Security Engineer – Security Operations & Incident Response
Grand Rapids, MI - USA
Job Summary
COMPANY DESCRIPTION
At AirLife we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line but the way we work and take care of our customers. With a mindset to evolve innovate and grow we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach impacting even more people around the world. Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care with safety patient comfort and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients customers and our people. Our values of Customer first Differentiate with our People Bias for Action Continuous Improvement and Accountability define who we are and how we work. Join us!
POSITION SUMMARY
The Security Engineer Security Operations & Incident Response is responsible for monitoring triaging and investigating security events across AirLifes global environment; leading incident response containment and recovery efforts; and continuously improving detection rules alert quality and security automation. This role operates and integrates AirLifes SIEM EDR vulnerability management and cloud security tooling partners with AirLifes managed detection and response provider (Arctic Wolf) and cross-functional Infrastructure Cloud IT and Application teams on remediation and helps mature AirLifes security operations and incident response capabilities.
POSITION QUALIFICATIONS
Knowledge Skills & Abilities:
- Strong understanding of security operations concepts including SIEM platforms log analysis and security alert triage.
- Hands-on experience leading incident response activities detection containment eradication recovery and post-incident review in an enterprise environment.
- Experience with detection engineering and alert-rule tuning including collaborating with an MDR/MSSP provider on tuning and escalation (Arctic Wolf experience preferred).
- Practical knowledge of EDR/endpoint protection platforms (Microsoft Defender preferred) vulnerability management tooling and cloud security posture management.
- Experience developing and maintaining incident response playbooks runbooks and security operations procedures.
- Understanding of Zero Trust architecture principles and their application to security operations and detection design.
- Knowledge of security compliance frameworks (NIST CIS Controls ISO 27001 GDPR) with practical application to security operations.
- Familiarity with security automation/orchestration concepts to streamline detection and response workflows.
- Working knowledge of Microsoft Entra ID and Active Directory including how identity signals inform incident investigation.
- Ability to manage multiple concurrent incidents projects and operational tasks in a dynamic environment (Smartsheet experience preferred).
- Strong root cause analysis and technical troubleshooting skills.
- Experience with backup and disaster recovery systems (Rubrik/Azure preferred) as part of recovery operations.
- Experience with KnowBe4 security awareness and phishing simulation administration preferred.
Level of Experience:
- Minimum of 35 years of professional IT experience including 2 years in a security operations incident response or SOC-focused role.
- Experience in a manufacturing healthcare or other regulated enterprise environment preferred.
Level of Education:
- Bachelors Degree in Cybersecurity Information Technology Computer Science or related field or equivalent experience.
- Relevant security operations/incident response certification preferred (CompTIA Security GCIH GCFA or equivalent).
Travel:
Up to 10% as required by the business.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Monitor triage and investigate security events and alerts generated by SIEM EDR and other security tooling across AirLifes environment.
- Lead incident response activities detection containment eradication and recovery and facilitate post-incident reviews to capture lessons learned and drive corrective actions.
- Improve detection rules alert quality and response playbooks to reduce false positives and improve mean time to detect and respond.
- Operate configure and integrate SIEM EDR vulnerability management and cloud security tools to strengthen AirLifes security posture.
- Develop and maintain incident response playbooks runbooks and standard operating procedures for common threat scenarios.
- Partner with Arctic Wolf (AirLifes MDR provider) on alert tuning escalation handling and investigation of identified threats.
- Partner with Infrastructure Cloud IT and Application teams to remediate vulnerabilities coordinate containment actions and implement security hardening measures.
- Support AirLifes vulnerability management program including scan review prioritization and remediation tracking.
- Track operational security metrics (e.g. alert volume dwell time time to remediate) and identify recurring risks or trends for leadership reporting.
- Participate in an on-call or escalation rotation to support after-hours incident response as applicable.
- Support KnowBe4 security awareness and phishing simulation administration in coordination with the Security GRC Engineer.
- Contribute to backup and disaster recovery operations (Rubrik/Azure) as part of incident recovery efforts.
- Maintain documentation of security operations architecture detection logic and incident response procedures.
OTHER RESPONSIBILITIES
- Uphold and embody AirLifes values in all aspects of work.
- Demonstrate accuracy and thoroughness in daily work; look for ways to improve and promote quality & safety.
- Inspire the trust of others; treat people with respect and dignity and embrace the value of diversity.
- Use time efficiently; perform job accurately thoroughly and conserve Company resources to improve profits.
- Contribute to building and maintaining a positive team environment.
- Assure all policies and guidelines are implemented and followed.
QUALITY POLICY
At AirLife Quality is our promise. It is our commitment to customer satisfaction and our dedication to product excellence in an evolving global healthcare market. This promise is kept through a continuously improving and effective Quality Management System and compliance to Regulatory Requirements.
DEIA STATEMENT
At AirLife we are committed to building a diverse workforce and an inclusive workplace that reflects the communities and customers we serve. We believe our philosophy on Diversity Equity Inclusion and Advancement (DEIA) encourages excellence and equips us to serve an evolving global marketplace.
Please note: The responsibilities outlined above are not exhaustive and may evolve over time. The role holder may be required to undertake additional duties as reasonably expected to meet the needs of the company.
Benefits
AirLife offers a comprehensive benefits package including medical dental and vision coverage 401(k) paid time off paid holidays bereavement leave Employee Assistance Program resources and medical leave benefits subject to applicable eligibility requirements. Certain positions may also be eligible for bonus commission or other incentive compensation.
Required Experience:
IC
About Company
Anesthesia and respiratory care products. Humidity Delivered Just Right Explore DuoTherm® Humidification System for personalized, accurate patient care Learn MoreSeven Days, One Simplified SolutionExplore NEW BALLARD™ 7Day Closed Suction System Learn MoreNew Distribution Partnership N ... View more