SOC Engineer
Listed on 2026-10-05
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security
Lyra Technology Group is a p rivate e quity-backed holding company that invests in and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group , we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term.
Image Quest is looking for an experienced SOC Engineer to serve as the technical backbone of our Security Operations Center. This is a senior technical role focused primarily on escalations and incident response, security tooling ownership, proactive threat hunting, and scripting and automation within a managed services environment. The SOC Engineer is the SOC's primary escalation point, owning confirmed compromises from containment through handoff to the Advisory Services team.
The ideal candidate is comfortable building deep, custom policy on the tools our analysts and clients depend on, hunting for threats that automated tooling misses, and reducing manual SOC workload over time.
Image Quest is a Nashville, Tennessee-based managed IT and managed security services provider serving regulated businesses across the United States, including banking, healthcare, insurance, legal, non-profit, and wealth management organizations. Founded in 2007, the company delivers managed IT, cybersecurity, incident response, virtual CISO leadership, compliance consulting, and cloud support, all with a proactive, compliance-focused approach. Image Quest is part of Lyra Technology Group.
Yourwork as a SOC Engineer will include several components:
- Own all escalations and confirmed compromises referred from the SOC Analysts.
- Investigate and triage escalated alerts to determine severity, scope, and whether a compromise is confirmed.
- Contain and resolve security incidents before they affect client business operations.
- Manage internal communication during suspected and confirmed incidents, and work directly with clients to explain the containment and investigation process under time constraints.
- Serve as backup to the SOC Analysts in responding to inbound alerts as needed.
- Conduct post-incident debriefs with the Cybersecurity Advisory team.
- Conduct proactive threat hunting across the client base rather than relying solely on inbound alerts.
- Continually monitor security intelligence and threat chatter that may affect Image Quest clients.
- Maintain a current understanding of the threat landscape relevant to Image Quest's client industries.
- Serve as the escalation point for Defender for Office, Iron Scales, and Mimecast configuration and tuning.
- Own escalated phishing investigations referred from the SOC Analysts, determining scope and whether further containment is needed.
- Adjust spam filter policy, including sender and domain blocks, allow lists, and quarantine rules, in response to confirmed phishing campaigns.
- Coordinate directly with clients on high-impact phishing incidents requiring same-day action.
- Configure and maintain Microsoft Defender for Endpoint, Sentinel One, Threat Locker, Huntress, and Arctic Wolf across the client base.
- Build deeper, custom Threat Locker policy beyond the standard baseline maintained by the SOC Analysts, precise enough to block real threats without breaking legitimate client applications.
- Investigate tooling gaps and false positives, tuning detection rules to reduce noise reaching the Analyst queue.
- Drive scripting and automation improvements across the SOC's alert and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).