Who we are
Technuf, LLC is a Maryland based SBA certified 8(a) small business company providing leading-edge and proven technologies, industry vertical domain expertise and highly skilled and
motivated professionals to achieve our customers’ mission critical business needs.
Position Summary
Technuf is seeking a hands-on Lead Security Platform & IT Operations Engineer to own the technical foundation of our managed security service and the managed IT estate that surrounds it. Our customers are small and midsize organizations — including insurance and financial-services clients — that need enterprise-quality monitoring, response and IT operations without enterprise-sized teams.
This is a technical leadership position with meaningful hands-on responsibility, not a people-management-only role. The successful candidate is equally comfortable designing resilient multi-tenant architecture, troubleshooting a broken log pipeline, tuning detections, hardening Microsoft 365, automating customer onboarding, and guiding an analyst through a high-severity incident.
Just as importantly, this person is the primary technical mentor for a SOC team made up largely of junior Level 1 and Level 2 analysts. Developing that team is a core measure of success in this role — not a side responsibility.
What you will own
- Technical ownership of the managed security platform, including Wazuh, Graylog, Wazuh Indexer / OpenSearch, Velociraptor, Grafana, Shuffle, MinIO, MySQL, Docker and related infrastructure.
- A secure, reliable multi-tenant architecture that preserves customer data separation, role-based access, auditability and consistent service delivery.
- Standardized customer onboarding — endpoint deployment, log-source integration, detection content, dashboards, alert routing, case workflows and offboarding.
- The day-to-day health, security and reliability of the managed IT estate — endpoints, servers, identities, Microsoft 365, the endpoint security stack and backups.
- Platform availability, capacity, performance, backup, recovery, upgrades, certificate management, vulnerability remediation and lifecycle planning.
- Senior technical escalation for ingestion failures, agent problems, detection gaps, platform incidents and complex customer investigations.
- The technical development of the SOC team — coaching, case reviews, runbooks, training exercises and clear escalation paths.
- Engineering standards, technical documentation, change control and knowledge transfer across the wider team.
Key Responsibilities
A. Platform architecture and operations
- Design and maintain highly available, supportable deployments across production, development and test environments.
- Administer containerized services, Linux hosts, storage, networking, DNS, TLS certificates, secrets and identity integrations.
- Monitor platform health, index growth, ingestion rates, queue depth, search performance, retention and resource utilization; resolve bottlenecks before they affect customers.
- Plan and execute controlled upgrades, migrations, backup validation and disaster-recovery testing with documented rollback procedures.
- Build monitoring and service-level indicators for ingestion continuity, agent health, alert latency, platform availability and customer coverage.
B. Customer onboarding and integrations
- Create repeatable onboarding patterns for Windows, Linux, macOS, firewalls, Microsoft 365, cloud services, identity platforms and common business applications.
- Develop secure deployment packages and configuration baselines for Wazuh agents, Windows Sysmon and Velociraptor clients.
- Build and maintain parsers, extractors, pipelines, streams, index strategies, API integrations and tenant-aware routing.
- Validate that each customer has complete log coverage, correct ownership, appropriate retention and tested alert delivery before production handoff.
C. Detection, automation and incident response
- Develop, test and tune Wazuh, Sigma and Graylog detection content to improve fidelity and reduce alert fatigue across varied customer environments.
- Implement enrichment and automated response workflows using CoPilot, Shuffle, threat-intelligence services, webhooks and APIs.
- Use Velociraptor for endpoint hunting, forensic collection and approved containment actions; ensure actions are logged, controlled and recoverable.
- Act as the senior platform and endpoint-response engineer during major incidents, preserving evidence and helping analysts determine scope, impact and containment steps.
- Perform post-incident technical reviews and convert lessons learned into improved detections, automation, hardening and runbooks.
D. Managed IT — endpoints, servers and Microsoft 365
- Own the standards for Windows workstation and server administration across the managed fleet: performance, uptime, patch currency and hardening baselines.
- Direct proactive monitoring and patch management through the RMM platform, with junior technicians executing routine tasks.
- Own Microsoft 365 and Entra ID architecture and security — conditional access, MFA, least-privilege roles, identity hardening and configuration policy via Intune / Endpoint Manager.
- Maintain and tune the endpoint security stack, DNS filtering, email security and DMARC enforcement.
- Coordinate vulnerability scans and security health checks, driving remediation through to closure.
- Serve as the senior escalation point for the helpdesk. Routine provisioning, password resets and first-line tickets are handled by junior technicians — this role owns the complex and the escalated.
E. Backup, continuity and compliance
- Administer endpoint offsite backup and independent Microsoft 365 cloud-to-cloud backup.
- Verify backup success, perform periodic restore tests and confirm recovery objectives are met.
- Contribute to business continuity and disaster-recovery planning and testing.
- Maintain audit-ready controls, configuration baselines and reporting aligned with insurance and financial-services obligations.
- Support periodic service and security reviews, and ensure changes follow documented change-management practice.
F. Team development and mentorship
This role serves as the primary technical mentor for a SOC team composed largely of junior Level 1 and Level 2 analysts. The engineer provides structured coaching, hands-on training, case reviews and guided troubleshooting to develop the team’s investigation, detection and incident-response capabilities. Success includes creating clear escalation paths, reusable runbooks and practical training exercises that progressively enable junior analysts to resolve more complex issues independently — while maintaining service quality and customer confidence.
- Run regular case reviews and guided troubleshooting sessions with Level 1 and Level 2 analysts.
- Define clear escalation paths so analysts know exactly when, how and to whom to escalate.
- Build reusable runbooks so the team can operate the platform without depending on undocumented individual knowledge.
- Design practical training exercises and simulations that build real investigation skill, not just tool familiarity.
- Give specific, constructive feedback that raises analysis quality while protecting customer confidence.
- Develop a visible skills path from Level 1 to Level 2 and beyond, including cross-training analysts as escalation backup.
Qualifications
Required experience and skills
- Five or more years in security engineering, SIEM engineering, detection engineering, infrastructure engineering or incident response, including at least two years owning production security platforms.
- Strong hands-on Linux administration and troubleshooting skills, including networking, storage, processes, permissions, TLS and system performance.
- Production experience with Wazuh and at least two of the following: Graylog, OpenSearch / Elasticsearch, Velociraptor, Grafana or Shuffle.
- Experience operating Docker or comparable container platforms, managing upgrades, persistent storage, backups and service dependencies.
- Practical Microsoft 365 and Entra ID administration, including Exchange Online and Intune / Endpoint Manager.
- Solid networking fundamentals — TCP/IP, DNS, DHCP, VPN, firewalls and VLAN concepts.
- Ability to onboard and normalize security data from endpoints, firewalls, Microsoft 365, cloud services and other third-party sources.
- Practical understanding of Windows security telemetry, Sysmon, endpoint investigation, network logs, authentication events and common attacker behavior.
- Scripting and automation ability using Python, PowerShell, Bash, REST APIs and structured data such as JSON or YAML.
- Demonstrated experience mentoring, coaching or technically leading junior engineers or analysts.
- Strong written documentation and customer communication skills, with professional proficiency in spoken and written English.
- Willingness to participate in an after-hours escalation rotation.
Preferred — nice to have
- Experience engineering a multi-tenant MSSP, MDR or SOC-as-a-Service platform serving many customers.
- Direct SOCFortress CoPilot administration or development experience.
- Experience in an MSP or multi-client / multi-site environment.
- Knowledge of tenant isolation, secrets management, RBAC, infrastructure as code, CI/CD, Git-based configuration management and automated testing.
- Experience with Microsoft 365 / Azure, AWS, common SMB firewalls and SaaS security integrations.
- Working knowledge of backup and recovery solutions, restore validation, ticketing / PSA systems and SLA-driven service delivery.
- Familiarity with MITRE ATT&CK, Sigma, the NIST Cybersecurity Framework, CIS Controls and security-service reporting.
- Relevant certifications such as CISSP, GIAC, OSCP, Security+, Microsoft (MS-102, AZ-104, MD-102), CompTIA, Linux or cloud certifications. Certifications are valued but do not substitute for hands-on ability.
Success Measures
- Customer onboarding becomes faster, repeatable and measurably less error-prone.
- Endpoint and log-source coverage is visible, monitored and reconciled for every customer.
- Platform incidents, ingestion gaps and agent failures are detected early and resolved within defined service targets.
- Detection fidelity improves while false positives and analyst rework decline.
- Upgrades and changes are tested, documented, recoverable and completed with minimal customer impact.
- The managed IT estate stays patched, backed up, recoverable and audit-ready.
- Junior analysts measurably progress — handling more complex cases independently, with fewer escalations for the same class of issue.
- The SOC team operates the platform using reliable runbooks rather than depending on undocumented individual knowledge.
First 90 Days
- Days 1–30. Assess the current architecture, tenants, integrations, security controls, managed IT estate, operational pain points, technical debt and failure history; establish a prioritized risk register. Meet every analyst and assess current skill levels.
- Days 31–60. Stabilize the highest-risk services, implement core health and coverage monitoring, improve backup and recovery confidence, standardize the most common onboarding path, and begin structured case reviews with the SOC team.
- Days 61–90. Deliver a practical platform roadmap covering scale, automation, detection quality, tenant isolation, lifecycle management, documentation and engineering staffing needs — together with a written skills-development plan for the SOC team.
Working Arrangement
- Location: Bangladesh, fully remote. This is not a hybrid role and there is no on-site requirement.
- Hours: Aligned to the US Eastern morning, starting at 6:00 AM Eastern — approximately 4:00 to 5:00 PM Bangladesh Standard Time, depending on US daylight saving. Candidates should be comfortable working a late-afternoon-to-evening schedule in Bangladesh.
- Availability: Participates in an after-hours escalation rotation for high-severity incidents.
- Reports to: Technical leadership (CTO or designee).
Key Relationships
- SOC analysts (Level 1 and Level 2) — technical mentor, coach and senior escalation point.
- Technical leadership — partner on service design, tooling decisions, customer commitments, capacity forecasts and technical risk.
- Helpdesk technicians — receive escalations, provide coaching and unblock complex tickets.
- Customers — translate technical findings into practical risks, decisions and remediation steps.
- Vendors and suppliers — coordinate hardware, licensing and third-party support cases.
Working Style
We value engineers who take ownership, automate recurring work, document what they build, communicate risk early and remain calm during incidents. The right person balances security rigor with the practical realities of small-business customers and a growing managed service — and takes genuine satisfaction in making the people around them better.
In short: a senior, security-minded engineer who owns the platform, keeps the managed estate patched, backed up and protected, and builds a junior SOC team into a capable one — the dependable technical anchor for the service, the team and the customer.
Equal Opportunity
Technuf is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other status protected by applicable law. Reasonable accommodations are available throughout the hiring process.
How to Apply
Please submit a résumé and a short description of a security platform you have personally operated or improved. Include the scale, your responsibilities, a difficult technical problem you solved and the measurable result. If you have mentored junior analysts or engineers, tell us briefly how you did it and what changed as a result.