SOC Engineer

Lyra Technology Group•Brentwood, TN
•$70,000 - $75,000•Hybrid

About The Position

ImageQuest is looking for an experienced SOC Engineer to serve as the technical backbone of our Security Operations Center. This is a senior technical role focused primarily on escalations and incident response, security tooling ownership, proactive threat hunting, and scripting and automation within a managed services environment. The SOC Engineer is the SOC's primary escalation point, owning confirmed compromises from containment through handoff to the Advisory Services team. The ideal candidate is comfortable building deep, custom policy on the tools our analysts and clients depend on, hunting for threats that automated tooling misses, and reducing manual SOC workload over time. About ImageQuest… ImageQuest is a Nashville, Tennessee-based managed IT and managed security services provider serving regulated businesses across the United States, including banking, healthcare, insurance, legal, non-profit, and wealth management organizations. Founded in 2007, the company delivers managed IT, cybersecurity, incident response, virtual CISO leadership, compliance consulting, and cloud support, all with a proactive, compliance-focused approach. ImageQuest is part of Lyra Technology Group. Your work as a SOC Engineer will include several components:

Requirements

  • 3+ years of proven IT security experience, with hands-on incident response or threat hunting experience.
  • Deep working knowledge of SentinelOne, ThreatLocker, Huntress, and Arctic Wolf, or comparable EDR, application control, SIEM, and MDR platforms.
  • Demonstrated ability to investigate, triage, and contain confirmed security incidents.
  • Working knowledge of a scripting language (e.g., PowerShell) for automation and tooling improvements.
  • Thorough understanding of networks (IP subnetting, TCP/IP, routing, VPN) and common attack vectors.
  • Familiarity with common industry pentesting tools and methodology.
  • Familiarity with regulatory frameworks and guidance, including NIST, CIS Controls, and ISO 27002.
  • Strong analytical and problem-solving skills, with the ability to cut through noise to find the root cause and exercise sound judgment under pressure.
  • Precise and detail-oriented when configuring tools that affect client production environments.
  • Ability to function well in a high-paced, interrupt-driven environment and balance proactive work against active escalations.
  • Strong written and verbal communication skills, with the ability to break down complex technical information for non-technical audiences.
  • Proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Microsoft Teams.

Nice To Haves

  • Bachelor's degree in computer science, information technology, or a related field desired.
  • Familiarity with virtualization technologies and the Microsoft Azure Portal.
  • Experience in a managed services or consulting environment.
  • Familiarity with SIEM platforms and vulnerability scanners.
  • Recommended certifications: CompTIA Security+, Network+, or CySA+, and Microsoft SC-200 or SC-300.

Responsibilities

  • Own all escalations and confirmed compromises referred from the SOC Analysts.
  • Investigate and triage escalated alerts to determine severity, scope, and whether a compromise is confirmed.
  • Contain and resolve security incidents before they affect client business operations.
  • Manage internal communication during suspected and confirmed incidents, and work directly with clients to explain the containment and investigation process under time constraints.
  • Serve as backup to the SOC Analysts in responding to inbound alerts as needed.
  • Conduct post-incident debriefs with the Cybersecurity Advisory team.
  • Conduct proactive threat hunting across the client base rather than relying solely on inbound alerts.
  • Continually monitor security intelligence and threat chatter that may affect ImageQuest clients.
  • Maintain a current understanding of the threat landscape relevant to ImageQuest's client industries.
  • Serve as the escalation point for Defender for Office, IronScales, and Mimecast configuration and tuning.
  • Own escalated phishing investigations referred from the SOC Analysts, determining scope and whether further containment is needed.
  • Adjust spam filter policy, including sender and domain blocks, allow lists, and quarantine rules, in response to confirmed phishing campaigns.
  • Coordinate directly with clients on high-impact phishing incidents requiring same-day action.
  • Configure and maintain Microsoft Defender for Endpoint, SentinelOne, ThreatLocker, Huntress, and Arctic Wolf across the client base.
  • Build deeper, custom ThreatLocker policy beyond the standard baseline maintained by the SOC Analysts, precise enough to block real threats without breaking legitimate client applications.
  • Investigate tooling gaps and false positives, tuning detection rules to reduce noise reaching the Analyst queue.
  • Drive scripting and automation improvements across the SOC's alert and ticketing tools to reduce manual, repetitive work.
  • Establish and maintain accurate documentation of SOC processes and incident responses.
  • Pull monthly reports and categorize SOC activity appropriately.
  • Support onboarding of new clients, including deployment of security tooling and validation of SOC coverage.
  • Provide technical expertise to Advisory Services during incidents, audits, and cyber insurance claims that require deep technical detail.
  • Participate in cyber incident response tabletop exercises as needed.
  • Ensure all client-facing documentation is consistent with ImageQuest format and professional standards.
  • Communicate technical incident details clearly to both technical and non-technical clients and internal stakeholders.
  • Collaborate with the Managed IT team, including the Network Operations Center, Field Technicians, and Service Desk.
  • Participate in occasional on-site client visits and off-site ImageQuest client events.

Benefits

  • Base compensation range of $70,000-$75,000
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service