Falcon Smart IT is seeking a Security Engineer to lead the installation, configuration, and management of enterprise security platforms. This senior-level role will serve as the top escalation point within the Security Operations team, requiring deep expertise in a modern security tool stack.
Responsibilities:
- Responsible for the engineering, installation, configuration, maintenance, and upgrade of enterprise security platforms supporting 11:11 customers and internal infrastructure
- Develop and review system and security designs to ensure compliance with corporate security policies and industry best practices
- Implement and support security technology solutions across endpoint, network, cloud, and data protection domains in accordance with best practices and company policies
- Provide advanced, multi-layered technical support to the customer base through services delivered by the Security Operations team
- Review and resolve security anomalies and incidents that are broad and potentially service impacting. Escalate to appropriate resource or management if necessary
- Act as the Tier 3 escalation point for customer issues and internal work units
- Serve as a liaison with customers, vendors, and other third-party providers to troubleshoot issues or participate in design sessions
- Ability to accurately track issues in the ticketing system while providing timely updates to customers on progress and resolution
- Create and maintain technical documentation including runbooks, configuration standards, and operational procedures
- Obtain and maintain technical certifications to further knowledge of products and services offered by the company
- All other duties as assigned by Manager
- Work supportively with colleagues, operating in a manner that is consistent with 11:11’s Code of Business Ethics and Company Values
- Responsibly receive, transmit, and handle company data and information per Company data handling agreements, work procedures, and policies
- Review and follow company policies and guidelines, data privacy practices, including annual compliance training certification and policy acknowledgements
- Additional duties as assigned
Requirements:
- 5+ years of security engineering or security operations experience in a senior or Tier 3 capacity
- Extensive experience with installation, configuration, and administration of Thales CipherTrust Transparent Encryption (CTE) across Linux and Windows platforms
- Extensive experience with Microsoft Sentinel, including data connector configuration, Log Analytics workspace design, analytics rules, workbooks, and automation playbooks
- Extensive experience writing advanced KQL queries for detection engineering, threat hunting, and incident investigation
- Extensive experience with ThreatX for web application and API protection, including policy configuration and behavioral rule tuning
- Extensive experience with Cortex XDR, including agent deployment, policy configuration, and endpoint incident response
- Extensive experience with Palo Alto Networks next-generation firewalls and Panorama
- Extensive experience with Azure security tools including Azure Arc, Microsoft Defender for Cloud, Azure Monitor, and Data Collection Rules (DCRs)
- In-depth experience administering and hardening Linux operating systems, specifically Ubuntu and RHEL
- In-depth experience administering and hardening Windows operating systems, including Windows 10, 11, and Windows Server
- Proficiency in scripting languages such as Python, PowerShell, or Bash for security automation and configuration tasks
- Strong analytical and problem-solving skills with the ability to operate effectively under pressure in a fast-paced environment
- Excellent written and verbal communication skills, including the ability to convey technical concepts to non-technical stakeholders
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience
- Relevant certifications preferred: Microsoft SC-200 (Security Operations Analyst), PCNSE (Palo Alto Networks Certified Network Security Engineer), CEH, AZ-500 (Azure Security Engineer), or equivalent