Threat Defense Engineer

Fortified Health Security

Brentwood (TN)

Hybrid

USD 120,000 - 180,000

Full time

24 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Fortified Health Security in Brentwood, TN seeks a Threat Defense Engineer to design, implement, and optimize security technologies across SIEM, EDR/MDR, IoMT, and cloud platforms. The role emphasizes security platform health, telemetry quality, and automation to improve service delivery for multiple clients.

Responsibilities include onboarding clients, configuring security controls, and developing detections, correlations, and data pipelines.

Qualifications

  • Bachelor's degree or equivalent in CS, MIS, or related field.
  • 2+ years in an MSSP, MDR, enterprise SOC, or multi-client security environment.
  • 3+ years hands-on experience administering or supporting enterprise security platforms.
  • 3+ years professional cybersecurity experience.
  • Experience supporting complex, distributed, multi-tenant security environments.
  • Healthcare security knowledge (HIPAA/HITRUST/NIST) preferred.

Responsibilities

  • Provide deep technical understanding of tools and processes used to support Fortified Health Security’s managed services.
  • Engineer, implement, configure, maintain, and optimize SIEM, EDR/MDR, IoMT, DLP, cloud, network, identity, and related security technologies.
  • Partner with clients on onboarding, implementation, configuration, service health reviews, and technical improvements.
  • Support multi-tenant MSSP environments with standardized configurations while honoring client-specific requirements.
  • Monitor and maintain health, availability, performance, connectivity, and effectiveness of security platforms and integrations.
  • Troubleshoot complex issues involving agents, APIs, collectors, log forwarding, authentication, networking, and data pipelines.
  • Create reusable engineering standards, baselines, templates, and workflows for scalability.
  • Travel up to 5% for client engagements and internal collaboration.

Skills

SIEM
EDR/XDR/MDR
Threat Hunting
Automation
Scripting
Log Management
Security Platform Health

Education

Bachelor's Degree in Computer Science
2+ years MSSP/MDR environment
3+ years enterprise security

Tools

Microsoft Sentinel
Splunk
USM Anywhere
CrowdStrike
Palo Alto Cortex

Job description

The Threat Defense Engineer is responsible for engineering, implementing, optimizing, and maturing the technologies and technical processes that support Fortified’s managed security services. Operating within a multi-client Managed Security Service Provider (MSSP) environment, the Engineer serves as a subject matter expert across SIEM, EDR/MDR, IoMT, DLP, cloud, network, identity, and other security technologies used in service delivery. The role focuses on security platform health, detection engineering, telemetry and log management, technical troubleshooting, automation, standardization, and resolving complex service-impacting issues. The Engineer works closely with clients, Security Operations, Threat Hunting, Incident Response, internal engineering teams, and technology vendors to ensure services are scalable, reliable, repeatable, and effective. The role also supports client onboarding, technicalmeetings, architecture discussions, training, and pre- and post-sales activities, with a focus on driving security, standardization, efficiency, and continuous service improvement.

Essential Job Functions

The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.

Responsibilities include:
  • Provide deep technical understanding of tools and processes used to support the delivery of Fortified’s managed services.
  • Engineer, implement, configure, maintain, and optimize SIEM, EDR/MDR, IoMT, DLP, cloud, network, identity, and related security technologies.
  • Partner with clients on onboarding, implementation, configuration, service health reviews, and technical improvements across supported lines of business.
  • Partner with clients on service implementation and delivery of all LOBs including but not limited to: Managed SIEM, EDR, IoMT, & DLP
  • Support multi-tenant MSSP environments by promoting standardized, repeatable configurations while accounting for documented client‑specific requirements.
  • Monitor and maintain the health, availability, performance, connectivity, and effectiveness of security platforms and integrations.
  • Troubleshoot complex issues involving agents, APIs, collectors, log forwarding, authentication, networking, integrations, and security data pipelines.
  • Provide guidance on log source ingestion, parsing, normalization, filtering, retention, validation, and telemetry quality.
  • Design, create, test, tune, and maintain detections, correlation rules, suppression logic, exclusions, watchlists, and other security content.
  • Analyze alert volume, false positives, and detection performance to improve actionable security coverage without reducing necessary visibility.
  • Perform advanced technical investigations and root cause analysis for security platform issues, escalations, detection gaps, and service-impacting events.
  • Develop scripts, API integrations, automation, and internal tooling to improve operational efficiency and reduce repetitive manual processes.
  • Create reusable engineering standards, configuration baselines, templates, and workflows that improve scalability and consistency across the client base.
  • Validate security telemetry and detection coverage to identify logging, visibility, integration, and control gaps.
  • Work directly with technology vendors to troubleshoot defects, resolve escalations, evaluate capabilities, and improve platform integrations.
  • Support Threat Hunting and Incident Response activities through telemetry enablement, query development, technical analysis, and detection validation.
  • Collaborate with Security Operations, Threat Hunting, Incident Response, and Engineering teams to ensure strong knowledge transfer and effective escalation paths.
  • Create, maintain, and mature Standard Operating Procedures (SOPs), architecture documentation, troubleshooting guides, implementation standards, and training materials.
  • Mentor junior technical staff on security platforms, investigation techniques, detection logic, troubleshooting, and engineering concepts.
  • Lead technical presentations, demonstrations, workshops, architecture discussions, customer training, and solution design sessions for internal and external stakeholders.
  • Provide pre-sales and post-sales technical support, including solution recommendations, architecture guidance, demonstrations, and technical validation as needed.
  • Maintain current knowledge of security technologies, emerging threats, industry trends, and healthcare security requirements, and ensure HIPAA Privacy and Security responsibilities are consistently followed.
Knowledge & Skills
Education & Experience
  • Bachelor's Degree in Computer Science, Management Information Systems, or other relevant combination of training and experience
  • 2+ years operating in an MSSP, MDR provider, enterprise SOC, or similar multi-client security environment
  • 3+ years of hands‑on experience administering, engineering, or supporting enterprise security platforms
  • 3+ years of professional cybersecurity experience
  • Experience supporting complex, distributed, or multi-tenant security environments
  • Advanced systems administration, integration, and technical troubleshooting experience
  • Healthcare industry experience preferred; familiarity with HIPAA, HITRUST, NIST, and other relevant security frameworks
Special Skills & Knowledge
  • Incident Response, Team building, Motivating, Arbitration & Consensus, Compliance Frameworks (NIST, HIPAA, HITRUST, PCI)
  • Expert understanding of the following subject matters/skills:
  • SIEM engineering, log management, correlation logic, detection engineering, tuning, and alert generation
  • EDR/XDR/MDR administration, endpoint security technologies, and security platform integrations
  • LevelBlue / USM Anywhere / USM Central, Microsoft Sentinel & Defender, Splunk, SentinelOne, CrowdStrike, Palo Alto Cortex, Detection & Suppression Rule Management, Scripting (Python, Bash, PowerShell), REST APIs, Automation, MITRE ATT&CK, Root Cause Analysis, Advanced Documentation, Security Platform Health Management, Security Platform Log Analysis, Windows & Linux Security Events, and MSSP Operational Knowledge
  • Solid understanding of intrusion detection/prevention systems, firewalls, endpoint detection & response systems, anti‑virus technologies, DLP, vulnerability management, cloud infrastructure, and related security controls
  • Solid understanding of network security, identity security, cloud security, and defense‑in‑depth concepts
  • Strong understanding of log source onboarding, telemetry management, forwarding, parsing, normalization, data quality, and security data pipeline troubleshooting
  • Demonstrated ability to analyze, investigate, tune, and remediate security platform issues, detections, and complex technical escalations
  • Advanced knowledge of the current threat landscape, including threat actors, APT activity, ransomware, cyber‑crime, and attacker tactics, techniques, and procedures
  • Advanced understanding of the OSI model, network protocols, Windows and Linux security events, cloud telemetry, authentication, and information security concepts

Preferred, but not required: SANS certifications, CompTIA Security+, CompTIA CySA+, Splunk Core Certified Power User, GIAC GCIA, GIAC GCDA, Cisco CyberOps, and AWS Certified Security – Specialty.

Requirements
Supervisory Responsibility
  • Provide technical mentorship and guidance to junior engineers and SOC analysts
  • No direct HR responsibilities for employees
Working Conditions & Travel Requirements
  • Must be willing to travel up to 5%
  • Hybrid role in Brentwood, TN
  • Capable of communication with clients via conference calls or emails to review and discuss alert data and security report findings

Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Solutions Architect
Solutions Architect

Fortified Health Security • Exton (PA)

Hybrid
USD 140,000 - 180,000
Incentive plan
Solutions Architect
Solutions Architect

Silversmith Capital Partners • Exton (PA)

On-site
USD 120,000 - 130,000
Solutions Architect
Solutions Architect

Fortified Health Security • Brentwood (TN)

Hybrid
USD 120,000 - 160,000
Solutions Architect
Solutions Architect

Kids for the Future • Exton (PA)

Hybrid
USD 120,000 - 130,000
Eligible for incentive plan
Solutions Architect
Solutions Architect

Silversmith Capital Partners • Brentwood (TN)

Hybrid
USD 120,000 - 130,000
Incentive plan
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Securiport LLC • Reston (VA)

On-site
USD 110,000 - 170,000
Senior Security Engineer
Senior Security Engineer

HealthDrive • Framingham (MA)

Hybrid
USD 85,000 - 115,000
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Highmark Health • Richmond (VA)

Hybrid
USD 120,000 - 160,000