At Ensitech, we are a custom software development company with more than 19 years of experience delivering high-quality technology solutions.
We are looking for an L2 Security Operations / Response Engineer to support the delivery of an AI-enabled cybersecurity service. The platform handles the initial security operations workflow, including alert intake, enrichment, correlation, triage, case creation, and known workflow execution. As an L2 Security Operations / Response Engineer, you will step in when human judgment, deeper investigation, containment, remediation, or technical escalation is required. You will investigate escalated cases across endpoint, identity, cloud, email, network, and SIEM environments, execute approved response actions, and validate remediation. The role initially operates as part of a shared or fractional delivery model supporting multiple customers, with the potential to evolve into dedicated resources, pods, and 24x7 coverage as service volume grows.
Key Responsibilities
Investigate security cases escalated by the AI-enabled security platform when deeper human analysis is required.
Perform investigations across endpoint, identity, cloud, email, network, and SIEM environments.
Apply technical judgment to determine the appropriate investigation, response, escalation, or remediation path.
Execute approved containment and remediation actions.
Validate that containment and remediation actions were successfully completed.
Escalate complex or specialized cases to L3 Security / Incident Response, Cloud Security, Detection & Automation, or other engineering resources as appropriate.
Collaborate with specialized security engineers to support end-to-end case resolution.
Contribute to the delivery of cybersecurity services across multiple customers in a shared or fractional capacity.
Support the evolution of the service toward dedicated resources, pods, and 24x7 operations as customer volume increases.
Required Skills & Experience
Experience in Security Operations, Incident Response, or a related cybersecurity discipline.
Hands-on experience investigating security events across multiple security domains.
Experience with endpoint, identity, cloud, email, network, and SIEM security environments.
Experience executing and validating security containment and remediation activities.
Ability to investigate escalated security cases and determine when additional technical expertise is required.
Strong understanding of security operations, incident escalation, and response processes.
Ability to work effectively in a service delivery environment supporting multiple customers.
Comfortable working in an environment where automation handles initial alert processing and human expertise is focused on investigation, response, remediation, and escalation.
Ability to work within evolving shared, fractional, dedicated, and eventually 24x7 delivery models.
What We Offer
✅ 100% remote opportunity
✅ Opportunity to work on cutting-edge AI projects
✅ Collaboration with leading Frontier LLM companies
✅ International and innovation-driven environment
✅ Potential contract extension based on performance and project needs
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!