Mechanicusย LLCย is a managed service provider with a security-forward practice โ Microsoft Sentinel,ย Blackpointย MDR, and a real SOC workflow rather than a "we forward alerts to a third party" arrangement.ย Roughly aย quarter of our monthly ticket volume is security work: targeted phishing investigations, malicious login attempts, SIEM triage, and MDR collaboration. We need a senior engineer who can own that work end-to-end.ย
Weโreย looking for aย Infrastructure & Security Engineerย who will serve as the senior technical escalation point for complex infrastructure, cloud, and security issues across client environments.ย ย
You'llย be the person Tier 2 calls when the impossible-travel alert turns out to be real, when the AVD environment needs re-architecting, when a client's M365 tenant has been compromised at 2am.ย You'llย also drive the proactive work โ hardening, detection engineering, post-incident reviews โ that keeps the volume from getting worse.ย
Weย don'tย expect youย to be inย theย office. We do expect youย to beย reachable during a P1.ย
Whatย Youโllย Be Doingย
Security Operations & Incident Responseย
Microsoft 365 & Identity Securityย
Cloud & Infrastructure Engineeringย
Technical Leadershipย
Whatย Weโreย Looking Forย
5+ yearsย of progressive IT experience, with at leastย 2 years focused on security operationsย (SOC analyst, security engineer, or senior engineer at a security-focused MSP).ย
Strongย Microsoft 365 security stackย experience: Defender for Office 365, Defender for Endpoint, Defender for Identity, Entra ID Protection, Conditional Access at scale.ย
Solidย Azureย fundamentals โ Entra ID, AVD, networking (VNets, NSGs, Private Endpoints), RBAC, and at least familiarity withย IaCย (Bicep or Terraform).ย
Incident response experienceย โย you'veย workedย a real BEC, a real ransomware incident, or a real account takeover end-to-end and can talk through the timeline, the decisions, and whatย you'dย do differently.ย
Nice To Haveย
- Certifications:ย SC-200, SC-300, AZ-500ย (mapped directly to our Microsoft Sentinel / Entra ID / Azure security work)ย
- Operational experience withย Blackpointย Cyber MDR โ incident handoff, isolation decisions, post-incident workflow with their SOC.ย
- Hands-on with our full operational stack:ย
- HaloPSAย (PSA/ticketing)
- NinjaOneย /ย NinjaRMMย (RMM)ย
- CIPPย (M365 multi-tenant admin)ย
- Huduย (documentation)ย
- Barracuda Email Protectionย policy management and incident response (BEC, mass-quarantine events).
- Experience designing CIS or NIST CSF-aligned baselines for SMB clients running Microsoft 365 and Azure.
HR Information:ย
- Full-time, permanent roleย
- Salary: $80,000 โ $110,000 depending on experienceย and certificationsย
- Annual performance bonus tied to security KPIs (mean time to detect, mean time toย contain, recurring-incident reduction)
- Health insurance
- Simple IRAย
- 12 daysย PTO to start (accrual increases with tenure) + 8 paid holidays
- Remote position (candidates living in Pittsburgh or surrounding areas are highly preferred)
- Schedule: Mondays-Fridays, 8 AM โ 5PMย
- Home office stipendย