Security Engineer positions focus on delivering results in their domain. This page aggregates open Security Engineer roles and what employers typically expect.
**Security Operations & Production Security Engineer** **Role Summary** We are looking for a mid-level Security Operations & Production Security Engineer to support Realtime’s growing security, architecture, and production operation's needs. This role will bridge security operations, detection engineering, incident response, cloud/identity security, and production readiness. The ideal candidate is hands-on, adaptable, and comfortable wearing multiple hats in a small team. This person will help operate and improve our security monitoring stack, support incident response, tune detections, maintain runbooks, validate security controls, coordinate with managed SOC/MDR partners, and help ensure systems are secure, observable, supportable, and ready for Day 2 operations. This role is best suited for someone who has strong SOC experience but wants to grow into security engineering, production support, automation, and architecture-adjacent responsibilities. **Why This Role Is Needed** Realtime’s security team is small and needs someone who can sit between the Security Architect and the Junior Analyst. The Security Architect should stay focused on architecture, governance, risk, security strategy, control design, and executive-level decision support. The Junior Analyst can help with monitoring, ticketing, and basic triage. This role fills the operational gap by owning the hands-on security engineering and production security work: detection tuning, incident coordination, tool administration, Jira/Slack workflow hygiene, runbooks, dashboards, Identity management, evidence collection, and day-to-day security operations. **Key Responsibilities** Security Operations & Monitoring - Monitor and triage alerts across Microsoft Defender, Sentinel, Huntress/MDR, Wiz, Datadog, Jira, and Slack channels. - Validate alert severity, business impact, affected assets, containment status, and escalation requirements. - Coordinate security events from initial triage through containment, documentation, closure, and post-incident follow-up. - Support daily dashboard review, security ticket queues, alert quality checks, and operational reporting. Detection Engineering & Tuning - Develop, tune, and maintain detection logic in Huntress, Defender, KQL, and related tools. - Reduce false positives and alert noise by reviewing recurring detections, suppression logic, enrichment opportunities, and escalation criteria. - Help build and improve alert runbooks, investigation workflows, and playbooks for phishing, malware, suspicious sign-ins, cloud exposure, endpoint events, and account compromise. - Support basic SOAR/automation efforts using Logic Apps, playbooks, webhooks, or other workflow tools. Incident Response & Production Security - Assist with incident response for endpoint, identity, cloud, email, and suspicious activity events. - Coordinate containment actions such as endpoint isolation, identity reset, access revocation, escalation to Tier 2/Tier 3 SOC, and follow-up remediation. - Maintain incident timelines, evidence, RCA notes, lessons learned, and closure documentation. - Help ensure P1/P2 incidents have clear communication, structured Slack threads, linked Jira tickets, and documented executive summaries when needed. Cloud, Identity & Endpoint Security - Support security operations across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Azure, endpoint protection, and cloud risk tools. - Help review suspicious sign-ins, MFA/SSO issues, risky users, privileged account activity, and access control gaps. - Assist with cloud exposure triage from Wiz or similar tools, including severity validation, ticket routing, and remediation tracking. - Support least-privilege reviews, conditional access validation, endpoint security posture, and security control checks. Production Readiness & Change Support - Support the Day 0 / Day 1 / Day 2 operating model by helping confirm that new systems and changes are ready for production from a security operations p…