Senior Cybersecurity Engineer / SentinelOne Lead

LetterNine
US - Louisiana - Independence
View Company Profile / << Go Back

  • Job Type: Full time
  • 2 days ago

Job Description

Requirements
- -----------

### Must have:

### - We need at least 5 years of hands-on cybersecurity experience. - We require deep practical expertise with SentinelOne Singularity, including deployment, policy administration, detection tuning, endpoint isolation, remediation, rollback, exclusions, and incident analysis. - We need experience in an MSP, MSSP, SOC, incident response, or other client-facing cybersecurity environment. - We require a solid command of endpoint defense, EDR, XDR, malware analysis, threat hunting, identity-based attacks, phishing, credential compromise, lateral movement, and persistence techniques. - We need experience investigating Windows endpoint activity, PowerShell abuse, suspicious scripts, unauthorized remote access tools, and malicious process behavior. - We require strong knowledge of Microsoft 365 security, including Entra ID, MFA, conditional access, audit logs, email protection, and account compromise response. - We need the ability to communicate clearly with both technical and non-technical audiences. - We require strong documentation skills and the ability to create clear, repeatable process materials. - We need someone who can work independently and help establish structure in a growing environment. - We prefer active SentinelOne certifications, including Palladium or an equivalent advanced credential. - We prefer technical certifications in Singularity Endpoint, XDR, Identity, Cloud, AI SIEM, or Incident Response. - We prefer SentinelOne partner, administrator, or engineer-level training through SentinelOne University. - We may also consider candidates without Palladium if they bring extensive real-world SentinelOne experience and are willing to earn the required certifications within an agreed timeline. - We value experience with MDR escalations and managed detection and response workflows. - We value familiarity with SentinelOne Singularity Identity, AI SIEM, Security Data Lake, Purple AI, and XDR operations. - We prefer exposure to platforms such as Microsoft Defender, Microsoft Purview, Microsoft Sentinel, Huntress, CrowdStrike, Sophos, Fortinet, Check Point, Proofpoint, Mimecast, or similar tools. - We prefer experience building cybersecurity services within an MSP or MSSP. - We value knowledge of compliance frameworks such as CIS Controls, NIST CSF, HIPAA, FTC Safeguards, SOC 2, or cyber insurance requirements. - We prefer experience producing client-facing reports and executive summaries. - We value experience training and mentoring internal technical teams. - We prefer relevant certifications such as CISSP, GCIH, GCIA, GCFA, CySA+, Security+, CEH, or similar. - We want a builder mindset, strong technical curiosity, calm decision-making under pressure, and a strong sense of ownership. - We need someone comfortable working directly with clients and translating technical risk into business impact. - We value a practical, process-oriented approach and a willingness to teach others.

Responsibilities:
- ----------------

- We will have this person serve as our primary technical lead for SentinelOne across our client base. - We will rely on them to design, deploy, configure, and manage SentinelOne Singularity environments. - We will expect them to create and maintain standardized policies, exclusions, groups, alerting rules, and response workflows. - We will have them manage applicable endpoint protection, EDR, XDR, MDR, identity protection, cloud security, AI SIEM, and related SentinelOne services. - We will ask them to review and fine-tune detections to reduce false positives while preserving strong protection. - We will have them support new client onboarding into SentinelOne and ensure proper deployment, visibility, and coverage. - We will have them work with SentinelOne partner resources to stay informed on new features, roadmap updates, licensing changes, and best practices. - We will have them lead investigations and responses for security alerts, suspicious activity, malware incidents, account compromise indicators, and endpoint events. - We will expect them to perform threat hunting using SentinelOne and other security tools. - We will have them analyze suspicious files, scripts, PowerShell activity, lateral movement signals, persistence methods, and endpoint telemetry. - We will rely on them to coordinate remediation actions such as isolation, rollback, quarantine, termination, account resets, persistence removal, and post-incident hardening. - We will have them produce clear incident reports for clients and internal stakeholders. - We will ask them to help create formal incident response playbooks and escalation procedures. - We will have them help develop our cybersecurity service offerings around SentinelOne and the broader security stack. - We will have them define standards for security onboarding, baseline hardening, monthly reviews, and ongoing cyber hygiene. - We will rely on them to build repeatable processes for EDR deployment, MDR escalation, SIEM review, vulnerability follow-up, and policy enforcement. - We will have them help shape our cybersecurity packages and service delivery model. - We will ask them to mentor help desk and systems engineers on cybersecurity fundamentals, alert triage, and SentinelOne best practices. - We will have them support leadership in building a long-term roadmap for our cybersecurity team. - We will have them act as a trusted cybersecurity advisor for clients. - We will expect them to join client meetings and explain findings, recommendations, incident outcomes, and risk-reduction actions. - We will have them prepare executive-friendly security reports, recommendations, and remediation plans. - We will rely on them to assist with security assessments, cyber insurance questionnaires, compliance requests, and vendor security reviews. - We will expect them to communicate technical issues in a clear, professional, and business-focused manner. - We will have them create and maintain runbooks, response procedures, deployment guides, and troubleshooting documentation. - We will have them document client-specific configurations, exclusions, policies, and escalation contacts. - We will ask them to build repeatable workflows for alert handling, incident response, reporting, and client communication. - We will have them work within our PSA, RMM, documentation, and ticketing systems.
- -----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Company:
- -------

We are a growing managed service provider focused on helping businesses simplify IT, strengthen security, and operate with confidence. As a direct SentinelOne partner, we are expanding our cybersecurity practice and looking for an experienced professional to help lead that growth. This is an in-person role offering a salary starting at $90,000 per year, along with 401(k) matching, dental, health, life, vision, paid time off, and a retirement plan. We are building our cybersecurity function from the ground up, so this position is ideal for someone who wants to shape service offerings, processes, team development, and long-term strategy while serving as our internal SentinelOne authority.
- ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------




Fast Track Upload