IT Security Engineer

KēSTA I.T.Salt Lake, UT
Onsite

About The Position

KēSTA I.T. is actively seeking an IT Security Engineer for an immediate full-time opportunity with our industry leading client. This role offers leadership, responsibility, and the chance to make a significant impact within a thriving and stable organization. An IT Security Engineer is responsible for monitoring, investigating, and responding to security alerts escalated from a 24/7 Security Operations Center (SOC), while supporting day-to-day security operations and continuous improvement initiatives. This role partners closely with internal IT and security teams to maintain and enhance the organization’s overall security posture. The position blends hands-on incident response, vulnerability management, and security tooling administration with a proactive approach to improving detection, response, and operational efficiency.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related field preferred
  • 3+ years of experience in cybersecurity operations or a related technical role
  • Relevant certifications such as CompTIA Security+, CySA+, SecurityX, or similar required
  • Hands-on experience supporting vulnerability management programs
  • Experience with endpoint security tools (e.g., AV, EDR, XDR platforms)
  • Understanding of common attack techniques, threat actors, and incident response methodologies
  • Familiarity with ticketing systems and ITSM processes
  • Strong documentation skills with the ability to clearly communicate findings and recommendations
  • Analytical and problem-solving mindset
  • Ability to balance reactive incident response with proactive security improvements

Nice To Haves

  • GIAC certifications (e.g., GCIH, GCED, GCIA)
  • Experience working with SIEM platforms and alert triage workflows
  • Experience supporting enterprise environments (on-premises and cloud)
  • Prior experience working in or alongside a 24/7 SOC environment

Responsibilities

  • Investigate, validate, and respond to security alerts and incidents escalated from a 24/7 SOC
  • Perform event triage, root cause analysis, and containment actions in collaboration with internal teams
  • Document incidents, investigations, and response activities in accordance with established procedures
  • Participate in incident response exercises, post-incident reviews, and lessons learned activities
  • Execute day-to-day vulnerability management processes, including identification and tracking of risks
  • Partner with infrastructure and application teams to drive timely remediation of vulnerabilities
  • Support the operation, maintenance, and optimization of security platforms, systems, and services
  • Administer and maintain security tools such as endpoint protection platforms (AV, EDR, XDR) and vulnerability scanning solutions
  • Tune detection rules, alerts, and operational policies to improve accuracy and reduce false positives
  • Contribute to security improvement initiatives aligned with organizational risk priorities
  • Assist in developing and enhancing SOC processes, playbooks, and runbooks
  • Identify opportunities to automate repetitive tasks and improve operational efficiency
  • Support audits, assessments, and compliance activities by producing evidence and assisting with remediation efforts
  • Ensure security operations align with internal policies and external regulatory requirements
  • Stay current on emerging threats, vulnerabilities, and industry best practices
  • Apply threat intelligence to enhance detection and response capabilities

Benefits

  • top performance is rewarded
  • personal time is valued
  • excellence is demanded at every level
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service