Security Engineer – Security Operations & Incident Response
Listed on 2026-08-31
-
IT/Tech
Cybersecurity
Security Engineer – Security Operations & Incident Response
At Air Life, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world.
Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer First, Differentiate with Our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work.
Join us!
The Security Engineer – Security Operations & Incident Response is responsible for monitoring, triaging, and investigating security events across Air Life's global environment; leading incident response, containment, and recovery efforts; and continuously improving detection rules, alert quality, and security automation. This role operates and integrates Air Life's SIEM, EDR, vulnerability management, and cloud security tooling, partners with Air Life's managed detection and response provider (Arctic Wolf) and cross-functional Infrastructure, Cloud, IT, and Application teams on remediation, and helps mature Air Life's security operations and incident response capabilities.
Position Qualifications
Knowledge, Skills, & Abilities:
- Strong understanding of security operations concepts, including SIEM platforms, log analysis, and security alert triage.
- Hands-on experience leading incident response activities — detection, containment, eradication, recovery, and post-incident review — in an enterprise environment.
- Experience with detection engineering and alert-rule tuning, including collaborating with an MDR/MSSP provider on tuning and escalation (Arctic Wolf experience preferred).
- Practical knowledge of EDR/endpoint protection platforms (Microsoft Defender preferred), vulnerability management tooling, and cloud security posture management.
- Experience developing and maintaining incident response playbooks, runbooks, and security operations procedures.
- Understanding of Zero Trust architecture principles and their application to security operations and detection design.
- Knowledge of security compliance frameworks (NIST, CIS Controls, ISO 27001, GDPR) with practical application to security operations.
- Familiarity with security automation/orchestration concepts to streamline detection and response workflows.
- Working knowledge of Microsoft Entra Active Directory, including how identity signals inform incident investigation.
- Ability to manage multiple concurrent incidents, projects, and operational tasks in a dynamic environment (Smartsheet experience preferred).
- Strong root cause analysis and technical troubleshooting skills.
- Experience with backup and disaster recovery systems (Rubrik/Azure preferred) as part of recovery operations.
- Experience with KnowBe4 security awareness and phishing simulation administration preferred.
Level of
Experience:
- Minimum of 3–5 years of professional IT experience, including 2+ years in a security operations, incident response, or SOC-focused role.
- Experience in a manufacturing, healthcare, or other regulated enterprise environment preferred.
Level of
Education:
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or related field or equivalent experience.
- Relevant security operations/incident response certification preferred (CompTIA Security+, GCIH, GCFA, or equivalent).
Travel:
Up to 10% as required by the business.
Essential Duties and Responsibilities
- Monitor, triage, and investigate security events and alerts generated by SIEM, EDR, and other security tooling across Air Life's environment.
- Lead incident response activities — detection, containment, eradication, and recovery — and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).