Cybersecurity Specialist III
$98,000–$110,000 year
On-siteWestborough, Massachusetts, United States
Job Summary
Triage security alerts across the enterprise estate to establish severity and scope, then investigate confirmed incidents using host, network, identity, and cloud log analysis to determine root cause. Execute containment and eradication steps while producing clear documentation suitable for internal review and audit evidence. Write, tune, and maintain SIEM queries and correlation rules across enterprise log sources, validating parsing and reducing false positives. Operate the recurring vulnerability scanning cycle, prioritizing findings based on severity and exploitability to coordinate remediation with system owners. Administer and tune the EDR platform, creating custom detection rules and investigating endpoint telemetry to improve visibility. Apply cloud security practices across AWS environments, including IAM policy review and monitoring configuration with native services like GuardDuty and Security Hub. Manage identity and access controls, conducting periodic access reviews and supporting certification campaigns for ISO 27001 and SOC 2. Participate in the security on-call rotation and perform security risk assessments of systems and vendors.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field
- Minimum 4 years of hands-on experience in a security operations, security analyst, or cybersecurity specialist role
- Demonstrated experience performing incident response, including alert triage, investigation to root cause, and written documentation of findings
- Hands-on SIEM experience, including writing and tuning queries and working directly with log data (Microsoft Sentinel, Splunk, Elastic, or equivalent)
- Practical vulnerability management experience, including risk-based prioritization and coordinating remediation with system owners
- Working experience with EDR platforms, including custom rule creation and analysis of endpoint telemetry
- Strong working knowledge of AWS services and core cloud security practices, including IAM, logging, monitoring, and posture management
- Applied understanding of identity and access management, including SSO, MFA, and least-privilege access models
- Experience performing or materially contributing to security risk assessments
- Clear technical writing — incident documentation, risk findings, and remediation guidance that a non-specialist owner can act on without translation
- Strong working knowledge of Windows and Linux, and the security controls associated with each
- Scripting and query ability for automation and data analysis (Python, PowerShell, KQL, or SPL)
- Familiarity with risk management and control frameworks: NIST CSF, ISO 27001, SOC 2, and CIS Controls
- Sound judgment under time pressure, with the discipline to escalate appropriately when information is incomplete
- Anticipate travel up to 10%, including periodic visits to LGESVT offices, data center facilities, and HQ as required
Desired Qualifications
- One or more of the following preferred: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC (GSEC, GCIH, or GCIA), CompTIA CySA+ or Security+, or Microsoft SC-200
- Candidates actively working toward an advanced certification are encouraged to apply; certification support is available
- Experience in the energy, utilities, or industrial sectors, or exposure to OT/ICS environments
- Familiarity with battery energy storage, renewable energy, or grid-scale infrastructure
- Prior exposure to ISO 27001 or SOC 2 audit cycles as an evidence provider
- Hands-on experience with Microsoft Entra ID, Microsoft Defender, or Microsoft Purview
- Demonstrated interest in detection engineering, security automation, or infrastructure-as-code
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.