About The Position

The Security Engineer – Security Operations & Incident Response is responsible for monitoring, triaging, and investigating security events across AirLife’s global environment; leading incident response, containment, and recovery efforts; and continuously improving detection rules, alert quality, and security automation. This role operates and integrates AirLife’s SIEM, EDR, vulnerability management, and cloud security tooling, partners with AirLife’s managed detection and response provider (Arctic Wolf) and cross-functional Infrastructure, Cloud, IT, and Application teams on remediation, and helps mature AirLife’s security operations and incident response capabilities.

Requirements

  • Strong understanding of security operations concepts, including SIEM platforms, log analysis, and security alert triage.
  • Hands-on experience leading incident response activities — detection, containment, eradication, recovery, and post-incident review — in an enterprise environment.
  • Experience with detection engineering and alert-rule tuning, including collaborating with an MDR/MSSP provider on tuning and escalation (Arctic Wolf experience preferred).
  • Practical knowledge of EDR/endpoint protection platforms (Microsoft Defender preferred), vulnerability management tooling, and cloud security posture management.
  • Experience developing and maintaining incident response playbooks, runbooks, and security operations procedures.
  • Understanding of Zero Trust architecture principles and their application to security operations and detection design.
  • Knowledge of security compliance frameworks (NIST, CIS Controls, ISO 27001, GDPR) with practical application to security operations.
  • Familiarity with security automation/orchestration concepts to streamline detection and response workflows.
  • Working knowledge of Microsoft Entra ID and Active Directory, including how identity signals inform incident investigation.
  • Ability to manage multiple concurrent incidents, projects, and operational tasks in a dynamic environment (Smartsheet experience preferred).
  • Strong root cause analysis and technical troubleshooting skills.
  • Experience with backup and disaster recovery systems (Rubrik/Azure preferred) as part of recovery operations.
  • Minimum of 3–5 years of professional IT experience, including 2+ years in a security operations, incident response, or SOC-focused role.
  • Experience in a manufacturing, healthcare, or other regulated enterprise environment preferred.
  • Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, or related field or equivalent experience.
  • Relevant security operations/incident response certification preferred (CompTIA Security+, GCIH, GCFA, or equivalent).

Nice To Haves

  • Arctic Wolf experience preferred
  • Microsoft Defender preferred
  • Smartsheet experience preferred
  • Experience with KnowBe4 security awareness and phishing simulation administration preferred
  • Experience in a manufacturing, healthcare, or other regulated enterprise environment preferred
  • Relevant security operations/incident response certification preferred (CompTIA Security+, GCIH, GCFA, or equivalent)

Responsibilities

  • Monitor, triage, and investigate security events and alerts generated by SIEM, EDR, and other security tooling across AirLife’s environment.
  • Lead incident response activities — detection, containment, eradication, and recovery — and facilitate post-incident reviews to capture lessons learned and drive corrective actions.
  • Improve detection rules, alert quality, and response playbooks to reduce false positives and improve mean time to detect and respond.
  • Operate, configure, and integrate SIEM, EDR, vulnerability management, and cloud security tools to strengthen AirLife’s security posture.
  • Develop and maintain incident response playbooks, runbooks, and standard operating procedures for common threat scenarios.
  • Partner with Arctic Wolf (AirLife’s MDR provider) on alert tuning, escalation handling, and investigation of identified threats.
  • Partner with Infrastructure, Cloud, IT, and Application teams to remediate vulnerabilities, coordinate containment actions, and implement security hardening measures.
  • Support AirLife’s vulnerability management program, including scan review, prioritization, and remediation tracking.
  • Track operational security metrics (e.g., alert volume, dwell time, time to remediate) and identify recurring risks or trends for leadership reporting.
  • Participate in an on-call or escalation rotation to support after-hours incident response, as applicable.
  • Support KnowBe4 security awareness and phishing simulation administration in coordination with the Security GRC Engineer.
  • Contribute to backup and disaster recovery operations (Rubrik/Azure) as part of incident recovery efforts.
  • Maintain documentation of security operations architecture, detection logic, and incident response procedures.

Benefits

  • medical coverage
  • dental coverage
  • vision coverage
  • 401(k)
  • paid time off
  • paid holidays
  • bereavement leave
  • Employee Assistance Program resources
  • medical leave benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service