SOC Engineer
Lyra Technology Group
Lyra Technology Group is a private equity-backed holding company that invests in and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group, we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term. SOC Engineer – ImageQuest ImageQuest is looking for an experienced SOC Engineer to serve as the technical backbone of our Security Operations Center. This is a senior technical role focused primarily on escalations and incident response, security tooling ownership, proactive threat hunting, and scripting and automation within a managed services environment. The SOC Engineer is the SOC's primary escalation point, owning confirmed compromises from containment through handoff to the Advisory Services team. The ideal candidate is comfortable building deep, custom policy on the tools our analysts and clients depend on, hunting for threats that automated tooling misses, and reducing manual SOC workload over time. About ImageQuest…. ImageQuest is a Nashville, Tennessee-based managed IT and managed security services provider serving regulated businesses across the United States, including banking, healthcare, insurance, legal, non-profit, and wealth management organizations. Founded in 2007, the company delivers managed IT, cybersecurity, incident response, virtual CISO leadership, compliance consulting, and cloud support, all with a proactive, compliance-focused approach. ImageQuest is part of Lyra Technology Group. Your work as a SOC Engineer will include several components: Escalation & Incident Response Own all escalations and confirmed compromises referred from the SOC Analysts. Investigate and triage escalated alerts to determine severity, scope, and whether a compromise is confirmed. Contain and resolve security incidents before they affect client business operations. Manage internal communication during suspected and confirmed incidents, and work directly with clients to explain the containment and investigation process under time constraints. Serve as backup to the SOC Analysts in responding to inbound alerts as needed. Conduct post-incident debriefs with the Cybersecurity Advisory team. Threat Hunting & Security Monitoring Conduct proactive threat hunting across the client base rather than relying solely on inbound alerts. Continually monitor security intelligence and threat chatter that may affect ImageQuest clients. Maintain a current understanding of the threat landscape relevant to ImageQuest's client industries. Spam Filter & Phishing Escalation Serve as the escalation point for Defender for Office, IronScales, and Mimecast configuration and tuning. Own escalated phishing investigations referred from the SOC Analysts, determining scope and whether further containment is needed. Adjust spam filter policy, including sender and domain blocks, allow lists, and quarantine rules, in response to confirmed phishing campaigns. Coordinate directly with clients on high-impact phishing incidents requiring same-day action. Endpoint & Tooling Ownership Configure and maintain Microsoft Defender for Endpoint, SentinelOne, ThreatLocker, Huntress, and Arctic Wolf across the client base. Build deeper, custom ThreatLocker policy beyond the standard baseline maintained by the SOC Analysts, precise enough to block real threats without breaking legitimate client applications. Investigate tooling gaps and false positives, tuning detection rules to reduce noise reaching the Analyst queue. Automation & Process Improvement Drive scripting and automation improvements across the SOC's alert and ticketing tools to reduce manual, repetitive work. Establish and maintain accurate documentation of SOC processes and incident responses. Pull monthly reports and categorize SOC activity appropriately. Client Onboarding & Advisory Support Support onboarding of new clients, including deployment of security tooling and validation of SOC coverage. Provide technical expertise to Advisory Services during incidents, audits, and cyber insurance claims that require deep technical detail. Participate in cyber incident response tabletop exercises as needed. Documentation & Communication Ensure all client-facing documentation is consistent with ImageQuest format and professional standards. Communicate technical incident details clearly to both technical and non-technical clients and internal stakeholders. Collaborate with the Managed IT team, including the Network Operations Center, Field Technicians, and Service Desk. Participate in occasional on-site client visits and off-site ImageQuest client events. Our ideal SOC Engineer has the following qualifications: 3+ years of proven IT security experience, with hands-on incident response or threat hunting experience. Bachelor's degree in computer science, information technology, or a related field desired. Deep working knowledge of SentinelOne, ThreatLocker, Huntress, and Arctic Wolf, or comparable EDR, application control, SIEM, and MDR platforms. Demonstrated ability to investigate, triage, and contain confirmed security incidents. Working knowledge of a scripting language (e.g., PowerShell) for automation and tooling improvements. Thorough understanding of networks (IP subnetting, TCP/IP, routing, VPN) and common attack vectors. Familiarity with common industry pentesting tools and methodology. Familiarity with regulatory frameworks and guidance, including NIST, CIS Controls, and ISO 27002. Strong analytical and problem-solving skills, with the ability to cut through noise to find the root cause and exercise sound judgment under pressure. Precise and detail-oriented when configuring tools that affect client production environments. Ability to function well in a high-paced, interrupt-driven environment and balance proactive work against active escalations. Strong written and verbal communication skills, with the ability to break down complex technical information for non-technical audiences. Proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Microsoft Teams. Nice to have: familiarity with virtualization technologies and the Microsoft Azure Portal, experience in a managed services or consulting environment, and familiarity with SIEM platforms and vulnerability scanners. Recommended certifications: CompTIA Security+, Network+, or CySA+, and Microsoft SC-200 or SC-300. This role is based in Brentwood, TN and will operate on a hybrid basis, with a base compensation range of $70,000-$75,000. We are seeking a candidate who goes beyond alert triage. The ideal candidate will be comfortable owning incidents end-to-end, making sound decisions with incomplete information, and taking full responsibility for the quality and accuracy of the security tooling our clients depend on. This includes the ability to receive an escalation, quickly distinguish a confirmed compromise from noise, contain the threat, communicate clearly with the client, document the response thoroughly, and hand it off successfully to Advisory Services. If you are an analytical, detail-oriented security professional who enjoys bringing order out of disorder in a managed services environment, we would welcome the opportunity to speak with you.
This job was verified from Greenhouse (US). Applications are completed on the original source.
Apply on the original listing ↗
Something wrong with this job?