Lead, Information Security Systems Engineer

RiseMe

Greenville (TX)

Hybrid

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

RiseMe is seeking a Lead Incident Response and Security Operations Engineer to establish and evolve the security operations across a hybrid environment including AWS, data centers, and corporate locations. You will oversee monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen confidentiality, integrity, and availability.

You will develop response plans, playbooks, and after-action reports, while coordinating remediation for vulnerabilities and

Qualifications

  • Active US Secret clearance or higher required.
  • Experience in security operations and incident response.
  • Hybrid-cloud environments experience, AWS and on-prem.
  • Strong documentation, ticketing, and stakeholder communications.

Responsibilities

  • Lead incident response across AWS, datacenter, network, endpoint, and corporate environments.
  • Develop and maintain incident-response plans, escalation paths, and runbooks.
  • Coordinate remediation tracking for vulnerabilities, findings, and corrective actions.
  • Produce security-operations metrics, risk reports, and stakeholder briefings.
  • Onboard and maintain log sources and integrations to support monitoring and audits.

Skills

Incident response
Security operations
Threat hunting
Hybrid-cloud
Log analysis

Education

Bachelor’s Degree
Graduate Degree
13+ years experience in lieu of degree

Tools

Splunk
Wazuh
AWS security
SIEM design

Job description

Job Title: Lead, Information Security Systems Engineer
Job Code: 44627
Job Location: Greenville, TX
Schedule: 9/80 - Employees work 9 out of every 14 days – totaling 80 hours worked – and have every other Friday off
Job Description:

The Lead Incident Response and Security Operations Engineer establish, operates, and continuously improves the Enterprise Product and Services’ incident response and security operations capability across a government-owned, contractor-operated hybrid environment that includes Amazon Web Services (AWS), multiple data centers, and a corporate location.

The role leads monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen the availability, integrity, and confidentiality of GSS services.

Infrastructure, system, and application owners retain responsibility for technical remediation, patching, and platform repair.

Essential Functions:
  • 15% travel based on business needs (CONUS or OCONUS).
  • Ability to work a flexible schedule includes off-shift work, weekends, occasional overtime, and on-call duties.
  • Establish and maintain security information and event management operations, including Wazuh health, log ingestion, data-quality validation, alert rules, dashboards, and detection tuning.
  • Monitor, triage, investigate, document, and coordinate response to security events across AWS, datacenter, network, endpoint, and corporate environments.
  • Create and manage security-incident tickets; preserve investigation evidence; document findings and actions; and validate closure with responsible technical owners.
  • Develop and maintain incident-response plans, escalation paths, severity criteria, playbooks, runbooks, and after-action reports.
  • Coordinate remediation tracking for vulnerabilities, security findings, and incident corrective actions, escalating overdue or material risk.
  • Conduct AWS security-alert and exposure reviews, including identity and access management, privileged access, logging, and cloud-security findings within assigned authority.
  • Onboard and maintain log sources and integrations needed to support monitoring, detection, incident investigation, and compliance evidence.
  • Conduct periodic reviews of privileged access, security-tool access, and operational logging coverage; support disaster-recovery and incident-response exercises.
  • Produce security-operations metrics, risk reports, and stakeholder briefings, and maintain documentation supporting the Risk Management Framework, audit readiness, and continuous monitoring.
Qualifications:
  • Active US Secret security clearance or higher.
  • Bachelor’s Degree and minimum 9 years of prior relevant experience.
  • Graduate Degree and a minimum of 7 years of prior related experience.
  • In lieu of a degree, a minimum of 13 years of prior related experience.
  • Current in at least one of the following; Certified Information Security Manager, Certified Information Systems Auditor, Certified Cloud Security Professional, Certificate of Cloud Security Knowledge, or comparable Department of Defense 8140 certification.
  • Minimum 8 years of security operations, incident response, or security engineering experience.
  • Demonstrated experience operating or engineering a security information and event management platform, developing detection rules, validating log ingestion, and tuning alerts.
  • Demonstrated experience with incident triage, investigation, evidence handling, ticket management, stakeholder communications, and closure documentation.
  • Demonstrated experience supporting hybrid-cloud environments, including AWS and on-premises data-center infrastructure.
Preferred Additional Skills
  • Knowledge of Windows, Linux, networking, identity and access management, security logging, and vulnerability-management processes.
  • Experience with SIEM, Logging and Monitoring infrastructure design, operation management
  • Splunk, Wazuh, SysAid, AWS security services, or comparable security information and event management, information technology service management, and cloud-security platforms.
  • Experience with MITRE ATT&CK, detection engineering, threat hunting, and alert use-case development.
  • Experience developing or maintaining incident-response and disaster-recovery plans, playbooks, tabletop exercises, or technical exercises.
  • Experience with plans of action and milestones, audit evidence, security assessments, and government compliance environments.
  • CISSP, CISM, CCSP, GCIH, GCIA, CySA+, Security+, AWS Certified Security - Specialty, or comparable certification.
  • Experience supporting government-owned, contractor-operated systems and multi-site operations.
  • Experience with Risk Management Framework assessment and authorization activities, National Institute of Standards and Technology Special Publication 800-53 controls, or Platform Information Technology environments.

#LI-AM2

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer / Lead
Senior Security Operations Engineer / Lead

Elan Partners • United States

On-site
USD 150,000 - 190,000
Consulting/Principal Security Engineer
Consulting/Principal Security Engineer

RELX • Raleigh (NC)

On-site
USD 104,900 - 174,700
Security System Administrator, Lead
Security System Administrator, Lead

CL 1e6d8f31 073f 48cd b324 b581c00084bf • Washington

Hybrid
USD 100,000 - 130,000
Cybersecurity Analyst V | Entp Information Security
Cybersecurity Analyst V | Entp Information Security

Texas Attorney General • Austin (TX)

Hybrid
USD 120,000 - 180,000
Benefits package
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Lead Security Engineer
Lead Security Engineer

Compunnel, Inc. • Washington, Northern (KY)

Hybrid
USD 140,000 - 210,000
Senior SecOps Engineer - Dallas
Senior SecOps Engineer - Dallas

Island • Dallas (TX)

On-site
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Huntsville (AL)

On-site
USD 90,000 - 130,000
Cybersecurity Lead
Cybersecurity Lead

Leader Communications Inc. (LCI) • Alexandria (VA)

On-site
USD 90,000 - 120,000