Description
Summary:
UltaHost is seeking a Senior Internal Security & Security Operations Engineer to own internal security, strengthen protection across workforce and systems, and lead incident response.
Highlights:
1. Senior, hands-on technical role in internal security and operations
2. Responsibility across IAM, security monitoring, SOC ops, and incident response
3. Opportunity to drive security improvements in a large-scale environment
UltaHost is looking for a Senior Internal Security \& Security Operations Engineer to take ownership of internal security and help strengthen the protection of our workforce, identities, systems, and day\-to\-day operations.
This is a senior, hands\-on technical role with responsibility across Identity \& Access Management (IAM), internal security, security monitoring, SOC operations, and incident response. The position requires someone who can combine strong technical security expertise with a structured and operational approach to access control, monitoring, investigation, and risk reduction.
You will be responsible for securing employee and contractor identities, privileged access, credentials, internal systems, endpoints, VPN and remote access, while ensuring that appropriate security controls are implemented and maintained throughout the account and access lifecycle.
A key part of the role will also involve actively monitoring security events and investigating suspicious activity across authentication systems, endpoints, internal applications, and cloud/SaaS environments. You will take an active role in identifying potential threats, investigating security incidents, collecting evidence, containing risks, coordinating remediation, and ensuring corrective actions are followed through to closure.
You will work closely with HR, IT, system owners, and other technical teams to improve access governance, strengthen internal security controls, enhance detection and response capabilities, and reduce security risks across UltaHost’s internal environment.
We are looking for someone who is comfortable taking end\-to\-end ownership — from implementing preventive controls and improving security monitoring to investigating real incidents and driving security improvements across the organization. **What You’ll Own****Identity, Access \& Credential Security*** Design and maintain RBAC across departments, roles, and critical systems.
* Manage MFA, SSO, PAM, password vaults, API keys, SSH keys, recovery codes, and secrets.
* Own security controls around onboarding, role changes, temporary access, contractor access, and offboarding.
* Identify and remove shared, dormant, unnecessary, and excessively privileged accounts.
* Conduct regular access reviews and maintain approval and audit evidence.
**Security Monitoring \& Incident Response*** Monitor and investigate alerts from SIEM, EDR, IDS/IPS, authentication systems, cloud/SaaS platforms, internal applications, and endpoints.
* Investigate suspicious logins, compromised accounts, credential leaks, malware, privilege abuse, insider risk, and unauthorized access.
* Collect evidence, contain threats, coordinate recovery, and drive corrective actions through closure.
* Maintain detection rules, alert quality, incident records, escalation paths, and response playbooks.
* Lead internal security incidents and support infrastructure/product incidents involving identities or credentials.
**Internal Systems \& Workforce Security*** Define security requirements for laptops, VPN and remote access, email, code repositories, support platforms, finance tools, and administrative systems.
* Work closely with HR and IT on joiner/mover/leaver processes and internal security investigations.
* Support security awareness, phishing prevention, and secure handling of sensitive information and credentials.
**What We’re Looking For*** 5\+ years of hands\-on experience in internal security, IAM, SOC/security operations, incident response, IT security, or a closely related role.
* Practical experience with RBAC, MFA, SSO, PAM, identity providers, password management, account lifecycle management, and access auditing.
* Hands\-on experience with SIEM, EDR, IDS/IPS, centralized logging, authentication logs, alert triage, and case management.
* Proven ability to investigate compromised accounts, malware, credential leaks, suspicious authentication activity, insider risk, and unauthorized access.
* Strong understanding of Linux access, SSH, VPN, endpoints, cloud/SaaS administration, email security, and remote\-workforce security.
* Strong organizational skills and the ability to enforce security controls while collaborating with HR, IT, managers, and system owners.
**Preferred Background**
Experience in web hosting, cloud infrastructure, data centers, SaaS, fintech, MSSP, or another distributed technology environment is highly valuable. Preferred certifications include Security\+, CySA\+, GCIH, SC\-200, IAM/PAM vendor certifications, CISSP, or equivalent practical expertise. Certifications are a plus — hands\-on experience matters more. **What Success Looks Like****You will help us improve:*** MFA and privileged\-access coverage
* Joiner/mover/leaver security and access\-removal speed
* Control of shared, dormant, and excessive access
* Alert response and incident\-resolution times
* Access\-review coverage and security evidence
* Internal security standards, procedures, and playbooks
**Important**
We are not looking for a policy/compliance\-only profile. The successful candidate must have real hands\-on experience administering access controls, operating security tooling, investigating logs, and responding to security incidents.
You will work closely with our second cybersecurity specialist, the Product \& Infrastructure Security Engineer, as well as DevOps, Network, Product, Engineering, Support, Abuse, HR, Finance, Legal, and executive management.
If you enjoy taking ownership, building security controls, investigating real incidents, and improving security in a large\-scale technology environment, we’d like to hear from you.