Skip to content

Open nowPosted 3 days ago

SOC Engineer

Lyra Technology Group15 open roles

Pay
$70,000 – $75,000 a year
Where
Brentwood, TN
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSOC EngineerLyra Technology Group · Brentwood, TN
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Lyra Technology Group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Lyra Technology Group postings stay open a median of 2 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 3 days ago

Lyra Technology Group median: 2 days open

The posting

Lyra Technology Group is a private equity-backed holding company that invests in and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group, we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term.

SOC Engineer – ImageQuest

ImageQuest is looking for an experienced SOC Engineer to serve as the technical backbone of our Security Operations Center. This is a senior technical role focused primarily on escalations and incident response, security tooling ownership, proactive threat hunting, and scripting and automation within a managed services environment. The SOC Engineer is the SOC's primary escalation point, owning confirmed compromises from containment through handoff to the Advisory Services team. The ideal candidate is comfortable building deep, custom policy on the tools our analysts and clients depend on, hunting for threats that automated tooling misses, and reducing manual SOC workload over time.

About ImageQuest….

ImageQuest is a Nashville, Tennessee-based managed IT and managed security services provider serving regulated businesses across the United States, including banking, healthcare, insurance, legal, non-profit, and wealth management organizations. Founded in 2007, the company delivers managed IT, cybersecurity, incident response, virtual CISO leadership, compliance consulting, and cloud support, all with a proactive, compliance-focused approach. ImageQuest is part of Lyra Technology Group.

Your work as a SOC Engineer will include several components:

Escalation & Incident Response

  • Own all escalations and confirmed compromises referred from the SOC Analysts.
  • Investigate and triage escalated alerts to determine severity, scope, and whether a compromise is confirmed.
  • Contain and resolve security incidents before they affect client business operations.
  • Manage internal communication during suspected and confirmed incidents, and work directly with clients to explain the containment and investigation process under time constraints.
  • Serve as backup to the SOC Analysts in responding to inbound alerts as needed.
  • Conduct post-incident debriefs with the Cybersecurity Advisory team.

Threat Hunting & Security Monitoring

  • Conduct proactive threat hunting across the client base rather than relying solely on inbound alerts.
  • Continually monitor security intelligence and threat chatter that may affect ImageQuest clients.
  • Maintain a current understanding of the threat landscape relevant to ImageQuest's client industries.

Spam Filter & Phishing Escalation

  • Serve as the escalation point for Defender for Office, IronScales, and Mimecast configuration and tuning.
  • Own escalated phishing investigations referred from the SOC Analysts, determining scope and whether further containment is needed.
  • Adjust spam filter policy, including sender and domain blocks, allow lists, and quarantine rules, in response to confirmed phishing campaigns.
  • Coordinate directly with clients on high-impact phishing incidents requiring same-day action.

Endpoint & Tooling Ownership

  • Configure and maintain Microsoft Defender for Endpoint, SentinelOne, ThreatLocker, Huntress, and Arctic Wolf across the client base.
  • Build deeper, custom ThreatLocker policy beyond the standard baseline maintained by the SOC Analysts, precise enough to block real threats without breaking legitimate client applications.
  • Investigate tooling gaps and false positives, tuning detection rules to reduce noise reaching the Analyst queue.

Automation & Process Improvement

  • Drive scripting and automation improvements across the SOC's alert and ticketing tools to reduce manual, repetitive work.
  • Establish and maintain accurate documentation of SOC processes and incident responses.
  • Pull monthly reports and categorize SOC activity appropriately.

Client Onboarding & Advisory Support

  • Support onboarding of new clients, including deployment of security tooling and validation of SOC coverage.
  • Provide technical expertise to Advisory Services during incidents, audits, and cyber insurance claims that require deep technical detail.
  • Participate in cyber incident response tabletop exercises as needed.

Documentation & Communication

  • Ensure all client-facing documentation is consistent with ImageQuest format and professional standards.
  • Communicate technical incident details clearly to both technical and non-technical clients and internal stakeholders.
  • Collaborate with the Managed IT team, including the Network Operations Center, Field Technicians, and Service Desk.
  • Participate in occasional on-site client visits and off-site ImageQuest client events.

Our ideal SOC Engineer has the following qualifications:

  • 3+ years of proven IT security experience, with hands-on incident response or threat hunting experience.
  • Bachelor's degree in computer science, information technology, or a related field desired.
  • Deep working knowledge of SentinelOne, ThreatLocker, Huntress, and Arctic Wolf, or comparable EDR, application control, SIEM, and MDR platforms.
  • Demonstrated ability to investigate, triage, and contain confirmed security incidents.
  • Working knowledge of a scripting language (e.g., PowerShell) for automation and tooling improvements.
  • Thorough understanding of networks (IP subnetting, TCP/IP, routing, VPN) and common attack vectors.
  • Familiarity with common industry pentesting tools and methodology.
  • Familiarity with regulatory frameworks and guidance, including NIST, CIS Controls, and ISO 27002.
  • Strong analytical and problem-solving skills, with the ability to cut through noise to find the root cause and exercise sound judgment under pressure.
  • Precise and detail-oriented when configuring tools that affect client production environments.
  • Ability to function well in a high-paced, interrupt-driven environment and balance proactive work against active escalations.
  • Strong written and verbal communication skills, with the ability to break down complex technical information for non-technical audiences.
  • Proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Microsoft Teams.
  • Nice to have: familiarity with virtualization technologies and the Microsoft Azure Portal, experience in a managed services or consulting environment, and familiarity with SIEM platforms and vulnerability scanners.
  • Recommended certifications: CompTIA Security+, Network+, or CySA+, and Microsoft SC-200 or SC-300.

This role is based in Brentwood, TN and will operate on a hybrid basis, with a base compensation range of $70,000-$75,000.

We are seeking a candidate who goes beyond alert triage. The ideal candidate will be comfortable owning incidents end-to-end, making sound decisions with incomplete information, and taking full responsibility for the quality and accuracy of the security tooling our clients depend on. This includes the ability to receive an escalation, quickly distinguish a confirmed compromise from noise, contain the threat, communicate clearly with the client, document the response thoroughly, and hand it off successfully to Advisory Services. If you are an analytical, detail-oriented security professional who enjoys bringing order out of disorder in a managed services environment, we would welcome the opportunity to speak with you.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Lyra Technology Group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Lyra Technology Group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Lyra Technology Group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.