FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity threat monitoring and incident response, with a strong focus on Microsoft 365 environments and compliance with CMMC and NIST SP 800-171 standards. Proficient in utilizing SIEM tools, endpoint detection, and automation workflows to effectively manage and remediate security incidents.
Highest-signal resume keywords
Cybersecurity Threat MonitoringIncident ResponseMicrosoft 365 SecuritySIEM OperationsCompTIA Security+ Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseSIEM OperationsLog AnalysisEndpoint Detection And ResponseVulnerability ScanningPowerShell ScriptingKQL ProficiencyAutomation WorkflowsMicrosoft 365 AdministrationActive Directory Management
Soft Skills
Professional CommunicationSelf-ManagementDocumentation HabitsReliability
Tools & Technologies
SIEM PlatformsEmail Security ControlsTines AutomationIdentity Protection ToolsEndpoint Security Platforms
Certifications & Qualifications
CompTIA Security+CompTIA Network+
Industry Keywords
CMMC ComplianceNIST SP 800-171MITRE ATT&CK FrameworkSecurity OperationsShift-Based Environment
Tech Stack
Tools & technologiesCyber SecurityDNSFirewallsTCP/IP
About the role
Key responsibilities & impact- Monitor client environments continuously for cybersecurity threats using SIEM, endpoint detection and response, identity protection, and email security platforms
- Own the live alert queue during each shift; triage detections, determine scope and severity, and execute or authorize appropriate responses
- Conduct structured shift handoffs and ensure every detection, investigation, and client commitment has a clear owner
- Investigate account compromise, business email compromise, social engineering, malware, and ransomware incidents
- Analyze servers, workstations, identities, and other potentially compromised assets
- Contain and remediate confirmed threats using automation workflows, scripts, policies, playbooks, and platform controls
- Escalate incidents according to the incident response plan when they exceed the analyst’s authority or expertise
- Provide timely, professional incident communications to clients and internal stakeholders
- Perform scheduled vulnerability scanning across client environments
- Support CMMC and NIST SP 800-171 compliance objectives by producing required monitoring evidence, logs, and reports
- Review overnight Tines automation logs, validate automated actions, and remediate or escalate exceptions
- Respond to overnight escalations while on call and document all actions
- Identify repetitive manual work and false positives for automation or detection tuning
- Test and provide structured feedback on new detections and automation workflows
- Track and document all work in the ticketing system
- Meet KPIs, support peers across both shifts, and escalate assignments when necessary
Requirements
What you’ll need- Two or more years of experience in security operations, incident response, or systems administration with a demonstrable security focus
- Demonstrated experience investigating and responding to identity, endpoint, and email-based threats in Microsoft 365 environments
- Working knowledge of SIEM operations, log analysis, and alert triage methodology
- Understanding of common attack techniques and the MITRE ATT&CK framework
- Familiarity with endpoint detection and response, identity protection, and email security controls and remediation actions
- Ability to perform disciplined, well-documented investigations
- Solid understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit logging
- Working knowledge of Windows server and workstation operating systems, Active Directory, TCP/IP, DNS, firewalls, and VPN
- Familiarity with vulnerability scanning platforms and remediation workflows
- Comfort validating and troubleshooting automated playbooks, including Tines or comparable SOAR tooling
- Basic scripting or query proficiency in PowerShell, KQL, or similar
- Disciplined ticket hygiene and documentation habits
- Ability to write clear, professional client-facing communications
- Reliability and self-management appropriate to a remote, shift-based role
- CompTIA Security+ certification, or attainment within the first six months
- CompTIA Network+ certification, or attainment within the first six months
- Must be willing to work EST hours
- Managed service provider experience is strongly preferred
- Experience supporting CMMC, NIST SP 800-171, or similar regulatory frameworks is desirable
- Prior detection engineering or automation playbook development experience is desirable
- Experience in a 24x7 or shift-based security operations environment is desirable
Benefits
Comp & perks- Medical Insurance — OSIbeyond pays 75% of the premium for the Employee's base medical plan
- Vision and Dental Insurance — OSIbeyond pays 75% of the premium for the Employee's plans
- Life Insurance — OSIbeyond pays 100% of the premium for the Employee's plans
- Short Term Disability Insurance — OSIbeyond pays 100% of the premium for the Employee's plans
- 401K with employer matching up to 4%
- 9 paid holidays
- Accrual-based PTO increasing with tenure; new hires start with 2 weeks
