Cybersecurity Specialist III
LG Energy Solution Michigan, Inc. Westborough, Massachusetts, United States · $98K–$110K/yr
Chemical Manufacturing · 1,001-5,000 employees
About the role
The Cybersecurity Specialist III is responsible for day-to-day security operations, including incident triage, SIEM management, and vulnerability remediation. They also collaborate with engineering teams to ensure secure cloud configurations and maintain compliance with industry standards.
What they look for
Requirements
Candidates must have at least 4 years of hands-on experience in security operations and a bachelor's degree in a relevant field. Proficiency in AWS security, SIEM tools, and incident response procedures is required.
Benefits
Full description
Cybersecurity Specialist III
Company Overview
LG Energy Solution Vertech, Inc. (LGES Vertech) is a full-service energy storage system supplier and integrator. Using our core strengths of expert service to our customers, unparalleled safety, and excellence in manufacturing, we bring standardized, fully integrated energy storage systems to a rapidly growing worldwide market. Our systems address our customers' needs to reduce capital equipment and installation costs while enhancing system level performance and reliability using automated monitoring systems and analytics across the battery, power conditioning and auxiliary systems. Our AEROS® energy operating system is the engine of innovation to provide advanced control functions allowing our customers to maximize the value of their energy storage assets. Our service capabilities include advanced monitoring and analytics, scheduled maintenance, augmentation, and auxiliary system upgrades. The combination of excellence in battery technology and production coupled with nearly two decades of energy storage integration makes LGES Vertech a leading supplier and integrator in the power and energy markets.
LGES Vertech is a highly matrixed, team oriented organization that fosters cross functional collaboration and innovation. The company seeks high caliber candidates with proven experience and with characteristics that embody our corporate commitment to the virtues of humble, hungry and smart in all we do. Our diverse and growing team enjoys competitive salaries, generous benefits, including 100% employer sponsored medical, dental, vision, life and disability insurance.
For more information about LGESVT, please visit www.lgensol-vt.com.
Position Overview
The Cybersecurity Specialist III is a senior individual contributor on the enterprise cybersecurity team at LG Energy Solution Vertech (LGESVT), reporting to the Lead Cybersecurity Engineer. The role carries day-to-day responsibility for security operations across LGESVT’s enterprise estate — incident triage and response, SIEM query development and tuning, vulnerability remediation, endpoint detection, cloud security in AWS, and identity and access management.
The role spans the full breadth of enterprise security operations rather than a single specialized area, and carries meaningful autonomy within each domain. The Specialist III operates independently on day-to-day security operations and works closely with the Lead Cybersecurity Engineer on complex engineering and incident response work.
Key Responsibilities
Incident Response & Investigation
- Act as a first responder for security alerts across the enterprise estate, performing triage to establish severity, scope, and the required response path.
- Investigate confirmed incidents completely to root cause using host, network, identity, and cloud log analysis.
- Produce clear and complete incident documentation — timeline, indicators, actions taken, and findings — suitable for internal review, audit evidence, and customer notification where contractually required.
- Execute containment and eradication steps under the direction of the Lead Cybersecurity Engineer and contribute to post-incident review and lessons learned.
- Participate in the security on-call rotation.
SIEM Operations & Detection
- Write, tune, and maintain SIEM queries and correlation rules across enterprise log sources.
- Work directly with raw log data to validate parsing, identify coverage gaps, and confirm that detections fire as intended.
- Tune alerts to reduce false positives while preserving detection coverage, documenting the rationale for each tuning decision.
- Support the onboarding of new log sources, including field mapping, normalization, and validation.
- Contribute detection content to the team’s MITRE ATT&CK-mapped detection library.
Vulnerability Management
- Operate the recurring vulnerability scanning cycle across servers, endpoints, and cloud workloads.
- Prioritize findings using severity, exploitability, asset criticality, and actual exposure — not CVSS score alone.
- Coordinate remediation with IT, Engineering, and system owners; track issues to closure and escalate where timelines slip.
- Maintain exception records with documented compensating controls and defined review dates.
- Report on vulnerability posture, remediation performance, and aging against defined service levels.
Endpoint Detection & Response
- Administer and tune the EDR platform, including policy configuration, exclusion management, and agent health monitoring.
- Create and maintain custom detection and logging rules to improve endpoint visibility.
- Investigate EDR detections and use endpoint telemetry to support broader incident investigations.
- Identify gaps in endpoint coverage and drive them to closure with IT and system owners.
Cloud Security — AWS
- Apply core cloud security practices across LGESVT’s AWS environment, including IAM policy review, logging and monitoring configuration, and security posture management.
- Configure and monitor native AWS security services — CloudTrail, CloudWatch, GuardDuty, Security Hub, and Config — and integrate relevant findings into the SIEM.
- Review AWS account and workload configuration against established baselines and CIS Benchmarks, tracking drift through to remediation.
- Support secure design of new AWS workloads in partnership with Engineering and the DevSecOps Engineer.
Identity & Access Management
- Apply IAM best practices across enterprise and cloud identity, including least privilege, role-based access, and separation of duties.
- Support administration of SSO, MFA, and conditional access policy in Microsoft Entra ID.
- Conduct periodic access reviews and support certification campaigns, including evidence production for ISO 27001 and SOC 2.
- Identify and help remediate standing privileged access, excessive entitlements, and orphaned or stale accounts.
Risk Assessment & Governance Support
- Perform security risk assessments of systems, vendors, and proposed changes, documenting findings and recommended treatments.
- Contribute to maintenance of the technology risk register, including tracking of open risks and mitigation status.
- Support third-party risk assessments and customer security questionnaires with technical input and supporting evidence.
- Provide technical evidence for ISO 27001, SOC 2, and CIS Controls audit and assessment activity.
Collaboration
- Work closely with the Lead Cybersecurity Engineer on complex security engineering and incident response matters.
- Collaborate with the DevSecOps Engineer, IT, Engineering, and Operations to deliver consistent security outcomes.
- Partner with the Cybersecurity Manager on compliance, audit, and governance activity.
- Contribute to security awareness content and provide practical guidance to the wider business.
Time & Travel Expectations
This role is open to any qualified applicant within the United States.
Depending on their physical location, candidates should expect to participate in video conference calls that originate in different time zones, including those with HQ in Seoul, South Korea.
Anticipate travel up to 10%, including periodic visits to LGESVT offices, data center facilities, and HQ as required.
Qualifications
Education & Certifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. Equivalent practical experience will be considered.
- One or more of the following preferred: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, GIAC (GSEC, GCIH, or GCIA), CompTIA CySA+ or Security+, or Microsoft SC-200.
- Candidates actively working toward an advanced certification are encouraged to apply; certification support is available.
Experience
- Minimum 4 years of hands-on experience in a security operations, security analyst, or cybersecurity specialist role.
- Demonstrated experience performing incident response, including alert triage, investigation to root cause, and written documentation of findings.
- Hands-on SIEM experience, including writing and tuning queries and working directly with log data (Microsoft Sentinel, Splunk, Elastic, or equivalent).
- Practical vulnerability management experience, including risk-based prioritization and coordinating remediation with system owners.
- Working experience with EDR platforms, including custom rule creation and analysis of endpoint telemetry.
- Strong working knowledge of AWS services and core cloud security practices, including IAM, logging, monitoring, and posture management.
- Applied understanding of identity and access management, including SSO, MFA, and least-privilege access models.
- Experience performing or materially contributing to security risk assessments.
Skills
- Clear technical writing — incident documentation, risk findings, and remediation guidance that a non-specialist owner can act on without translation.
- Strong working knowledge of Windows and Linux, and the security controls associated with each.
- Scripting and query ability for automation and data analysis (Python, PowerShell, KQL, or SPL).
- Familiarity with risk management and control frameworks: NIST CSF, ISO 27001, SOC 2, and CIS Controls.
- Sound judgment under time pressure, with the discipline to escalate appropriately when information is incomplete.
Preferred Attributes
- Experience in the energy, utilities, or industrial sectors, or exposure to OT/ICS environments.
- Familiarity with battery energy storage, renewable energy, or grid-scale infrastructure.
- Prior exposure to ISO 27001 or SOC 2 audit cycles as an evidence provider.
- Hands-on experience with Microsoft Entra ID, Microsoft Defender, or Microsoft Purview.
- Demonstrated interest in detection engineering, security automation, or infrastructure-as-code.
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
-
Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr