hirly

Lyratechgroup

SOC Engineer

Brentwood, TN

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Lyratechgroup first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
On-site / unstated
First seen by hirly
30 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Lyra Technology Group is a p rivate e quity-backed holding company that invests in and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group , we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term.

SOC Engineer – ImageQuest

ImageQuest is looking for an experienced SOC Engineer to serve as the technical backbone of our Security Operations Center. This is a senior technical role focused primarily on escalations and incident response, security tooling ownership, proactive threat hunting, and scripting and automation within a managed services environment. The SOC Engineer is the SOC's primary escalation point, owning confirmed compromises from containment through handoff to the Advisory Services team. The ideal candidate is comfortable building deep, custom policy on the tools our analysts and clients depend on, hunting for threats that automated tooling misses, and reducing manual SOC workload over time.

About ImageQuest….

ImageQuest is a Nashville, Tennessee-based managed IT and managed security services provider serving regulated businesses across the United States, including banking, healthcare, insurance, legal, non-profit, and wealth management organizations. Founded in 2007, the company delivers managed IT, cybersecurity, incident response, virtual CISO leadership, compliance consulting, and cloud support, all with a proactive, compliance-focused approach. ImageQuest is part of Lyra Technology Group.

Your work as a SOC Engineer will include several components:

Escalation & Incident Response

Own all escalations and confirmed compromises referred from the SOC Analysts.

Investigate and triage escalated alerts to determine severity, scope, and whether a compromise is confirmed.

Contain and resolve security incidents before they affect client business operations.

Manage internal communication during suspected and confirmed incidents, and work directly with clients to explain the containment and investigation process under time constraints.

Serve as backup to the SOC Analysts in responding to inbound alerts as needed.

Conduct post-incident debriefs with the Cybersecurity Advisory team.

Threat Hunting & Security Monitoring

Conduct proactive threat hunting across the client base rather than relying solely on inbound alerts.

Continually monitor security intelligence and threat chatter that may affect ImageQuest clients.

Maintain a current understanding of the threat landscape relevant to ImageQuest's client industries.

Spam Filter & Phishing Escalation

Serve as the escalation point for Defender for Office, IronScales, and Mimecast configuration and tuning.

Own escalated phishing investigations referred from the SOC Analysts, determining scope and whether further containment is needed.

Adjust spam filter policy, including sender and domain blocks, allow lists, and quarantine rules, in response to confirmed phishing campaigns.

Coordinate directly with clients on high-impact phishing incidents requiring same-day action.

Endpoint & Tooling Ownership

Configure and maintain Microsoft Defender for Endpoint, SentinelOne, ThreatLocker, Huntress, and Arctic Wolf across the client base.

Build deeper, custom ThreatLocker policy beyond the standard baseline maintained by the SOC Analysts, precise enough to block real threats without breaking legitimate client applications.

Investigate tooling gaps and false positives, tuning detection rules to reduce noise reaching the Analyst queue.

Automation & Process Improvement

Drive scripting and automation improvements across the SOC's alert and ticketing tools to reduce manual, repetitive work.

Establish and maintain accurate documentation of SOC processes and incident responses.

Pull monthly reports and categorize SOC activity appropriately.

Client Onboarding & Advisory Support

Support onboarding of new clients, including deployment of security tooling and validation of SOC coverage.

Provide technical expertise to Advisory Services during incidents, audits, and cyber insurance claims that require deep technical detail.

Participate in cyber incident response tabletop exercises as needed.

Documentation & Communication

Ensure all client-facing documentation is consistent with ImageQuest format and professional standards.

Communicate technical incident details clearly to both technical and non-technical clients and internal stakeholders.

Collaborate with the Managed IT team, including the Network Operations Center, Field Technicians, and Service Desk.

Participate in occasional on-site client visits and off-site ImageQuest client events.

Our ideal SOC Engineer has the following qualifications:

3+ years of proven IT security experience, with hands-on incident response or threat hunting experience.

Bachelor's degree in computer science, information technology, or a related field desired.

Deep working knowledge of SentinelOne, ThreatLocker, Huntress, and Arctic Wolf, or comparable EDR, application control, SIEM, and MDR platforms.

Demonstrated ability to investigate, triage, and contain confirmed security incidents.

Working knowledge of a scripting language (e.g., PowerShell) for automation and tooling improvements.

Thorough understanding of networks (IP subnetting, TCP/IP, routing, VPN) and common attack vectors.

Familiarity with common industry pentesting tools and methodology.

Familiarity with regulatory frameworks and guidance, including NIST, CIS Controls, and ISO 27002.

Strong analytical and problem-solving skills, with the ability to cut through noise to find the root cause and exercise sound judgment under pressure.

Precise and detail-oriented when configuring tools that affect client production environments.

Ability to function well in a high-paced, interrupt-driven environment and balance proactive work against active escalations.

Strong written and verbal communication skills, with the ability to break down complex technical information for non-technical audiences.

Proficiency with Microsoft Office (Excel, Word, PowerPoint, Outlook) and Microsoft Teams.

Nice to have: familiarity with virtualization technologies and the Microsoft Azure Portal, experience in a managed services or consulting environment, and familiarity with SIEM platforms and vulnerability scanners.

Recommended certifications: CompTIA Security+, Network+, or CySA+, and Microsoft SC-200 or SC-300.

This role is based in Brentwood, TN and will operate on a hybrid basis, with a base compensation range of $70,000-$75,000.

We are seeking a candidate who goes beyond alert triage. The ideal candidate will be comfortable owning incidents end-to-end, making sound decisions with incomplete information, and taking full responsibility for the quality and accuracy of the security tooling our clients depend on. This includes the ability to receive an escalation, quickly distinguish a confirmed compromise from noise, contain the threat, communicate clearly with the client, document the response thoroughly, and hand it off successfully to Advisory Services. If you are an analytical, detail-oriented security professional who enjoys bringing order out of disorder in a managed services environment, we would welcome the opportunity to speak with you.

Original posting on Lyratechgroup's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job