points.
  • Maintain accurate operational data in dashboards, tickets, alerts, and response records.
  • Provide day-to-day guidance on triage, response, vulnerabilities, and operations questions.
  • Share knowledge with peers and help keep procedures and handoffs consistent.
  • Identify patterns in alerts, vulnerabilities, incidents, and repeated operational issues.
  • Recommend practical improvements to detections, playbooks, dashboards, automation, and workflows.
  • Support planning for operations maturity, MSSP/vendor coordination, tooling, and automation.
  • Keep up with relevant threat, detection, response, and vulnerability management practices.

Benefits

  • 401(k) plan with 50% company match (no cap) and immediate 100% vesting
  • Medical, dental, and vision insurance (100% paid for employee)
  • Annual bonus program based upon performance, achievement, and company profitability
  • Term life, AD&D insurance, and voluntary life insurance
  • Disability income protection insurance
  • Pre-tax flexible spending plans (health and dependent care)
  • Paid parental leave
  • Paid holidays, vacation, and personal time
  • Training/professional development opportunities and company-paid memberships for professional associations and licenses
  • Wellness benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service