| Location | Jacksonville, Florida (Remote) |
Security Operations Technician Needed! Job Overview: The Security Operations Technician is a Tier 2 technical cybersecurity role responsible for the health, coverage, and configuration integrity of Scarlett-managed security platforms across internal and client environments. The primary duty of this role is security platform health management, coverage reconciliation, and execution of approved security changes, including firewall updates and security configuration changes. Queue coverage and incident support are secondary, rotational responsibilities performed under established runbooks and the direction of Security Operations leadership. When engaged in an active security incident, the Cyber Incident Response Specialist may provide direction for incident response activities. This role participates in the Security Operations on-call rotation and rotates into Security Analyst and incident support coverage when demand requires. This role is intended to strengthen operational consistency across the Scarlett security stack while providing a defined development path toward Security Analyst and Incident Response roles. Hours will fluctuate based on incident volume and maintenance schedules, and overtime is paid in accordance with company policy and applicable law. Responsibilities & Duties: Security Agent Health & Coverage Management •Monitor and remediate security agent health across EDR, RMM, and application control platforms, including offline, degraded, outdated, and duplicate agents. •Perform coverage reconciliation between RMM asset inventory, EDR consoles, and documentation systems to identify unprotected or unmanaged endpoints. •Deploy, reinstall, and troubleshoot security agents during client onboarding, platform migrations, and remediation efforts. •Maintain agent version currency and execute staged rollout schedules across the client portfolio. •Track and report portfolio-wide coverage metrics and close gaps against each client’s contracted security stack. Security Reconciliation & Auditing •Reconcile security tool tenants and licensing against active client lists, removing stale tenants, licenses, and assets for offboarded clients and decommissioned systems. •Audit alignment between contracted security services and deployed controls for each client. •Perform recurring user account reconciliation across M365, security consoles, VPN, and firewall administration accounts, flagging orphaned and terminated-user accounts. •Validate MFA enrollment coverage and conditional access policy application across managed tenants. •Support evidence collection for compliance engagements related to platform configuration, coverage, and change records. Firewall & Network Security Changes •Execute approved firewall changes, including rule additions, NAT policies, VPN tunnel builds, and content filtering updates, in accordance with the change management process. •Perform firmware updates and scheduled maintenance on firewalls and network security appliances. •Conduct periodic firewall rule reviews, flagging stale, overly permissive, or undocumented rules for review. •Maintain site-to-site and client VPN configurations, including certificate and pre-shared key rotation. Security Change Execution •Implement approved security configuration changes across M365 and Entra tenants, including conditional access, DLP policy deployment, and mail flow and anti-phishing rules. •Perform application control policy maintenance, including application approvals, ringfencing adjustments, and policy tuning within defined guardrails, escalating novel approval requests. •Apply security baseline configurations to new endpoints, servers, and tenants during onboarding. •Support syslog and log source onboarding and maintenance, ensuring log flow continuity from firewalls, servers, and security platforms into the logging pipeline. Vulnerability & Patch Support •Track vulnerability scan output and coordinate or execute remediation, including patching, configuration changes, and mitigations, within defined SLAs. •Validate remediation completion and maintain exception documentation. •Support penetration testing engagement logistics, including runner deployment, connectivity validation, and pre-engagement checklist completion. On-Call & Coverage Rotation •Participate in the Security Operations on-call rotation, providing after-hours first response to alerts, agent outages, and client-reported security events. Participation in the on-call rotation is an essential function of the role. •Provide surge support during active incidents under the direction of the Cyber Incident Response Specialist or Security Operations leadership, including evidence collection, containment task execution such as endpoint isolations, account disables, and block deployments, and status documentation. •Rotate into Security Analyst queue coverage during PTO, incident surges, and staffing gaps, performing alert validation and initial triage per established runbooks. •Support after-hours maintenance windows for firewall firmware, agent rollouts, and platform changes. Documentation & Ticket Hygiene •Maintain accurate platform documentation, credentials, network diagrams, and configuration records in the documentation system. •Work the security change queue, meeting SLA targets for standard changes. •Escalate anomalies discovered during routine work, including unexpected accounts, disabled agents, and unauthorized changes, to Security Operations leadership or the Cyber Incident Response Specialist. Other •To support onboarding, training, and team integration, employees in this position are expected to work onsite during their first 90 days of employment unless the position is specifically designated as fully remote. Following successful completion of the introductory period, employees may participate in the Company's flexible hybrid work arrangements in accordance with business needs, role requirements, manager discretion and Company policy. •After-hours and weekend work is a requirement of this position as needed. •Other duties as assigned. Certification Requirement CompTIA Security+ or an equivalent entry-level cybersecurity certification is not required at the time of role acceptance. The individual accepting the Security Operations Technician role must obtain CompTIA Security+ or an approved equivalent certification within 180 days of role acceptance, with training and exam costs funded by Scarlett. Maintaining progress toward this certification and completing it within the required period is an expectation of accepting and remaining in this role. Qualifications: •High school diploma or equivalent required. •2+ years of hands-on experience in IT support, systems administration, or security operations at a Tier 2 or equivalent level. •Working knowledge of Windows administration and networking fundamentals, including TCP/IP, DNS, VPN, and firewall concepts. •Experience with RMM, EDR, application control, or endpoint management platforms preferred. •Familiarity with M365 and Entra administration preferred. •Ability to participate in a rotating on-call schedule, including after-hours and weekend response, as an essential function of the role. •Strong documentation habits and change management discipline. •CompTIA Security+ or approved equivalent certification within 180 days of role acceptance; training provided by Scarlett. Environmental and Physical Requirements: •The work environment for this position is a standard office setting. •The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment. •The employee must occasionally lift and/or move up to 25 pounds. •Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Success Metrics •Agent coverage and health maintained at or above defined targets across the client portfolio. •Reconciliation audits completed on schedule, with identified gaps documented and closed. •Firewall and security changes executed within SLA and in accordance with change management, with zero unauthorized changes. •Vulnerability and patch remediation SLAs met, with exceptions documented. •On-call response time targets met, and queue coverage performed in accordance with established runbooks. •Documentation maintained accurate and current across assigned platforms and clients. |