Managed security services and GRC consulting for mid-market companies
NuHarbor Security operates a full-stack managed security practice built on detection (Splunk, CrowdStrike, Sentinel), vulnerability management (Tenable), and offensive tooling (Cobalt Strike, CALDERA). Their active project list—GRC program maturation, detection tuning, adversary emulation, automation workflows—reveals an internal focus on operationalizing their own service delivery at scale. Hiring is concentrated in security roles (14 of 16 open positions) across mid-to-senior levels, indicating they're scaling delivery capacity to handle growing client demand while maturing their own processes.
NuHarbor Security is a national managed security services provider founded in 2014, headquartered in Colchester, Vermont. The firm serves hundreds of clients with integrated offerings across managed detection and response, vulnerability management, penetration testing, compliance consulting, and GRC advisory. Their tech stack spans cloud platforms (AWS, Azure, GCP), endpoint detection (CrowdStrike), SIEM (Splunk), vulnerability scanning (Tenable), and threat emulation tools (Cobalt Strike, CALDERA), enabling both reactive monitoring and proactive adversary simulation. The organization operates with 51–200 employees and is hiring primarily for security delivery roles.
Splunk Enterprise Security for SIEM, CrowdStrike Falcon for endpoint detection, Tenable One for vulnerability management, Microsoft Sentinel, Wireshark for network analysis, Cobalt Strike and CALDERA for offensive testing, and cloud infrastructure across AWS, Azure, and GCP.
Active initiatives include long-term GRC program development, detection tuning, proactive threat hunting, adversary emulation exercises, and automation playbooks for scanning, reporting, and vulnerability remediation workflows.
Other companies in the same industry, closest in size