Confidentiality Notice
The information contained in this document may not be disclosed, reproduced, distributed, or used for any purpose without the prior written consent of Critical Path Security, LLC. Except as required by law, the recipient agrees to maintain the confidentiality of this document and to limit access to individuals directly involved in the evaluation process.
No license, express or implied, is granted by disclosure of this document except as necessary for evaluation purposes.
Critical Path Security | Kennesaw, GA
About Critical Path Security
Critical Path Security is a human-led cybersecurity services company delivering managed security operations, incident response, and advisory support for organizations that need trusted execution across IT and OT environments. We combine experienced analysts, real-world response expertise, and purpose-built visibility and detection capabilities to identify what matters, investigate quickly, and help clients act with confidence. More than a monitoring vendor, we operate as an extension of our clients' teams by bringing accountability, context, and follow-through to day-to-day detection and response. From managed SOC and incident response to penetration testing, vCISO leadership, compliance support, and security awareness, we help organizations strengthen resilience, reduce risk, and improve security outcomes over time.
The Role
Location Kennesaw, GA
Type Full-time
Target Start Q2 2026
This is a senior technical position responsible for the quality and maturity of CPS's managed security operations. You will serve as a Tier 3 escalation point, lead incident response for complex events, develop detection and response playbooks, and contribute to the operational processes that enable our SOC to scale.
The role is hands-on. You will work the SOC floor -- triaging, investigating, and responding to real threats across multi-tenant client environments -- while also contributing to the systems, processes, and documentation that make the entire team more effective. If you are the kind of analyst who sees a repetitive workflow and writes a script to fix it, you will thrive here.
This is an opportunity to help build a SOC operation at a company protecting critical infrastructure and other regulated customer verticals.
Responsibilities
Detection & Response (Primary)
- Serve as Tier 3 escalation point for complex security incidents across multiple client environments
- Lead incident response for confirmed compromises -- containment, eradication, root cause analysis, and post-incident reporting
- Perform advanced alert triage and investigation across SIEM, EDR, and network telemetry
- Conduct proactive threat hunting on a regular cadence using MITRE ATT&CK framework
- Build, tune, and manage detection rules and correlation logic
- Produce clear, client-facing incident reports, security recommendations, and posture assessments
Scripting, Automation & SOC Maturation
- Capacity to write scripts in native, supported and vendor specific languages (i.e., Python, BASH, PowerShell, etc.) to support automation to reduce manual effort across triage, enrichment, and reporting workflows
- Build and maintain SOAR playbooks to orchestrate response actions and improve incident handling efficiency
- Develop and maintain runbooks, playbooks, and standard operating procedures for the SOC's most common alert types
- Systematize and improve client reporting workflows (DSLRs, QBR deliverables)
- Establish and track SOC performance metrics (MTTD, MTTR, false positive rate, SLA compliance)
- Audit and refine existing SOPs to raise operational consistency
Mentorship & Client Engagement
- Mentor and develop junior analysts -- raise the team's investigative capability and operational discipline
- Participate in client-facing communications: incident briefings, security recommendations, and periodic reviews
- Support customer onboarding and environment tuning for new engagements
What You Bring
Required
Requirement Detail
Experience 5+ years hands-on cybersecurity operations; 3+ years in a SOC environment at Tier 2/3 level
SIEM Hands-on proficiency with at least one major platform (Elastic/ELK preferred; Splunk, Sentinel, QRadar acceptable)
Detection Engineering Writes, tunes, and manages detection rules; familiarity with MITRE ATT&CK mapping
Incident Response Hands-on IR experience including evidence collection, containment, root cause analysis, and post-incident reporting
Python & Scripting Strong Python scripting -- builds parsers, API integrations, enrichment scripts, and automation for SOC workflows. PowerShell or Bash a plus.
SOAR Experience with SOAR platforms (Cortex XSOAR, Splunk SOAR, or Swimlane) -- has designed or maintained playbooks that automate triage, enrichment, or response workflows
Process Development Has built or significantly improved SOPs, playbooks, or runbooks in a previous role
Communication Strong written communication for client-facing deliverables; comfortable on customer calls
Work Style Self-directed; identifies and resolves problems without waiting for direction
Preferred
- Prior MSSP or MDR experience (multi-tenant operations, SLA management)
- OT/ICS security awareness (SCADA, Modbus, DNP3, Purdue Model, passive monitoring)
- Experience with Zeek, Suricata, or network-level detection tools
- Git/version control for playbook and script management
- GCIH, GCIA, GCFA, CySA+, or OSCP certifications
What We Offer
Compensation Competitive base salary commensurate with experience
Benefits Health insurance, PTO, standard benefits package
Work Model 4 days on-site in Kennesaw, GA / 1 day remote
Growth Path Clear trajectory to SOC Lead or SOC Engineering Lead as we scale
Impact You will directly shape how the SOC operates; this is a build role, not a maintain role
Mission Protect critical infrastructure -- energy grids, water systems, manufacturing operations -- from real-world cyber threats
Critical Path Security is an equal opportunity employer. We welcome applications from all backgrounds and are committed to building a diverse, high-performing team.
Pay: $120,000.00 - $140,000.00 per year
Benefits:
- Dental insurance
- Health insurance
- Paid time off
- Relocation assistance
- Vision insurance
Location:
- Kennesaw, GA 30144 (Preferred)
Ability to Relocate:
- Kennesaw, GA 30144: Relocate before starting work (Required)
Work Location: In person