Security Analyst/Engineer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Systems Engineer
Who We Are...
Since our founding in 1901, Limbach's primary core value has always been simple:
We Care. That commitment extends to our people, our customers, and the communities we serve‑driving a culture of belonging across our industry.
Limbach Facility Services LLC, a subsidiary of Limbach Holdings, Inc., (NASDAQ: LMB), is a leading building systems solutions firm delivering mission‑critical systems that support life's most important moments. We specialize in revitalizing and maintaining HVAC, mechanical, electrical, plumbing, and control systems within existing facilities‑ensuring buildings are always ready to perform when it matters most.
Learn more about Limbach by checking out our You Tube channel:
We Are Limbach - You Tube
From healthcare and education to government and commercial facilities, we partner with building owners and operators to safeguard reliability, efficiency, and comfort where it's needed most.
Our vision is to create value for building owners targeting opportunities for long term relationships.
Our purpose is to create great opportunities for people.
Learn more about Limbach's commitment to our people and career opportunities, straight from our employees via the Limbach Unlocked podcast:
Limbach Unlocked - Why We Chose Limbach
We carry out our vision and purpose through a commitment to our four core values...
- We Care
- We Act with Integrity
- We Are Innovative
- We Are Accountable
- Base salary range of $130K - $140K
- Full portfolio of medical, dental, and vision benefits, along with 401K plan and company match.
- HSA, FSA, and life insurance offerings.
- Maximize your professional development with our award‑winning Learning & Engagement team.
- Engage in our "We Care" culture through our ERGs, brought to you by EMBRACE.
- Career pathing flexibility and mobility.
As Security Analyst / Engineer, you will serve as the organization's primary, hands‑on security operations lead. Reporting directly to the CIO, the candidate will triage SOC outputs, tune detection logic, drive automated response through SOAR playbooks, own the vulnerability management lifecycle, and lead incident response from detection through remediation and post‑incident lessons learned. They act as a trusted partner to our outsourced SOC, the quarterback for IR, and the technical voice to the CIO and Board on operational security posture working closely with our IT Operations leader.
ThisPosition...
Some examples of the work you might do includes:
- Security Operations & Monitoring: Serves as the primary liaison to our outsourced SOC and vCISO. Triage, validate, and prioritize alerts from SIEM (e.g., Google Chronicle, Gray Matter, or equivalent). Ensures log integrity, enrichment, and actionable alerting.
- SOAR & Automation: Builds, maintains, and iterates SOAR playbooks (Google SOAR or comparable) to automate containment, enrichment, and evidence collection; lowers MTTR by automating low‑risk actions while preserving human judgment for high‑impact events.
- Incident Response: Lead detection containment eradication recovery workflows. Owns post‑incident reviews, creates remediation roadmaps, and tracks closure of corrective actions. Conducts regular tabletop exercises and maintains IR runbooks and escalation paths.
- EDR/MDR/XDR Management: Administers and tunes EDR/MDR/XDR platforms (deployment health, telemetry, detection rules, containment capabilities). Investigates endpoint events, performs root cause analysis, and coordinates remediation with IT operations.
- Vulnerability Management: Operates the vulnerability management program (Rapid7, Tenable.io, or equivalent): schedules scans, triages findings, prioritizes by risk and asset criticality, and shepherds remediation with engineering teams. Proposes and verifies system hardening measures and baselines.
- Detection Engineering: Authors correlation rules, analytic searches, and detection content; reduces false positives while increasing meaningful detections. Builds dashboards and KPIs that communicate detection coverage and efficacy.
- M&A & Integration Security: Leads security due diligence and integration activities for acquisitions: identities & accesses…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).