Security Operations Engineer
Security Operations Engineer
If you're a security professional who likes getting into the technology, solving problems, and owning more than one narrow piece of the stack, this is an opportunity to have real impact across a growing security environment.
District Partners has been engaged by an established professional organization to identify a Security Operations Engineer who will have meaningful ownership across security operations, cloud, identity, endpoint protection, automation, and infrastructure security. This is a small, highly technical environment where your work is visible, your ideas matter, and you'll have the opportunity to directly influence how the organization's security capabilities continue to evolve.
The ideal candidate built their foundation in systems administration, infrastructure, networking, or IT operations before moving deeper into cybersecurity. Security operations and DevSecOps will be the primary focus, but you need to understand how the technology underneath the security tools actually works. You'll troubleshoot, investigate, script, automate, and get into the weeds.
This is also a true small-shop environment. There are no layers of specialized teams to hand work off to. You need to be someone who will take on whatever needs to get done, whether that's a complex security investigation or a straightforward IT issue. No task is beneath the role.
Why You'll Actually Care
You'll have broad ownership across CrowdStrike, Cloudflare, Azure security, identity, endpoint protection, vulnerability management, zero trust, incident response, automation, and infrastructure security. Current initiatives include identity and zero-trust modernization, security automation, AI governance, security awareness, and continued investment across the security stack.
The strongest career progression will often look something like:
IT Operations / Systems Administration / Infrastructure → Security Operations / Cybersecurity
This is not a narrowly siloed enterprise security role. The right person is technically curious, resourceful, and comfortable moving between deep security work and fundamental IT operations. You should be equally willing to investigate a security event, troubleshoot a networking or endpoint issue, work through an integration, or handle a relatively simple technical problem because it needs to get done.
If you're accustomed to owning only one piece of the technology stack and handing everything else to another team, this probably isn't the right environment. If you like having broad ownership, getting into the weeds, and being the person who figures things out, you'll have plenty of opportunity to do that here.
What You'll Be Owning
- Monitor, investigate, and respond to security events and incidents
- Work extensively within CrowdStrike and Cloudflare
- Support Azure security and Microsoft Defender, Sentinel, Entra ID, and Conditional Access
- Drive vulnerability identification, remediation, and ongoing vulnerability management
- Support identity, authentication, endpoint security, and zero-trust initiatives
- Troubleshoot issues across networks, endpoints, operating systems, cloud, and infrastructure
- Use PowerShell, Python, APIs, scripting, and automation to improve security operations and integrations
- Partner across IT to identify and remediate security risks
- Support security awareness, governance, risk, audit, and policy initiatives
- Jump into broader IT and infrastructure needs when necessary
- Proactively identify and own problems rather than waiting for work to be assigned
What You Bring to the Table
- 2-5 years of relevant hands-on experience across cybersecurity and IT operations
- Experience working in a small or lean IT environment where you personally owned problems across multiple technical areas
- Strong foundation in systems administration, infrastructure, networking, or IT operations
- Practical, hands-on cybersecurity experience with security operations as a primary focus
- CrowdStrike and Cloudflare experience strongly preferred, or meaningful experience with comparable enterprise security platforms
- Experience supporting security within Microsoft Azure
- Knowledge of Defender, Sentinel, Entra ID, Conditional Access, or related Microsoft security technologies
- Strong understanding of networking, TCP/IP, DNS, operating systems, endpoints, identity, and enterprise infrastructure
- Experience with incident response, vulnerability management, endpoint security, and cloud security
- Experience with PowerShell, Python, APIs, scripting, automation, or orchestration
- Ability to independently troubleshoot technical problems from the infrastructure layer through the security layer
- Ability to step into the existing environment and contribute without extensive training on fundamental IT or security concepts
- Willingness to take ownership of both complex and routine technical work
- Strong communication skills with the ability to clearly and specifically explain your own technical work, projects, troubleshooting approach, and decisions
Preferred Qualifications
- Direct CrowdStrike and Cloudflare experience
- Fortinet and zero-trust experience
- DevSecOps or security automation exposure
- Identity security / IAM experience
- Security+, CISSP, SC-200, AZ-500, or similar certifications
A Few Things Worth Knowing
- Compensation: $102,000-$120,000 depending on experience
- Onsite 5 days per week for the first 3 months
- Potential to work from home up to 2 days per week after the first 3 months
Required Skills
Required Languages
🇬🇧 English