Overview In this role you protect MasterMind, a TMS platform, by turning security alerts into actionable intelligence. You will monitor Azure-native and enterprise environments, follow established playbooks, and escalate threats to keep systems and customers safe. You'll work with a SOC-focused team to tune detections, learn from incidents, and grow your expertise. This role offers hands-on threat detection, rapid triage, and meaningful contribution to a fast-paced security program.
Compensation / Benefits- Medical, dental & vision
- Life & AD&D insurance
- Legal & employee assistance
- 401(k) with 4% match
- Flexible PTO
- Giving Back - St. Jude Children's Research Hospital
Responsibilities- Monitor and investigate security alerts in Microsoft Sentinel and Mastery's Azure environment
- Execute documented triage and escalation playbooks and contain or remediate when appropriate
- Document investigation notes clearly for teammates, auditors, or customers
- Apply Cyber Kill Chain and MITRE ATT&CK concepts to identify actual threats
- Escalate context-rich findings to Security Operations Engineer or Team Lead
- Flag false positives and visibility gaps to improve rule tuning
- Take on stretch assignments (basic scripting, log analysis, evidence collection) to grow toward senior SecOps
- Support detection tuning and contribute to ongoing improvements
Key requirements- 2+ years in security operations, IT, or related alert-driven, shift-based role
- Familiarity with SIEM platforms (Microsoft Sentinel or comparable)
- Working knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks
- Eager and coachable
- Clear communicator
- Even-keeled under pressure
- Basic scripting exposure (Python or PowerShell)
- Security+ or equivalent entry-level certification (e.g., SC-200)
- Exposure to Azure or another major cloud platform