Logo for US LBM

US LBM Engineer - Cybersecurity Operations

Role overview

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field
  • 3+ years of experience in cybersecurity operations, security engineering, or incident response
  • Hands-on experience with Microsoft Defender XDR technologies
  • Experience with Microsoft Sentinel

Responsibilities

  • Monitor, investigate, and respond to cybersecurity alerts, incidents, and threats across enterprise and cloud environments
  • Administer and optimize Microsoft Sentinel, including log collections, integrations, and analytics rules
  • Develop and tune detections, alerts, and KQL queries to improve visibility and reduce false positives
  • Coach and mentor junior cybersecurity analysts

About the company

US LBM logo

US LBM

Building Materials Wholesale

You already know US. US LBM’s local brands are some of the most well known and celebrated names in building products distribution. Our local teams are your friends, family members and neighbors. US LBM’s brands include ALCO Doors, Arrow Building Center, Arrowhead Stairs & Trim, Bailey Lumber & Supply, Barrons, Bellevue Builders Supply, Brand Vaughan Lumber, Breckenridge & Edwards Building Centers, BSA, Crown Components, Darby Doors, Deering Lumber, Desert Companies, East Haven Builders Supply, Evergreen Lumber, Forge Lumber, Foxworth-Galbraith Lumber, GBS Builders Supply, Gilcrest/Jewett Lumber, Higginbotham Brothers, Hines Building Supply, Hart Lumber & Components, Jennings Builders Supply, Myers Building Product Specialists, Junior's Building Supplies, KI Lumber, Lampert Lumber, Lumber Specialties, Lyman Companies, Maner Builders Supply, Massey Builders Supply, Myrtle Beach Building Supply, Meek’s, Mid-Cape Home Centers, Musselman Lumber, NexGen , Oldham Lumber, Parker’s Building Supply, Poulin Lumber, Professional Builders Supply, R&K Building Supplies, Raymond Building Supply, Ridgefield Supply, Ridout Lumber, Shelly's Supply, Standard Lumber & Supply, Truss Fab, Universal Supply, Wisconsin Building Supply and Zeeland Lumber & Supply. The products we sell are the foundational materials needed to build, maintain and renovate your home or business. The entrepreneurial spirit that fueled the origins of our divisions and the creation of US LBM still propel us today. That spirit along with our culture of empowerment, drive to continuously improve and the strength of our collective enterprise creates unlimited opportunities for US, our associates, customers and communities, now and in the future. Our trusted teams and talented people are what will let US realize those opportunities and achieve success together. We hope you’ll join US on our journey.

Company details

Company typeXLarge
IndustryBuilding Materials Wholesale
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

US LBM is one of the leading and fastest growing distributors of specialty building materials in the United States, with a team of over 13,000 employees located throughout the country. Since our founding in 2009, we have acquired over 100 companies and have expanded to more than 450 locations serving 37 states. US LBM is a progressive organization that promotes a unique culture that focuses on the value of its customers and associates. Developing our people is critical to our strategy and fostering our culture of empowerment.

.

A Brief Overview
The US LBM Engineer - Cybersecurity Operations is a hands-on technical role responsible for monitoring, detecting, investigating, and responding to cyber threats across US LBM's Microsoft security environment. This position supports Microsoft Sentinel, Microsoft Defender XDR, Attack Surface Reduction (ASR), threat hunting, incident response, automation, and security for Microsoft 365 Copilot and AI technologies.

Pay Rate: $100K - $120K annual salary

What you will do

  • Monitor, investigate, and respond to cybersecurity alerts, incidents, and threats across enterprise and cloud environments.
  • Administer and optimize Microsoft Sentinel, including log collections, integrations, connectors, analytics rules, watchlists, threat intelligence integrations, and dashboards.
  • Working with the Cyber Solutions team, support and maintain Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
  • Develop and tune detections, alerts, and KQL queries to improve visibility and reduce false positives.
  • Perform threat hunting and security investigations using Defender XDR and Sentinel.
  • Coach and mentor junior cybersecurity analysts by providing guidance on investigations, threat hunting, detection engineering, Microsoft security technologies, and incident response best practices.
  • Implement and maintain automation using Sentinel Automation Rules and Logic Apps.
  • Manage, monitor, and maintain health of Microsoft Defender for Endpoint, and cyber related agents Support and collaborate in the establishment and maintenance of server and workstation security baselines, including QA check on server builds.
  • Optimize Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules and endpoint hardening.
  • Support security controls, governance, and monitoring for Microsoft 365 Copilot and AI-enabled technologies.
  • Coordinate penetration testing engagements and track remediation activities.
  • Support purple team exercises and validate the effectiveness of security detections and response capabilities.
  • Collaborate with infrastructure, cloud, identity, and application teams to improve security posture.
  • Develop and maintain operational procedures, runbooks, and technical documentation.


Required For All Jobs

  • Perform other duties as assigned.
  • Comply with all policies and standards.
  • Adhere to Company’s commitment to workplace safety.
  • Participate in and complete assigned trainings.


Education Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field.


Experience Qualifications

  • 3+ years of experience in cybersecurity operations, security engineering, or incident response.
  • Hands-on experience with Microsoft Defender XDR technologies.
  • Experience with Microsoft Sentinel.
  • Experience investigating security incidents involving endpoints, identities, phishing, malware, and cloud services.
  • Experience writing KQL queries for threat hunting, investigations, and detection engineering.
  • Experience implementing and managing Microsoft Attack Surface Reduction (ASR) rules.


Skills and Abilities

  • Strong understanding of security operations, threat hunting, detection engineering, and incident response.
  • Working knowledge of Windows, Active Directory, Microsoft Entra ID, networking, and cloud security.
  • Strong analytical and problem-solving skills.
  • Experience with Microsoft Azure Cloud environment and typical hybrid environment preferred.
  • Experience with Microsoft Intune preferred.
  • Experiencing implementing automated desired state configuration, server baselines, and CIS benchmarking preferred.
  • Experience with Tenable products or other vulnerability management solutions preferred.
  • Experience with purple team exercises and security control validation preferred.


Licenses and Certifications

  • SC-200, AZ-500, Security+, CISSP, or similar certifications preferred.


Travel Requirements

  • 10% Travel.

.

US LBM Holdings, LLC, is an equal-opportunity employer. We do not discriminate on the basis of race, color, religion, creed, national origin or ancestry, sex, age, physical or mental disability, veteran or military status, genetic information, sexual orientation, gender identity, marital status, military status, order of protection status, or any other legally recognized protected basis under federal, state, or local law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Cybersecurity Engineer Related jobs

Other jobs at US LBM

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.