Demo

Security Engineer

realtime
Miami, FL Full Time
POSTED ON 6/3/2026
AVAILABLE BEFORE 7/2/2026
Security Operations & Production Security Engineer

Role Summary

We are looking for a mid-level Security Operations & Production Security Engineer to support Realtime’s growing security, architecture, and production operation's needs. This role will bridge security operations, detection engineering, incident response, cloud/identity security, and production readiness.

The ideal candidate is hands-on, adaptable, and comfortable wearing multiple hats in a small team. This person will help operate and improve our security monitoring stack, support incident response, tune detections, maintain runbooks, validate security controls, coordinate with managed SOC/MDR partners, and help ensure systems are secure, observable, supportable, and ready for Day 2 operations.

This role is best suited for someone who has strong SOC experience but wants to grow into security engineering, production support, automation, and architecture-adjacent responsibilities.

Why This Role Is Needed

Realtime’s security team is small and needs someone who can sit between the Security Architect and the Junior Analyst. The Security Architect should stay focused on architecture, governance, risk, security strategy, control design, and executive-level decision support. The Junior Analyst can help with monitoring, ticketing, and basic triage.

This role fills the operational gap by owning the hands-on security engineering and production security work: detection tuning, incident coordination, tool administration, Jira/Slack workflow hygiene, runbooks, dashboards, Identity management, evidence collection, and day-to-day security operations.

Key Responsibilities

Security Operations & Monitoring

  • Monitor and triage alerts across Microsoft Defender, Sentinel, Huntress/MDR, Wiz, Datadog, Jira, and Slack channels.
  • Validate alert severity, business impact, affected assets, containment status, and escalation requirements.
  • Coordinate security events from initial triage through containment, documentation, closure, and post-incident follow-up.
  • Support daily dashboard review, security ticket queues, alert quality checks, and operational reporting.

Detection Engineering & Tuning

  • Develop, tune, and maintain detection logic in Huntress, Defender, KQL, and related tools.
  • Reduce false positives and alert noise by reviewing recurring detections, suppression logic, enrichment opportunities, and escalation criteria.
  • Help build and improve alert runbooks, investigation workflows, and playbooks for phishing, malware, suspicious sign-ins, cloud exposure, endpoint events, and account compromise.
  • Support basic SOAR/automation efforts using Logic Apps, playbooks, webhooks, or other workflow tools.

Incident Response & Production Security

  • Assist with incident response for endpoint, identity, cloud, email, and suspicious activity events.
  • Coordinate containment actions such as endpoint isolation, identity reset, access revocation, escalation to Tier 2/Tier 3 SOC, and follow-up remediation.
  • Maintain incident timelines, evidence, RCA notes, lessons learned, and closure documentation.
  • Help ensure P1/P2 incidents have clear communication, structured Slack threads, linked Jira tickets, and documented executive summaries when needed.

Cloud, Identity & Endpoint Security

  • Support security operations across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Azure, endpoint protection, and cloud risk tools.
  • Help review suspicious sign-ins, MFA/SSO issues, risky users, privileged account activity, and access control gaps.
  • Assist with cloud exposure triage from Wiz or similar tools, including severity validation, ticket routing, and remediation tracking.
  • Support least-privilege reviews, conditional access validation, endpoint security posture, and security control checks.

Production Readiness & Change Support

  • Support the Day 0 / Day 1 / Day 2 operating model by helping confirm that new systems and changes are ready for production from a security operations perspective.
  • Review or help prepare monitoring requirements, alert runbooks, support escalation paths, rollback considerations, security validation evidence, and operational handoff materials.
  • Work with architecture, engineering, and operations teams to ensure production changes are documented, traceable, and supportable.
  • Help maintain CMDB/Jira asset relationships, monitoring links, runbook references, and security control mappings where needed. Realtime’s configuration management materials specifically call out CMDB accuracy, monitoring coverage, alert routing, runbook linkage, support RACI, SLA/SLO mapping, and operational acceptance as part of Day 2 readiness.
  • Documentation, Metrics & Continuous Improvement
  • Create and maintain security runbooks, knowledge base articles, investigation guides, escalation procedures, and incident templates.
  • Track and report operational metrics such as alert volume, false positives, SLA breaches, time to acknowledge, time to isolate, time to contain, and closure quality.
  • Identify recurring issues and recommend improvements to detections, workflows, tooling, dashboards, and team processes.
  • Help mentor the Junior Analyst by reviewing tickets, improving triage quality, and sharing investigation techniques.

Required Qualifications

  • 3–5 years of experience in SOC operations, security operations, production support, security engineering, or a similar hands-on cybersecurity role.
  • Experience with Microsoft security tools such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft 365 security, or Azure security services.
  • Ability to investigate alerts using SIEM/EDR data, KQL, logs, endpoint telemetry, identity logs, and cloud signals.
  • Experience with incident triage, phishing investigations, malware alerts, suspicious sign-ins, endpoint events, and escalation workflows.
  • Basic understanding of cloud security, identity security, MFA, SSO, conditional access, endpoint protection, and vulnerability/cloud exposure management.
  • Ability to write clear documentation, incident notes, runbooks, ticket updates, and executive-ready summaries.
  • Comfortable working in a small team where priorities change, and the person may need to support operations, engineering, documentation, and coordination.
  • Strong communication skills and ability to work across Slack, Jira, Teams, security tools, managed SOC providers, engineers, and business stakeholders.

Preferred Qualifications:

  • Experience with Identity management, Defender, KQL, Logic Apps, SOAR/playbook automation, or detection tuning.
  • Experience with tools such as Huntress, Wiz, Datadog, Jira Service Management, Slack, OpenIAM
  • Security , Microsoft SC-200, CySA , GCIH, Microsoft AZ-500, CCSP, CISSP, or similar certifications.
  • Exposure to ITIL, change management, ARB/CAB processes, CMDB, production readiness, or operational handoff.
  • Basic scripting or automation experience with PowerShell, Python, Logic Apps, APIs, or workflow automation.
  • Experience working in an MSSP, MDR, SOC, or 24/7 operations environment

Salary Range:$125,000 -155,000 annually, plus a target 5% annual performance bonus which will be based on the employee's and company's performance. Final compensation will be based on the candidate's experience and qualifications.

Our pay structure considers various geographical markets within the United States. The base salary for this role reflects the typical expected earnings. However, the final compensation package is determined by several factors, such as your location, job-specific expertise, skills, experience, and other relevant job-related considerations.

What We Offer:

  • A unique opportunity to shape the journey of realtime
  • Working within a rapidly growing, game-changing business
  • Remote, flexible working options
  • Competitive compensation
  • Generous STI and LTI provisions
  • Health, Dental and Vision Insurance
  • Paid Annual Leave
  • Paid Sick Leave
  • 401K, and more

Equal Opportunity Statement:

Realtime is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status.

Application Window: Applications are accepted on an ongoing, continuous basis until the position is filled.

Powered by JazzHR

qKvqSE7HUR

Salary : $125,000 - $155,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Engineer?

Sign up to receive alerts about other jobs on the Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$65,440 - $83,454
Income Estimation: 
$102,189 - $143,024
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at realtime

  • realtime Miami, FL
  • RTPOS Client Support Technician I Overview: Client Support Technicians are our front-line call center employees. Their mission is to provide our dealers an... more
  • 4 Days Ago

  • realtime Chicago, IL
  • Market Manager Location: Chicago Field-based Market Manager covering the Chicago area Company Description Realtime offers the most flexible cutting-edge Re... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Security Engineer jobs in the Miami, FL area that may be a better fit.

  • Nation Security Miami, FL
  • Company Description Nation Security employer dynamic is like non-other in many aspects. We provide on-the-job training, position advancements, and learning... more
  • 6 Days Ago

  • Nation Security Homestead, FL
  • Company Description Nation Security is a top security service provider. We have capabilities and logistics to service Crowd Events, Corporate Events, Resid... more
  • 2 Months Ago

AI Assistant is available now!

Feel free to start your new journey!