Sr. Security Operations Engineer

Boyd Group InternationalElmhurst, IL
46d$130,000 - $160,000

About The Position

The Security Operations Engineer (Level 3) serves as a senior technical resource responsible for protecting enterprise systems, networks, and data through daily security monitoring, incident investigations, and escalation handling for recurring or complex issues, and targeted improvements to security controls. This role is highly hands-on and acts as a bridge between infrastructure and enterprise security, implementing approved security configurations, tuning SIEM/EDR and related security tooling, driving automation, standardizing incident and runbook procedures, and strengthening the organization's overall security posture.

Requirements

  • 5+ years of experience in security operations, incident response, and/or infrastructure operations with security ownership.
  • Proficiency in scripting or automation languages such as PowerShell, Python, or Bash to streamline SecOps workflows.
  • Strong understanding of network security, system administration (Windows/Linux), and cloud security principles.
  • Hands-on experience configuring, tuning, and operating SIEM platforms (e.g., Microsoft Sentinel), EDR/XDR solutions, and vulnerability management tools.
  • Experience applying security changes through standard infrastructure change processes and working with infrastructure/application teams to complete remediation.
  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).

Responsibilities

  • Threat Detection & Incident Response: Monitor, triage, and respond to alerts from SIEM, EDR, and other security tools.
  • Lead or coordinate investigations, containment, and remediation of security incidents with infrastructure, network, and application teams through completion.
  • Perform root cause analysis and document corrective/preventive actions for the responsible teams.
  • Maintain incident response playbooks and update them as detections, tooling, or procedures change to ensure consistent handling.
  • Communicate findings and recommendations to technical stakeholders and, as needed, business stakeholders, in an audit-ready manner.
  • Vulnerability Management & Remediation: Perform vulnerability assessments (scheduled scans for servers, endpoints, and key cloud services) and coordinate remediation with IT and application teams based on severity and asset criticality.
  • Manage patching schedules, apply system hardening and secure configuration standards on Infra/Ops-owned platforms, and monitor remediation status to ensure timely closure.
  • Ensure vulnerability and configuration management tools have complete and accurate asset coverage and follow up with owning teams to resolve coverage gaps.
  • Provide regular vulnerability and remediation status reporting to management.
  • Security Operations & Tooling: Tune and maintain SIEM, EDR, and security-related firewall rules to optimize detection, reduce false positives, and address noisy or misconfigured event sources.
  • Ensure SIEM/EDR and other security tooling have complete and healthy log/agent coverage, working with Infrastructure and Enterprise Security to close gaps.
  • Review and promote new or updated detections through the Infra/Ops change process to prevent alert overload and keep rules aligned with Security-approved standards.
  • Develop automation scripts and playbooks (PowerShell, Python) to streamline triage, enrichment, and remediation workflows.
  • Administer and optimize endpoint protection and cloud security tools, including routine health and configuration reviews.
  • Provide and maintain security configurations and evidence for audits and compliance reviews.
  • Security Configuration & Audit Support: Support security assessments, audits, and control reviews by providing security configurations, logs, and monitoring evidence.
  • Translate security policies into deployable operational practices and configurations through established Infra/Ops change processes.
  • Help enforce access management and network segmentation standards in coordination with Infrastructure and Enterprise Security.
  • Continuous Improvement: Maintain detailed documentation of security tooling, detections, configurations, and operational processes.
  • Identify security gaps and operational inefficiencies and propose and implement initiatives to address them.
  • Incorporate lessons learned from incidents and monitoring into runbooks, detections, and configurations.
  • Recommend technical and process improvements to strengthen defenses.
  • Participate in ongoing professional development to stay current with emerging threats, tools, and technologies in cybersecurity.

Benefits

  • Annual Paid Time Off (PTO) plans
  • 2 weeks of Paid Parental Leave for Full time Employees who work a minimum of 30 hours per week
  • 6 paid holidays annually
  • Medical, Prescription Drug, Dental & Vision Insurance effective Day 1
  • 401(k) Retirement Plan with company match
  • Employer Paid Short-Term Disability & Life Insurance
  • Additional Voluntary Life Insurance
  • Continuing Education Opportunities
  • Free Prescription or Non-Prescription Safety Glasses annually
  • Annual Voluntary Uniform Stipend
  • Flexible PTO Plan
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service