{"schemaVersion":"jobsearcher.job.v1","id":"a565cc6689b601799a54b577","url":"https://jobsearcher.com/jobs/a565cc6689b601799a54b577","canonicalUrl":"https://jobsearcher.com/jobs/a565cc6689b601799a54b577","title":"Security Operations Engineer (builder-operator) - MSP/MSSP","description":"Contract to Hire Careful Security is a boutique cybersecurity and compliance firm. We act as the security operations and vCISO function for a portfolio of clients, and we run the security tooling that protects them.This is a builder role: you will stand up and then run the security stack across our client base, not inherit a finished one. You will build SIEM deployments from scratch, wire and migrate EDR and RMM tenants, manage user lifecycles across identity platforms, and write the queries and alerts that turn raw telemetry into the security KPIs our clients see. Then you operate what you built: triage, tune, respond, harden.You work directly in client environments and on shared multi-tenant consoles. Your judgment is the control; there is no one between you and a production change.What you will do:- Build SIEM deployments from scratch in client clouds (Wazuh): installation, log-source onboarding, rules, alert tuning, dashboards- Administer and migrate EDR across client tenants (SentinelOne): deployment, policy, exclusion discipline on shared consoles- Run RMM onboarding, patching, scripting, SSO and roles (NinjaOne)- Manage user lifecycles across M365, Entra ID and Google Workspace: provisioning, offboarding, access revocation, credential rotation- Write and maintain the queries, scripts and API pulls behind client security KPIs and alerting- Stand up and harden Azure environments: VMs, networking, Entra ID, RBAC- Triage and tune detections; run incident response for phishing, BEC and endpoint compromise- Design network and SASE segmentation; verify backup and recovery actually restores- Brief client leadership in plain languageHow we hire:We screen for how you think, not what you have memorized. Our written screen presents realistic scenarios from our actual work and asks how you would reason through them. Candidates who clear it move to a live conversation on the same kinds of problems.IDEAL QUALIFICATIONS - 3+ years in an MSP or MSSP administering security and IT tooling across multiple client tenants- Hands-on EDR administration (SentinelOne or equivalent: CrowdStrike, Defender for Endpoint): deployment, policy, exclusions, tenant migration- RMM administration (NinjaOne or equivalent: Datto, ConnectWise, Kaseya): onboarding, patching, scripting, SSO and role configuration- Built or substantially rebuilt a SIEM deployment (Wazuh, Security Onion, Elastic, or Splunk): installation, log-source onboarding, rule and alert tuning, not just console use- Azure administration: VMs, networking, Entra ID, RBAC, and standing up new environments from scratch- User lifecycle management across M365 / Entra / Google Workspace: provisioning, offboarding, access revocation, credential rotation- Alert triage and management: tuning noise down without suppressing true positives- Comfortable writing queries and scripts for security KPIs and reporting (KQL, SQL, PowerShell, Python, or API-based)PREFERRED QUALIFICATIONS - SentinelOne, NinjaOne, or Wazuh specifically (we run all three)- Cato SASE, Cisco Umbrella, KeepAware, or Microsoft Purview exposure- SOC analyst experience: incident response, phishing and BEC investigation, endpoint isolation- Experience building client environments or security stacks from zero at an MSP- Certifications (AZ-500, SC-200, Security+, GCIH, OSCP) welcome; judgment matters more than letters","company":"Careful Security","rawCompany":"careful security","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-29T09:15:27.039Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Operations Engineer (builder-operator) - MSP/MSSP","description":"Contract to Hire Careful Security is a boutique cybersecurity and compliance firm. We act as the security operations and vCISO function for a portfolio of clients, and we run the security tooling that protects them.This is a builder role: you will stand up and then run the security stack across our client base, not inherit a finished one. You will build SIEM deployments from scratch, wire and migrate EDR and RMM tenants, manage user lifecycles across identity platforms, and write the queries and alerts that turn raw telemetry into the security KPIs our clients see. Then you operate what you built: triage, tune, respond, harden.You work directly in client environments and on shared multi-tenant consoles. Your judgment is the control; there is no one between you and a production change.What you will do:- Build SIEM deployments from scratch in client clouds (Wazuh): installation, log-source onboarding, rules, alert tuning, dashboards- Administer and migrate EDR across client tenants (SentinelOne): deployment, policy, exclusion discipline on shared consoles- Run RMM onboarding, patching, scripting, SSO and roles (NinjaOne)- Manage user lifecycles across M365, Entra ID and Google Workspace: provisioning, offboarding, access revocation, credential rotation- Write and maintain the queries, scripts and API pulls behind client security KPIs and alerting- Stand up and harden Azure environments: VMs, networking, Entra ID, RBAC- Triage and tune detections; run incident response for phishing, BEC and endpoint compromise- Design network and SASE segmentation; verify backup and recovery actually restores- Brief client leadership in plain languageHow we hire:We screen for how you think, not what you have memorized. Our written screen presents realistic scenarios from our actual work and asks how you would reason through them. Candidates who clear it move to a live conversation on the same kinds of problems.IDEAL QUALIFICATIONS - 3+ years in an MSP or MSSP administering security and IT tooling across multiple client tenants- Hands-on EDR administration (SentinelOne or equivalent: CrowdStrike, Defender for Endpoint): deployment, policy, exclusions, tenant migration- RMM administration (NinjaOne or equivalent: Datto, ConnectWise, Kaseya): onboarding, patching, scripting, SSO and role configuration- Built or substantially rebuilt a SIEM deployment (Wazuh, Security Onion, Elastic, or Splunk): installation, log-source onboarding, rule and alert tuning, not just console use- Azure administration: VMs, networking, Entra ID, RBAC, and standing up new environments from scratch- User lifecycle management across M365 / Entra / Google Workspace: provisioning, offboarding, access revocation, credential rotation- Alert triage and management: tuning noise down without suppressing true positives- Comfortable writing queries and scripts for security KPIs and reporting (KQL, SQL, PowerShell, Python, or API-based)PREFERRED QUALIFICATIONS - SentinelOne, NinjaOne, or Wazuh specifically (we run all three)- Cato SASE, Cisco Umbrella, KeepAware, or Microsoft Purview exposure- SOC analyst experience: incident response, phishing and BEC investigation, endpoint isolation- Experience building client environments or security stacks from zero at an MSP- Certifications (AZ-500, SC-200, Security+, GCIH, OSCP) welcome; judgment matters more than letters","datePosted":"2026-08-29T09:15:27.039Z","dateModified":"2026-08-29T09:15:27.039Z","hiringOrganization":{"@type":"Organization","name":"Careful Security","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a565cc6689b601799a54b577"},"url":"https://jobsearcher.com/jobs/a565cc6689b601799a54b577"}}