Security Engineer – Security Operations & Incident Response
AirLife - Grand Rapids, MI
Hiring: Security Engineer – Security Operations & Incident Response Company: AirLife Location: Grand Rapids, MI Job Posted Time: 2026-09-03 11:19:52 Target Skills & Keywords : Azure, GDPR, Root Cause Analysis, SIEM, SOC, Zero Trust About the job Experience: •Minimum of 3–5 years of professional IT experience, including 2+ years in a security operations, incident response, or SOC-focused role. Required Skills: •Monitor, triage, and investigate security events and alerts generated by SIEM, EDR, and other security tooling across AirLife’s environment. •Lead incident response activities — detection, containment, eradication, and recovery — and facilitate post-incident reviews to capture lessons learned and drive corrective actions. •Improve detection rules, alert quality, and response playbooks to reduce false positives and improve mean time to detect and respond. •Operate, configure, and integrate SIEM, EDR, vulnerability management, and cloud security tools to strengthen AirLife’s security posture. •Develop and maintain incident response playbooks, runbooks, and standard operating procedures for common threat scenarios. •Partner with Arctic Wolf (AirLife’s MDR provider) on alert tuning, escalation handling, and investigation of identified threats. •Partner with Infrastructure, Cloud, IT, and Application teams to remediate vulnerabilities, coordinate containment actions, and implement security hardening measures. •Support AirLife’s vulnerability management program, including scan review, prioritization, and remediation tracking. Qualifications: •In-depth knowledge of security operations concepts, including SIEM platforms, log analysis, and security alert triage. •Hands-on experience leading incident response activities — detection, containment, eradication, recovery, and post-incident review — in an enterprise environment. •Practical knowledge of EDR/endpoint protection platforms (Microsoft Defender preferred), vulnerability management tooling, and cloud security posture management. •Understanding of Zero Trust architecture principles and their application to security operations and detection design. •Knowledge of security compliance frameworks (NIST, CIS Controls, ISO 27001, GDPR) with practical application to security operations. •Operational familiarity with security automation/orchestration concepts to streamline detection and response workflows. •Solid functional working knowledge of Microsoft Entra ID and Active Directory, including how identity signals inform incident investigation. •Demonstrated capacity to manage multiple concurrent incidents, projects, and operational tasks in a dynamic environment (Smartsheet experience preferred). •Strong root cause analysis and technical troubleshooting skills. •Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, or related field or equivalent experience. Compensation: •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!