Back to search
Fortified Health Security Linkedin · Posted yesterday

Threat Defense Engineer

Brentwood

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Job Summary

The Threat Defense Engineer is responsible for engineering, implementing, optimizing, and maturing the technologies and technical processes that support Fortified’s managed security services. Operating within a multi-client Managed Security Service Provider (MSSP) environment, the Engineer serves as a subject matter expert across SIEM, EDR/MDR, IoMT, DLP, cloud, network, identity, and other security technologies used in service delivery. The role focuses on security platform health, detection engineering, telemetry and log management, technical troubleshooting, automation, standardization, and resolving complex service-impacting issues. The Engineer works closely with clients, Security Operations, Threat Hunting, Incident Response, internal engineering teams, and technology vendors to ensure services are scalable, reliable, repeatable, and effective. The role also supports client onboarding, technicalmeetings, architecture discussions, training, and pre- and post-sales activities, with a focus on driving security, standardization, efficiency, and continuous service improvement.

Essential Job Functions

The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.


Responsibilities include:

  1. · Provide deep technical understanding of tools and processes used to support the delivery of Fortified’s managed services.
  2. · Engineer, implement, configure, maintain, and optimize SIEM, EDR/MDR, IoMT, DLP, cloud, network, identity, and related security technologies.
  3. · Partner with clients on onboarding, implementation, configuration, service health reviews, and technical improvements across supported lines of business.
  4. · Partner with clients on service implementation and delivery of all LOBs including but not limited to: Managed SIEM, EDR, IoMT, & DLP
  5. · Support multi-tenant MSSP environments by promoting standardized, repeatable configurations while accounting for documented client-specific requirements.
  6. · Monitor and maintain the health, availability, performance, connectivity, and effectiveness of security platforms and integrations.
  7. · Troubleshoot complex issues involving agents, APIs, collectors, log forwarding, authentication, networking, integrations, and security data pipelines.
  8. · Provide guidance on log source ingestion, parsing, normalization, filtering, retention, validation, and telemetry quality.
  9. · Design, create, test, tune, and maintain detections, correlation rules, suppression logic, exclusions, watchlists, and other security content.
  10. · Analyze alert volume, false positives, and detection performance to improve actionable security coverage without reducing necessary visibility.
  11. · Perform advanced technical investigations and root cause analysis for security platform issues, escalations, detection gaps, and service-impacting events.
  12. · Develop scripts, API integrations, automation, and internal tooling to improve operational efficiency and reduce repetitive manual processes.
  13. · Create reusable engineering standards, configuration baselines, templates, and workflows that improve scalability and consistency across the client base.
  14. · Validate security telemetry and detection coverage to identify logging, visibility, integration, and control gaps.
  15. · Work directly with technology vendors to troubleshoot defects, resolve escalations, evaluate capabilities, and improve platform integrations.
  16. · Support Threat Hunting and Incident Response activities through telemetry enablement, query development, technical analysis, and detection validation.
  17. · Collaborate with Security Operations, Threat Hunting, Incident Response, and Engineering teams to ensure strong knowledge transfer and effective escalation paths.
  18. · Create, maintain, and mature Standard Operating Procedures (SOPs), architecture documentation, troubleshooting guides, implementation standards, and training materials.
  19. · Mentor junior technical staff on security platforms, investigation techniques, detection logic, troubleshooting, and engineering concepts.
  20. · Lead technical presentations, demonstrations, workshops, architecture discussions, customer training, and solution design sessions for internal and external stakeholders.
  21. · Provide pre-sales and post-sales technical support, including solution recommendations, architecture guidance, demonstrations, and technical validation as needed.
  22. · Maintain current knowledge of security technologies, emerging threats, industry trends, and healthcare security requirements, and ensure HIPAA Privacy and Security responsibilities are consistently followed.

Knowledge & Skills

Education & Experience

  1. · Bachelor's Degree in Computer Science, Management Information Systems, or other relevant combination of training and experience
  2. · 2+ years operating in an MSSP, MDR provider, enterprise SOC, or similar multi-client security environment

· 3+ years of hands-on experience administering, engineering, or supporting enterprise security platforms

· 3+ years of professional cybersecurity experience

  1. · Experience supporting complex, distributed, or multi-tenant security environments
  2. · Advanced systems administration, integration, and technical troubleshooting experience
  3. · Healthcare industry experience preferred; familiarity with HIPAA, HITRUST, NIST, and other relevant security frameworks

Special Skills & Knowledge

· Proficient understanding of the following subject matters/skills:

  1. o Incident Response, Team building, Motivating, Arbitration & Consensus, Compliance Frameworks (NIST, HIPAA, HITRUST, PCI)
  2. · Expert understanding of the following subject matters/skills:
  3. o SIEM engineering, log management, correlation logic, detection engineering, tuning, and alert generation
  4. o EDR/XDR/MDR administration, endpoint security technologies, and security platform integrations
  5. · LevelBlue / USM Anywhere / USM Central, Microsoft Sentinel & Defender, Splunk, SentinelOne, CrowdStrike, Palo Alto Cortex, Detection & Suppression Rule Management, Scripting (Python, Bash, PowerShell), REST APIs, Automation, MITRE ATT&CK, Root Cause Analysis, Advanced Documentation, Security Platform Health Management, Security Platform Log Analysis, Windows & Linux Security Events, and MSSP Operational Knowledge
  6. · Solid understanding of intrusion detection/prevention systems, firewalls, endpoint detection & response systems, anti-virus technologies, DLP, vulnerability management, cloud infrastructure, and related security controls
  7. · Solid understanding of network security, identity security, cloud security, and defense-in-depth concepts
  8. · Strong understanding of log source onboarding, telemetry management, forwarding, parsing, normalization, data quality, and security data pipeline troubleshooting
  9. · Demonstrated ability to analyze, investigate, tune, and remediate security platform issues, detections, and complex technical escalations
  10. · Advanced knowledge of the current threat landscape, including threat actors, APT activity, ransomware, cyber-crime, and attacker tactics, techniques, and procedures
  11. · Advanced understanding of the OSI model, network protocols, Windows and Linux security events, cloud telemetry, authentication, and information security concepts


Licenses, Certifications, etc.

Preferred, but not required: SANS certifications, CompTIA Security+, CompTIA CySA+, Splunk Core Certified Power User, GIAC GCIA, GIAC GCDA, Cisco CyberOps, and AWS Certified Security – Specialty.

Requirements

Supervisory Responsibility

· Provide technical mentorship and guidance to junior engineers and SOC analysts

· No direct HR responsibilities for employees


Working Conditions & Travel Requirements

· Must be willing to travel up to 5%

· Hybrid role in Brentwood, TN

· Capable of communication with clients via conference calls or emails to review and discuss alert data and security report findings


Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search