Infrastructure Engineer, Senior
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
Security Operations is a key part of Southland’s cybersecurity program, supporting the monitoring, response, tooling, workflows, and coordination that help protect the company from cyber threats. This role helps improve how Southland detects issues, responds to incidents, manages operational risk, and keeps security work moving across users, endpoints, servers, cloud services, and business systems.
As an Infrastructure Engineer, Senior, you will work with cybersecurity, IT, infrastructure, support, vendors, and business teams to investigate alerts, respond to incidents, follow up on vulnerabilities, and improve operational workflows. This role is hands‑on and helps turn security events into clear action, documentation, and remediation.
Relationship Building/Management- Build strong working relationships with cybersecurity, IT operations, infrastructure, support, vendors, and business teams.
- Serve as a hands‑on resource for operations questions, escalations, incidents, and follow‑up work.
- Work with technical owners so investigation steps, impact, and next actions are clear.
- Build trust by communicating clearly, following through, and staying close to the work.
- Investigate alerts from EDR, SIEM, email, identity, vulnerability, cloud, and endpoint tools.
- Review alert details, logs, user activity, endpoint data, and related context to determine risk.
- Escalate issues clearly when an incident, containment action, or business decision is needed.
- Document findings, decisions, and next steps so work can be tracked and reviewed.
- Support incident response activities, including scoping, containment, remediation, and recovery follow‑up.
- Coordinate with IT, support, infrastructure, and business owners during response and remediation work.
- Follow up on vulnerabilities, misconfigurations, exposure, and operational findings through closure.
- Help reduce disruption by keeping response work organized, practical, and timely.
- Use security operations tools such as EDR, SIEM, email security, identity security, vulnerability management, and ITSM platforms.
- Support tuning, automation, dashboards, playbooks, and data quality improvements.
- Help connect alerts, tickets, evidence, ownership, and remediation status across tools.
- Improve visibility, alert quality, response speed, and reduction of manual work.
- Support rollout of new security tools, monitoring practices, response processes, and operational standards.
- Help analysts, engineers, support teams, and stakeholders understand what is changing.
- Listen to feedback, identify issues early, and recommend practical adjustments.
- Support testing, training, and readiness before new tools or processes go live.
- Document investigations, incident notes, playbooks, runbooks, escalation paths, and decision points.
- Maintain accurate operational data in dashboards, tickets, alerts, and response records.
- Provide day‑to‑day guidance on triage, response, vulnerabilities, and operations questions.
- Share knowledge with peers and help keep procedures and handoffs consistent.
- Identify patterns in alerts, vulnerabilities, incidents, and repeated operational issues.
- Recommend practical improvements to detections, playbooks, dashboards, automation, and workflows.
- Support planning for operations maturity, MSSP/vendor coordination, tooling, and automation.
- Keep up with relevant threat, detection, response, and vulnerability management practices.
Qualifications
- Strong hands‑on security operations, incident response, threat detection, or vulnerability experience.
- Experience with EDR, SIEM, email security, identity security, vulnerability management, ITSM, or similar tools.
- Solid understanding of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).