Infrastructure Engineer, Senior
Skills
About the role
Position Summary
Security Operations is a key part of Southland’s cybersecurity program, supporting the monitoring, response, tooling, workflows, and coordination that help protect the company from cyber threats. This role helps improve how Southland detects issues, responds to incidents, manages operational risk, and keeps security work moving across users, endpoints, servers, cloud services, and business systems.
As an Infrastructure Engineer, Senior, you will work with cybersecurity, IT, infrastructure, support, vendors, and business teams to investigate alerts, respond to incidents, follow up on vulnerabilities, and improve operational workflows. This role is hands-on and helps turn security events into clear action, documentation, and remediation.
Position Details
Relationship Building/Management
Build strong working relationships with cybersecurity, IT operations, infrastructure, support, vendors, and business teams.
Serve as a hands-on resource for operations questions, escalations, incidents, and follow-up work.
Work with technical owners so investigation steps, impact, and next actions are clear.
Build trust by communicating clearly, following through, and staying close to the work.
Monitoring and Triage
Investigate alerts from EDR, SIEM, email, identity, vulnerability, cloud, and endpoint tools.
Review alert details, logs, user activity, endpoint data, and related context to determine risk.
Escalate issues clearly when an incident, containment action, or business decision is needed.
Document findings, decisions, and next steps so work can be tracked and reviewed.
Incident and Vulnerability Response
Support incident response activities, including scoping, containment, remediation, and recovery follow-up.
Coordinate with IT, support, infrastructure, and business owners during response and remediation work.
Follow up on vulnerabilities, misconfigurations, exposure, and operational findings through closure.
Help reduce disruption by keeping response work organized, practical, and timely.
Technology and Tool Support
Use security operations tools such as EDR, SIEM, email security, identity security, vulnerability management, and ITSM platforms.
Support tuning, automation, dashboards, playbooks, and data quality improvements.
Help connect alerts, tickets, evidence, ownership, and remediation status across tools.
Improve visibility, alert quality, response speed, and reduction of manual work.
Change Management
Support rollout of new security tools, monitoring practices, response processes, and operational standards.
Help analysts, engineers, support teams, and stakeholders understand what is changing.
Listen to feedback, identify issues early, and recommend practical adjustments.
Support testing, training, and readiness before new tools or processes go live.
Support and Documentation
Document investigations, incident notes, playbooks, runbooks, escalation paths, and decision points.
Maintain accurate operational data in dashboards, tickets, alerts, and response records.
Provide day-to-day guidance on triage, response, vulnerabilities, and operations questions.
Share knowledge with peers and help keep procedures and handoffs consistent.
Continuous Improvement
Identify patterns in alerts, vulnerabilities, incidents, and repeated operational issues.
Recommend practical improvements to detections, playbooks, dashboards, automation, and workflows.
Support planning for operations maturity, MSSP/vendor coordination, tooling, and automation.
Keep up with relevant threat, detection, response, and vulnerability management practices.
Qualifications
Strong hands-on security operations, incident response, threat detection, or vulnerability experience.
Experience with EDR, SIEM, email security, identity security, vulnerability management, ITSM, or similar tools.
Solid understanding of alert triage, endpoint security, identity risk, cloud security, and response workflows.
Experience supporting investigations, incidents, vulnerabilities, tool tuning, or process improvement.
Ability to work well with both business stakeholders and technical teams.
Strong communication skills and a practical, straightforward approach.
Ability to sort through technical issues, make sound recommendations, and keep work moving.
Experience with MSSP coordination, incident playbooks, SIEM tuning, or automation is preferred.
Interest in tools that improve visibility, automation, reporting, and day-to-day execution.
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field is preferred.
Minimum 4 – 6 years of experience in cybersecurity, security operations, incident response, IT operations, networking, or related role.
Benefits
As a 100% employee-owned company, we offer a comprehensive benefits package for you and your family:
401(k) plan with 50% company match (no cap) and immediate 100% vesting
Medical, dental, and vision insurance (100% paid for employee)
Annual bonus program based upon performance, achievement, and company profitability
Term life, AD&D insurance, and voluntary life insurance
Disability income protection insurance
Pre-tax flexible spending plans (health and dependent care)
Paid parental leave
Paid holidays, vacation, and personal time
Training/professional development opportunities and company-paid memberships for professional associations and licenses
Wellness benefits
About Southland Industries
To learn more about careers at Southland, explore our career opportunities, follow us on social media, and check out our website.
Pay: Final pay is determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data. For (Colorado/New York City/California/Washington/Maryland/Virginia/DC) this ranges from $91,300.00 - $156,121.00 plus annual incentive, benefits, and retirement program as outlined above.
Contingent Employment: All employment offers are contingent upon successful drug tests, background checks, and professional reference checks. Roles that include driving as an essential job duty will be required to have a successful Motor Vehicle Record check (MVR). We are not able to offer sponsorship of employment at this time.
External Agency Announcement: Its Southland Industries' policy not to accept candidate submissions from recruiting agencies without an active and authorized work order. Candidate ownership can only be established after a bona fide work order is issued by a member of the Southland Industries Talent Acquisition team and the candidate is appropriately submitted through our Applicant Tracking System (ATS).
Compensation
This Platform Engineer role pays $91k-$156k/yr. Within typical range for platform engineer roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.