Trean Corporation logo
Hiring from
United States
Work type
Hybrid
Posted
Sep 25, 2026
Is this job info correct?

Description

POSITION SUMMARY:

**Please note: Trean will not sponsor applicants for work visas.**

The Security Engineer is responsible for the day-to-day execution of the organization's cybersecurity operations program. This role serves as a hands-on member of the cybersecurity team, reviewing security alerts, investigating incidents, analyzing security events, managing security-related requests, conducting risk assessments, and identifying opportunities to strengthen security controls and processes.


The ideal candidate has experience in security operations and incident response and is seeking an opportunity to expand their skills and responsibilities across risk management, vulnerability management, security process improvement, and cybersecurity operations.


The Security Engineer must possess strong technical and analytical skills, maintain awareness of the evolving cybersecurity threat landscape, and understand modern attack techniques including ransomware, phishing, business email compromise, identity-based attacks, cloud security threats, and emerging risks associated with artificial intelligence. Success in this role requires the ability to evaluate risks, recommend practical security improvements, and contribute to the continuous evolution of the organization's cybersecurity capabilities.


RESPONSIBILITIES:

  • Monitor and investigate security alerts and suspicious activity across the enterprise environment.
  • Analyze suspected cybersecurity events and perform triage, containment, eradication, and recovery activities.
  • Manage cybersecurity incidents through the full incident response lifecycle, including investigation, documentation, escalation, and post-incident review.
  • Serve as the primary reviewer and analyst for security alerts, security-related requests, security incidents, and risk assessments, ensuring timely investigation, documentation, remediation recommendations, and follow-through.
  • Review, analyze, and resolve security-related tickets, requests, and reported security concerns.
  • Perform application, vendor, infrastructure, and technology risk assessments and provide recommendations to mitigate identified risks.
  • Review security questionnaires, technology implementations, and proposed business or technology changes to identify security risks and control gaps.
  • Assess security vulnerabilities, system misconfigurations, and control weaknesses and work with stakeholders to drive remediation efforts.
  • Research emerging cyber threats, attacker tactics, techniques, and procedures (TTPs), and recommend improvements to security controls and defenses.
  • Develop and maintain security procedures, response playbooks, technical documentation, and operational standards.
  • Identify opportunities to improve cybersecurity processes, incident response workflows, ticket handling procedures, and operational efficiency.
  • Recommend and implement enhancements to security controls, monitoring capabilities, and security processes based on lessons learned, risk assessments, and emerging threats.
  • Participate in projects and technology initiatives to ensure security requirements and risks are appropriately considered.
  • Support the evaluation and secure adoption of emerging technologies, including artificial intelligence solutions, within the organization.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
  • 2-4 years of experience in cybersecurity, security operations, incident response, or a related information security role.
  • Demonstrated experience performing day-to-day security operations activities, including alert triage, incident investigation, security ticket review, remediation tracking, and resolution of security-related requests.
  • Experience supporting or participating in cybersecurity incident response activities, including investigation, containment, eradication, recovery, and documentation.
  • Experience conducting or participating in technology, application, vendor, or cybersecurity risk assessments.
  • Experience identifying security vulnerabilities, control weaknesses, and recommendations for remediation.
  • Knowledge of current cybersecurity threats, attack techniques, defensive security principles, and industry best practices.
  • Understanding of information security concepts including identity and access management, endpoint security, vulnerability management, security monitoring, and incident response.
  • Strong analytical and problem-solving skills with the ability to assess risk, prioritize work, and recommend practical solutions.
  • Ability to assess, prioritize, and manage multiple security events, incidents, assessments, and requests in a fast-paced environment.
  • Ability to learn new technologies, evaluate security risks, and recommend process and security control improvements.
  • Strong written and verbal communication skills with the ability to document findings and communicate technical information to both technical and non-technical audiences.
  • Ability to work independently, exercise sound judgment, and collaborate effectively with cross-functional teams.
  • Ability to work in a hybrid work environment with a minimum onsite presence of three days per week at a designated company office location.
  • Demonstrated integrity, trustworthiness, and the ability to maintain strict confidentiality when handling sensitive company, customer, employee, and cybersecurity-related information.


PREFERRED QUALIFICATIONS

  • Experience conducting application, vendor, or technology risk assessments.
  • Experience supporting security engineering initiatives and implementation of security controls.
  • Security certifications such as Security+, CySA+, SSCP, GSEC, GCIH, or equivalent.
  • Experience working in a regulated industry such as insurance, financial services, healthcare, or a similar environment.
  • Experience identifying opportunities to improve security processes, workflows, and operational effectiveness.
  • Exposure to cloud security, identity and access management, artificial intelligence technologies, or security automation.
  • Experience reviewing vendor security questionnaires, technology implementations, or application security assessments.


IDEAL CANDIDATE

  • Currently works in a security operations, SOC, or cybersecurity analyst role.
  • Reviews security alerts, investigates incidents, and manages security-related tickets as part of their daily responsibilities.
  • Has participated in risk assessments, security reviews, vendor reviews, or vulnerability management activities and is ready to take ownership of those activities.
  • Demonstrates strong analytical thinking, attention to detail, and sound judgment.
  • Maintains a high level of integrity and discretion when handling sensitive and confidential information.
  • Is eager to expand their technical skills, contribute to security improvements, and grow into a more senior cybersecurity role over time.

WORKING CONDITIONS

This position is located in a professional office environment. This role routinely uses standard office equipment and requires the physical demands of a normal office position with some light lifting. This is a full-time position with benefits. This position follows Trean's hybrid work model and requires a minimum onsite presence of three days per week at a designated company office location.


DISCLAIMER

This job description is not a contract of employment. It represents the minimum requirements of the job and includes the major responsibilities but not all responsibilities. Trean Corporation will change and update this job description, as necessary.

Any employment with Trean Corporation will be “at will,” meaning that either you or the Company may terminate your employment at any time and for any reason, with or without cause or advance notice.



Similar jobs

Apply for this job