Sr. IT Security Engineer (Hybrid)

BelkCharlotte, NC
Hybrid

About The Position

The Sr Security Engineer is responsible for security system deployments, configuration, monitoring, and automation of security tools and processes. The role will also be responsible for security operations, including the protection of cloud infrastructure and AI/ML systems. Provides support to planning and implementing security controls which safeguard and monitor events for information systems, enterprise applications, cloud environments, outsourced services, and data. Provides Tier II support for security related incidents and issues. Lead automation development for detection, incident response playbooks, and tool orchestration across SIEM, XDR, EDR, and other security and compliance tools. Design defensive solutions to secure enterprise generative AI tools, LLM pipelines, MCPs and autonomous AI agents against prompt injections, data leakage, and unauthorized access. Lead incident response, threat hunting, and SOC operational efficiency improvements. Safely deploy AI-powered security tools and agents to streamline threat triage and SOC workflows. Organize, lead, and mentor the security team members.

Requirements

  • Bachelor’s degree in Computer Science or related field or equivalent combination of industry related professional experience and education
  • 10 – 15 years combined experience working in both IT and Cyber Security.
  • Experience working within the NIST 2.0 CSF and Mitre Att&ck frameworks.
  • Hands-on experience working with diverse security control stacks and tools.
  • 5+ years experience with scripting languages like Python or Powershell.
  • 5+ years experience in writing SIEM queries, parsers and alerts.
  • Mastery of the full IR lifecycle—from containment and eradication to root-cause analysis, digital forensics, and post-incident remediation across enterprise environments.
  • Hands-on experience architecting, managing, and optimizing SIEM platforms (e.g., Splunk, Microsoft Sentinel, Elastic) to write custom detection rules, parser logic, and correlation queries.
  • Expertise in deploying, fine-tuning, and managing Endpoint Detection & Response solutions (e.g., CrowdStrike Falcon, SentinelOne, Microsoft Defender) to minimize false positives and maximize coverage.
  • Hands-on experience evaluating, securing, and monitoring enterprise AI tools, LLM pipelines, and autonomous AI agents against risks like prompt injection, data poisoning, and unauthorized tool execution.
  • Practical skill in integrating AI assistants and agents into Blue Team workflows to accelerate threat hunting, log analysis, and alert triage
  • Deep knowledge of securing IDAM and PAM ecosystems (e.g., Azure AD/Entra ID, Okta, CyberArk), enforcing Zero Trust principles, RBAC, and conditional access policies.
  • Proficiency in automating manual operational tasks and incident response playbooks using SOAR tools (e.g., Palo Alto Cortex XSOAR, Swimlane) or custom scripting in Python and PowerShell.
  • Directing, organizing, and mentoring security operation teams.
  • Managing containment, eradication, forensics, and post-incident remediation.
  • Architecting and tuning platforms like Splunk, Microsoft Sentinel, or Elastic.
  • Engineering and optimizing agents (CrowdStrike, SentinelOne) to reduce false positives.
  • Securing enterprise AI systems and pipelines against prompt injections and data leakage.
  • Governing and monitoring autonomous AI agents and execution permissions.
  • Hypothesis-driven querying of telemetry to spot undetected adversaries.
  • Managing detection logic and alert rules using Git and CI/CD pipelines.
  • Aligning defensive coverage and gap analysis against known adversary TTPs.
  • Securing workloads, IAM, and configurations across AWS, Azure, or GCP.
  • Prioritizing asset exposure and orchestrating risk remediation.

Responsibilities

  • Security system deployments, configuration, monitoring, and automation of security tools and processes.
  • Security operations, including the protection of cloud infrastructure and AI/ML systems.
  • Planning and implementing security controls which safeguard and monitor events for information systems, enterprise applications, cloud environments, outsourced services, and data.
  • Tier II support for security related incidents and issues.
  • Automation development for detection, incident response playbooks, and tool orchestration across SIEM, XDR, EDR, and other security and compliance tools.
  • Design defensive solutions to secure enterprise generative AI tools, LLM pipelines, MCPs and autonomous AI agents against prompt injections, data leakage, and unauthorized access.
  • Incident response, threat hunting, and SOC operational efficiency improvements.
  • Deploy AI-powered security tools and agents to streamline threat triage and SOC workflows.
  • Organize, lead, and mentor the security team members.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service