Security Engineer
$125k - $155kReal Time Technologies, LLC
Security Operations & Production Security Engineer
Role Summary
We are looking for a mid-level Security Operations & Production Security Engineer to support Realtime’s growing security, architecture, and production operation's needs. This role will bridge security operations, detection engineering, incident response, cloud/identity security, and production readiness.
The ideal candidate is hands-on, adaptable, and comfortable wearing multiple hats in a small team. This person will help operate and improve our security monitoring stack, support incident response, tune detections, maintain runbooks, validate security controls, coordinate with managed SOC/MDR partners, and help ensure systems are secure, observable, supportable, and ready for Day 2 operations.
This role is best suited for someone who has strong SOC experience but wants to grow into security engineering, production support, automation, and architecture-adjacent responsibilities.
Why This Role Is Needed
Realtime’s security team is small and needs someone who can sit between the Security Architect and the Junior Analyst. The Security Architect should stay focused on architecture, governance, risk, security strategy, control design, and executive-level decision support. The Junior Analyst can help with monitoring, ticketing, and basic triage.
This role fills the operational gap by owning the hands-on security engineering and production security work: detection tuning, incident coordination, tool administration, Jira/Slack workflow hygiene, runbooks, dashboards, Identity management, evidence collection, and day-to-day security operations.
Key Responsibilities
Security Operations & Monitoring
- Monitor and triage alerts across Microsoft Defender, Sentinel, Huntress/MDR, Wiz, Datadog, Jira, and Slack channels.
- Validate alert severity, business impact, affected assets, containment status, and escalation requirements.
- Coordinate security events from initial triage through containment, documentation, closure, and post-incident follow-up.
- Support daily dashboard review, security ticket queues, alert quality checks, and operational reporting.
Detection Engineering & Tuning
- Develop, tune, and maintain detection logic in Huntress, Defender, KQL, and related tools.
- Reduce false positives and alert noise by reviewing recurring detections, suppression logic, enrichment opportunities, and escalation criteria.
- Help build and improve alert runbooks, investigation workflows, and playbooks for phishing, malware, suspicious sign-ins, cloud exposure, endpoint events, and account compromise.
- Support basic SOAR/automation efforts using Logic Apps, playbooks, webhooks, or other workflow tools.
Incident Response & Production Security
- Assist with incident response for endpoint, identity, cloud, email, and suspicious activity events.
- Coordinate containment actions such as endpoint isolation, identity reset, access revocation, escalation to Tier 2/Tier 3 SOC, and follow-up remediation.
- Maintain incident timelines, evidence, RCA notes, lessons learned, and closure documentation.
- Help ensure P1/P2 incidents have clear communication, structured Slack threads, linked Jira tickets, and documented executive summaries when needed.
Cloud, Identity & Endpoint Security
- Support security operations across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Azure, endpoint protection, and cloud risk tools.
- Help review suspicious sign-ins, MFA/SSO issues, risky users, privileged account activity, and access control gaps.
- Assist with cloud exposure triage from Wiz or similar tools, including severity validation, ticket routing, and remediation tracking.
- Support least-privilege reviews, conditional access validation, endpoint security posture, and security control checks.
Production Readiness & Change Support
- Support the Day 0 / Day 1 / Day 2 operating model by helping confirm that new systems and changes are ready for production from a security operations perspective.
- Review or help prepare monitoring requirements, alert runbooks, support escalation paths, rollback considerations, security validation evidence, and operational handoff materials.
- Work with architecture, engineering, and operations teams to ensure production changes are documented, traceable, and supportable.
- Help maintain CMDB/Jira asset relationships, monitoring links, runbook references, and security control mappings where needed. Realtime’s configuration management materials specifically call out CMDB accuracy, monitoring coverage, alert routing, runbook linkage, support RACI, SLA/SLO mapping, and operational acceptance as part of Day 2 readiness.
- Documentation, Metrics & Continuous Improvement
- Create and maintain security runbooks, knowledge base articles, investigation guides, escalation procedures, and incident templates.
- Track and report operational metrics such as alert volume, false positives, SLA breaches, time to acknowledge, time to isolate, time to contain, and closure quality.
- Identify recurring issues and recommend improvements to detections, workflows, tooling, dashboards, and team processes.
- Help mentor the Junior Analyst by reviewing tickets, improving triage quality, and sharing investigation techniques.
Required Qualifications
- 3–5 years of experience in SOC operations, security operations, production support, security engineering, or a similar hands-on cybersecurity role.
- Experience with Microsoft security tools such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft 365 security, or Azure security services.
- Ability to investigate alerts using SIEM/EDR data, KQL, logs, endpoint telemetry, identity logs, and cloud signals.
- Experience with incident triage, phishing investigations, malware alerts, suspicious sign-ins, endpoint events, and escalation workflows.
- Basic understanding of cloud security, identity security, MFA, SSO, conditional access, endpoint protection, and vulnerability/cloud exposure management.
- Ability to write clear documentation, incident notes, runbooks, ticket updates, and executive-ready summaries.
- Comfortable working in a small team where priorities change, and the person may need to support operations, engineering, documentation, and coordination.
- Strong communication skills and ability to work across Slack, Jira, Teams, security tools, managed SOC providers, engineers, and business stakeholders.
Preferred Qualifications:
- Experience with Identity management, Defender, KQL, Logic Apps, SOAR/playbook automation, or detection tuning.
- Experience with tools such as Huntress, Wiz, Datadog, Jira Service Management, Slack, OpenIAM
- Security+, Microsoft SC-200, CySA+, GCIH, Microsoft AZ-500, CCSP, CISSP, or similar certifications.
- Exposure to ITIL, change management, ARB/CAB processes, CMDB, production readiness, or operational handoff.
- Basic scripting or automation experience with PowerShell, Python, Logic Apps, APIs, or workflow automation.
- Experience working in an MSSP, MDR, SOC, or 24/7 operations environment.
Salary Range: $125,000 -155,000 annually , plus a target 5% annual performance bonus which will be based on the employee's and company's performance. Final compensation will be based on the candidate's experience and qualifications.
Our pay structure considers various geographical markets within the United States. The base salary for this role reflects the typical expected earnings. However, the final compensation package is determined by several factors, such as your location, job-specific expertise, skills, experience, and other relevant job-related considerations.
What We Offer:
A unique opportunity to shape the journey of realtime
Working within a rapidly growing, game-changing business
Remote, flexible working options
Competitive compensation
Generous STI and LTI provisions
Health, Dental and Vision Insurance
Paid Annual Leave
Paid Sick Leave
401K, and more
Realtime is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status.
Application Window : Applications are accepted on an ongoing, continuous basis until the position is filled.- ...High level of knowledge in cloud security. High level of expertise in operating security tools: Firewall & NAC: Palo Alto (Perimeter & Datacenter), Counteract, Endpoint Management: SCCM, Microsoft Intune, Crowdstrike, Qualys, IAM & MFA: Azure Conditional...Suggested
$80k
...Information Security Engineer Description SUKU is seeking an Information Security Engineer specializing in web application security and hands-on security architecture for our agile blockchain startup. You'll work closely with our CTO...SuggestedImmediate startRemote workTrial periodFlexible hours- ...PHYSICAL SECURITY NETWORK ENGINEER - SOUTHCOM J2 JOB DESCRIPTION Position Title: Physical Security Network Engineer Employment Status: Full-Time, Salaried, Exempt Location: Doral, Florida Security Requirements: TopSecret/SCI Security Clearance POSITION...SuggestedFull timeContract workTemporary workFor contractorsWork at officeLocal areaWorldwideRelocationWeekend work
- ...Overview The Identity Security Engineer is a pivotal member of the Identity and Access Management team, responsible for ensuring efficient and secure user access across the organization. This role focuses on improving the user onboarding experience, streamlining employee...Suggested
$180k - $210k
...and scale to millions of users. In January 2026, Crossmint secured MiCA authorization from Spain's CNMV, becoming one of a select... ...About the role We are seeking a Senior Security Engineer to own the operational execution of security at Crossmint as we...SuggestedFull timeTemporary workPart timeWork at officeRemote workWorldwideFlexible hours- ...Title: Sr. IT Security Engineer Location: Miami, US- 5 days on site in Miami office Palo Alto is a must Someone that came from Windows Admin background and moved into Security Plus- AD, Azure Reporting: Sr. Manager, IT Security Seasoned...Work experience placementWork at office
- ...POA&M tracking activities, supporting remediation efforts and preparation of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating issues in accordance with defined processes. - Maintain and update incident...Minimum wageContract workTemporary workWork experience placementRemote work
$15.36k - $23.04k
...Lead Security Engineer (AI) – Product Security USA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC Nu is one of the largest digital financial platforms in the world, with more than 127 million customers across Brazil, Mexico, and Colombia. Guided by our mission...Work at officeWork from homeRelocation packageFlexible hours$106k - $170k
...Position Overview The Blackstone Security Operations – Engineering team is growing to support new cross‑functional security needs. The Associate Security Engineer is responsible for providing Security Information and Event Management (SIEM), automation, and security platform...Local area- ...federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on... ...that matter at a national scale. The Junior Security Engineer supports 24x7 enterprise cybersecurity operations by monitoring...Minimum wageFull timeContract workTemporary workWork experience placementRemote work
$92.5k - $171.5k
...The successful candidate will support a highly motivated engineering team in defining, designing, implementing, documenting, testing and sustaining security solutions on National Security Systems, or other systems engineered for our government customers, using current...Local areaFlexible hours- ...Taurean is a mission-driven defensive cyber operations firm delivering security engineering, risk management, and compliance execution for federal and regulated environments. Our teams protect operational systems, sensitive data, and high-assurance environments through...Full timeWeekend work
- ...Security Operations Engineer - Miami/Hybrid About the Role Boats Group is looking for a Security Operations Engineer to join our crew. In this role, you will design, implement, and maintain security measures across our production and corporate IT environments...Work at officeRemote workMonday to Friday
- ...environments - Strong attention to detail and ability to work in structured, compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring - Experience or exposure to vulnerability management,...Minimum wageContract workTemporary workWork experience placementRemote work
- ...Principal Security Engineer - IAM This role will be onsite in our Irving, TX or Miami, FL offices. Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates...Live inWork at officeLocal area
$106k - $170k
...The Blackstone Group L.P. in Miami is looking for an Associate Security Engineer to support cross-functional security needs. This role involves providing SIEM and security platform engineering support while participating in security investigations. The ideal candidate...- ...Cloud Security Engineer Implement and maintain cloud security frameworks, ensuring compliance with NIST 800-53 Rev. 5, FedRAMP, and DoD IL-4/IL-5 security mandates. Configure and manage Identity and Access Management (IAM) solutions, role-based access controls (RBAC...Temporary workFlexible hours
- ...access management. Minimum 5 years of experience in cloud security. Experience configuring access controls in Azure. Experience... ...Certified Security - Specialty, or Microsoft Azure Security Engineer Associate. Preferred Qualifications: Experience...
- ...Position: Cloud Security Engineer LCAT: Mid Location: SOUTHCOM HQ, Doral, FL / Off-site Office: U.S. SOUTHERN Command J2 Required clearance: Secret Required education: Bachelor's degree in Cybersecurity, Information Assurance, or a related field, or five...Temporary workWork at officeFlexible hours
- ...Job Title Cloud Security Engineer Location Doral, FL 33122 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education Bachelor's Degree Travel Security Clearance Required Secret Job Description Prescient...Full timeContract work
$165k - $175k
...Overview The IT Security Team is looking for a seasoned professional to support a passionate, innovative, and results driven team. The Senior Security Operations Center (SOC) Cloud Engineer is responsible for monitoring, detecting, and responding to threats in...Hourly payWork experience placementLocal areaRemote workNight shift- ...Senior Security Development EngineerLocation: Miami, FL (Dadeland Area)Type: 1 Year ContractCompensation: $75-100 per hour SherlockTalent is looking for a Senior Security Development Engineer (Security Engineer + Software Engineer) that will be a part of the Cybersecurity...Hourly payWork experience placement
$200k - $275k
...A leading financial technology company is seeking a security expert to partner with product teams, conduct threat modeling, and review product source code. This remote role requires expertise in web application architecture, cloud services, and experience with security...Remote work$225k - $275k
...giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.Affirm values information security as a critical part of the company's continued success. Our mission is to make information security programmatic and cultural in...Work at officeRemote workFlexible hours- ...long-term career development while valuing your unique skills and experiences. Your role and responsibilities The Azure Security Engineer will support a large team of infrastructure, security and application team during migration of on-prem and cloud applications...Worldwide
- ...• Employee Assistance Program • Flexible Spending Accounts - POSITION SUMMARY: The development, security, and operations (DevSecOps) Engineer ensures that security is a core part of the software development life cycle (SDLC) by integrating security practices...Work at officeLocal areaImmediate startFlexible hours
- ...Job Description: Job Summary A Development, Security, and Operations (DevSecOps) Engineer is needed to integrate security practices into the software development lifecycle (SDLC). The role focuses on embedding security into development processes, automating security...
- ...CARNIVAL CRUISE LINES is hiring a Sr. Application Security Engineer to implement and maintain software security capabilities for their global brands. This remote position will use your expertise in SAST, DAST, and cloud infrastructure to enhance security practices. The...Remote work
- ...-site Type: Full Time Start: Immediate Salary: Based on competencies About BunkerSec.com BunkerSec is a leading provider of Cyber Security Solutions , dedicated to protecting enterprises from digital threats. We are looking for a skilled Penetration Tester / Ethical Hacker...Full timeImmediate start
- ...We are seeking a highly skilled and proactive Senior Security Operations Engineer to join a growing cybersecurity team supporting a global banking transformation initiative. This role is pivotal in establishing and maintaining robust security operations across expanding...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- security infrastructure engineer Miami, FL
- senior cloud security engineer Miami, FL
- senior application security engineer Miami, FL
- physical security engineer Miami, FL
- sr information security engineer Miami, FL
- senior security operations engineer Miami, FL
- IT security engineer Miami, FL
- information technology security engineer Miami, FL
- security software engineer Miami, FL
- aws cloud security engineer Miami, FL


