All Jobs Vacancy

Sr Security Automation & Detection Engineer (SIEM/SOAR)

Posted 1 day ago by Reliable Software Resources

Role : :: Sr Security Automation & Detection Engineer (SIEM/SOAR)

Duration :: Long Term

Job Description ::: Logging

  • Experience with deploying log pipeline solutions (e.g., Bindplane, Cribl, Databahn, forwarder agents) and troubleshooting performance
  • Experience using webhooks and an understanding of common cloud & security tooling platforms such as AWS, Azure, Microsoft Defender, Crowdstrike, and more.
  • Experience using and/or understanding security logs, understanding the difference between security and operational logs, and the fields that matter from a security perspective within security logs
  • Ability to understand common logging formats (syslog, JSON, KV, CEF, etc.)
  • Experience with creating parsers to normalize log data from disparate formats, ensuring that downstream security needs are met
  • Ability to create monitoring/health dashboards across a variety of solutions for scenarios such as silent log sources

Detections

Ability to author and tune risk based alerts and machine based learning techniques (beyond what platforms natively support such as XSIAM or Google SecOps)

  • Experience in leading SIEM technologies such as Google SecOps or Palo XSIAM
  • Experience in upstream tools with detection suites like CrowdStrike, MSFT Defender, Wiz, Proofpoint, Obsidian

SOAR

Experience in leading SOAR platforms such as Google SecOps SOAR, Palo Alto XSOAR (Demisto), Swimlane, Splunk SOAR (Phantom), etc

  • Ability to design, build, and maintain automated playbooks/workflows that orchestrate detection, enrichment, and response actions
  • Ability to build and maintain custom integrations/connectors (Python, REST APIs) to extend platform functionality beyond out-of-the-box content
  • Experience building and maintaining scheduled Jobs (recurring/batch automation independent of case-triggered playbooks)
  • Ability to build custom HTML widgets/visual reporting tied to automation and case data
  • Experience with the marketplace/content ecosystem - evaluating, deploying, and customizing pre-built integrations vs. building from scratch

Best Regards

Abdul Samad

Rate:
Not specified
Location:
Remote
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Not Specified

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job