Networking: Strong understanding of common business network requirements and knowledge of some common equipment brands. Ability to perform simple network troubleshooting. Ability to scope requirements for AWN services based on client’s network.
Cloud: Ability to enable IaaS-specific security controls. Ability to troubleshoot simple cloud-based service configurations for logging purposes. Familiarity with regional privacy laws.
Software as a Service: Knowledge of vulnerability management including tools and processes used to create an effective vulnerability management program.
Strong knowledge of vulnerability management including tools and processes used to create an effective vulnerability management program. Strong understanding of the concepts of Business Continuity Planning. Strong understanding of Disaster Recovery Planning and Incident Response concepts.
Authentication & Access Control: Strong understanding of Active Directory policies and events. High-level understanding of the features of Group Policy and working with INF security templates.
Endpoint: Understanding of how to harden a system using best practices and frameworks like the CIS benchmarks. Understanding of common tools used to conduct OS Based attacks. Ability to audit and make policy recommendations for common EPP/EDR solutions. Ability to read and effectively use Windows event logs, especially those originating from Sysmon, to conduct investigations and make security recommendations. Knowledge of common Windows services and protocols and how they should be properly secured.
Perimeter: Intermediate understanding of firewall concepts. Some intermediate troubleshooting skills. Familiarity with hardening common services. Be able to speak to specific advantages between IDS & IPS and when and where you might use one over the other. Familiarity with typical VPN scenarios. Knowledge of GEO filtering and potential impacts.
Communication: Hold technical conversations effectively in English, plus any additional languages required for the location, in both written and verbal contexts. Strong customer de-escalation and conflict resolution skills. Ability to break down client requests into actionable, trackable tasks.
Demonstrated ability to apply critical thinking to resolve issues and overcome challenges with some assistance as required.
Customer Focus: Brings together aspects of a trend or policy into a clear picture for internal and customers to understand. Looks for ways to add value beyond customers’ immediate requests and acts on them. Anticipates customers’ upcoming needs and concerns. Explores and addresses long-term customer needs. Demonstrates a strong commitment to customer success by providing responsive, transparent, and proactive support—keeping customers informed throughout service delivery, responding within established SLOs, and following through on commitments. Prioritizes customers’ concerns and addresses them quickly and with the customer’s best interest in mind.
Strategic Ownership: Owns the end-to-end customer outcome and quarterbacks the experience across service lines (cSOC, GTO, AWIR, and Aurora), coordinating internal teams and driving issues to resolution.
Analytical Thinking: Analyzes and interprets complex security events, incidents, vulnerabilities, and trends across network, endpoint, cloud, and log data to deliver sound, actionable guidance without supervision.
Independent Judgment: Manages assigned customers and consultancy sessions independently on any topic, exercising confident judgment on complex, cross-domain matters and recognizing when to engage other experts.
Communication and Influence: Explains complex technical issues clearly to both technical teams and C-suite executive audiences, and builds credible, trusted relationships with customers and internal stakeholders.
Leadership and Mentorship: Coaches and mentors Concierge Security Engineers 2 and junior team members, ensures the technical correctness of their work, and—when acting as team captain—coordinates the team’s day-to-day workload.
Collaboration: Partners with internal subject matter experts and service teams to resolve complex, cross-functional issues while keeping the customer experience coordinated rather than fragmented.
Adaptability and Continuous Learning: Stays current with evolving security threats, tools, and best practices and applies new knowledge to customer environments.
5 years relevant experience
Relevant IT or security education could include university degree, college diploma, or industry certifications
Technical competencies are generally at the intermediate level, as the engineer has to manage customers independently. May have technical competency of special interest at the advanced level.