Security Operations Engineer

Richline Group•Tamarac, FL
•$75,000 - $85,000•Hybrid

About The Position

The Security Operations Engineer is responsible for executing and operating enterprise cybersecurity functions across Richline Group subsidiaries. Reporting to the Senior Cybersecurity Analyst / Cybersecurity Lead, this role focuses on vulnerability management, patch coordination, security monitoring, endpoint security, and incident response execution. The position supports a unified cybersecurity stack and works corporately across locations, with a strong emphasis on Microsoft Windows enterprise environments.

Requirements

  • 3-5 years of hands-on experience in security operations, infrastructure security, SOC operations, or a related cybersecurity role.
  • Strong working knowledge of enterprise Microsoft Windows environments, including Windows endpoints, Windows Server, Active Directory, patching, authentication, and security hardening concepts.
  • Hands-on experience working with enterprise EDR/XDR platforms, including alert investigation, endpoint activity review, containment, and remediation support.
  • Experience with vulnerability management and enterprise patch management, including vulnerability review, risk-based prioritization, remediation tracking, and validation.
  • Experience with SIEM and security monitoring platforms, including alert triage, log analysis, investigation, documentation, and escalation.
  • Working knowledge of incident response processes and security investigation practices.
  • General understanding of cloud and internet-facing security controls such as WAF, application protection, bot protection, API security, and cloud security technologies.
  • Strong analytical, troubleshooting, documentation, and communication skills.

Nice To Haves

  • Experience with proactive threat hunting using EDR/XDR technologies and endpoint telemetry is highly desirable.
  • Experience administering enterprise email security platforms and related modules, including phishing and malware protection, URL and attachment analysis, data loss prevention, and cloud/SaaS security capabilities, is a plus but not required.
  • Experience with SOAR, security automation, or playbook development is a plus.
  • Experience supporting security in Microsoft cloud or hybrid environments is preferred.
  • Experience with network security technologies such as firewalls, IDS/IPS, DNS/web security, segmentation, or network traffic analysis is beneficial.

Responsibilities

  • Operate enterprise vulnerability scanning and patch management platforms.
  • Support risk-based patch schedules, remediation priorities, and vulnerability service-level targets across subsidiaries.
  • Coordinate remediation activities with Network, Systems, and Endpoint Administrators.
  • Track remediation progress, validate closure, and produce vulnerability and patch compliance reporting.
  • Support vulnerability exception handling in coordination with GRC and cybersecurity leadership.
  • Monitor and investigate security alerts from SIEM, MDR, EDR/XDR, IDS/IPS, cloud security, and related enterprise security technologies.
  • Perform first-level investigation and triage, identify false positives, document findings, and escalate validated issues when additional action is required.
  • Perform day-to-day operational tasks within enterprise endpoint detection and response platforms, including alert review, endpoint investigation, containment support, and policy-related administration under approved standards.
  • Support tuning and continuous improvement of security monitoring and detection capabilities.
  • Execute incident response activities such as evidence collection, endpoint isolation, containment, remediation support, and documentation.
  • Maintain incident timelines, investigation notes, and supporting evidence.
  • Support post-incident reviews and corrective action tracking.
  • Support the operation and monitoring of cloud and internet-facing security controls, including web application firewalls (WAF), bot management and detection, application and API protection, traffic filtering, and related threat-prevention technologies.
  • Assist with investigation of suspicious web, application, and cloud activity and coordinate remediation or escalation as required.
  • Support security controls across cloud-based and hybrid enterprise environments.
  • Perform day-to-day operational management of cybersecurity tools under approved designs, policies, and standards.
  • Support SOAR playbook execution, workflow automation, and operational security process improvements.
  • Maintain documentation, operational procedures, and technical runbooks for assigned security technologies.
  • Work closely with IT Operations, GRC, application teams, and external security providers to coordinate security activities and remediation.
  • Provide operational metrics, findings, and status reporting to cybersecurity leadership.
  • Participate in security reviews, incident exercises, and continuous improvement initiatives.

Benefits

  • Base pay range: $75,000 - $85,000 annually
  • Total compensation will be determined based on factors such as skills, education, and/or experience.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service