Security Operations Engineer
Listed on 2025-12-29
-
IT/Tech
Cybersecurity, Network Security
Our goal at FedPoint is to foster an engaging environment for our employees that promotes career growth and supports a work-life balance. From professional development to wellness programs to volunteer opportunities, we have created a culture that puts our employees on a positive pathway to success.
About Fed Point
FedPoint creates and operates digital benefits marketplaces that make it easy forour millions of federal and military customers to understand, select, and use their benefits.
A subsidiary of John Hancock Life & Health Insurance Company, FedPoint was founded in 2002 and is headquartered in Portsmouth, NH.
Our mission
Create and deliver world-class benefits experiences for our customers, clients, and business partners.
Security Operations Engineer
Platform Operations | Enterprise IT & Cloud Security
FedPoint is seeking an experienced Security Operations Engineer to help protect enterprise systems, networks, and data across both traditional and cloud environments. This role is critical to strengthening our security operations capabilities, improving incident response maturity, and supporting a scalable cloud security framework aligned with regulatory and industry best practices.
This is a hybrid role requiring two days per week in the office and offers the opportunity to work on complex security challenges within a regulated enterprise environment.
What You Will DoSecurity Operations (40%)
Perform day-to-day security operations, including monitoring, detection, investigation, and response to cybersecurity threats.
Implement and maintain security technologies across endpoint, network, identity, and cloud environments.
Support and administer tools including EDR, DLP, secure web gateway, email security, IDPS, firewalls, SIEM, and identity protection solutions.
Configure and maintain cloud web filtering tools, including policy design, SAML integration, and performance monitoring.
Install, configure, and support Network Access Control (NAC) solutions in enterprise environments.
Conduct and oversee forensic investigations to determine root cause and prevent recurrence of security incidents.
Review vulnerability findings, assess risk, and partner with infrastructure and application teams to drive remediation.
Lead and mentor IT Security and Infrastructure Engineers on threat detection, prevention, and incident response best practices.
Vulnerability Management (40%)
Support the enterprise Vulnerability Management Program and ensure alignment with risk tolerance and operational priorities.
Classify and prioritize vulnerabilities based on criticality, exposure, and business impact.
Provide operational guidance to IT teams on interpreting scan results and applying effective mitigation strategies.
Support automated and manual patching processes, including systems requiring customized remediation timelines.
Track remediation progress, produce reports, and ensure accountability across stakeholders.
Facilitate regular patch review meetings to identify blockers and align remediation with business constraints.
Incident Response (20%)
Partner with Security Compliance and Policy teams to develop, maintain, and execute the incident response program.
Serve as an on-call cybersecurity escalation point during security incidents.
Detect, analyze, triage, and remediate threats across the enterprise.
Analyze SOC alerts, anomalies, and false positives, escalating issues as appropriate.
Leverage threat intelligence to correlate indicators of compromise and communicate risk to leadership and technical teams.
Maintain situational awareness through daily monitoring of internal and external cybersecurity alerts.
Required QualificationsBachelor’s degree in Cybersecurity, Information Technology, or a related field preferred, or 8+ years of equivalent professional experience
.
Minimum of 5 years of hands‑on cybersecurity experience supporting cloud, endpoint, identity, and network security technologies.
Demonstrated experience administering cloud web filtering solutions
, including architecture, deployment, policy design, and troubleshooting.
Proven experience supporting federal or highly regulated environments
.
Strong working knowledge of network…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).