Role : :: Sr Security Automation & Detection Engineer (SIEM/SOAR)
Duration :: Long Term
Job Description ::: Logging
- Experience with deploying log pipeline solutions (e.g., Bindplane, Cribl, Databahn, forwarder agents) and troubleshooting performance
- Experience using webhooks and an understanding of common cloud & security tooling platforms such as AWS, Azure, Microsoft Defender, Crowdstrike, and more.
- Experience using and/or understanding security logs, understanding the difference between security and operational logs, and the fields that matter from a security perspective within security logs
- Ability to understand common logging formats (syslog, JSON, KV, CEF, etc.)
- Experience with creating parsers to normalize log data from disparate formats, ensuring that downstream security needs are met
- Ability to create monitoring/health dashboards across a variety of solutions for scenarios such as silent log sources
Detections
Ability to author and tune risk based alerts and machine based learning techniques (beyond what platforms natively support such as XSIAM or Google SecOps)
- Experience in leading SIEM technologies such as Google SecOps or Palo XSIAM
- Experience in upstream tools with detection suites like CrowdStrike, MSFT Defender, Wiz, Proofpoint, Obsidian
SOAR
Experience in leading SOAR platforms such as Google SecOps SOAR, Palo Alto XSOAR (Demisto), Swimlane, Splunk SOAR (Phantom), etc
- Ability to design, build, and maintain automated playbooks/workflows that orchestrate detection, enrichment, and response actions
- Ability to build and maintain custom integrations/connectors (Python, REST APIs) to extend platform functionality beyond out-of-the-box content
- Experience building and maintaining scheduled Jobs (recurring/batch automation independent of case-triggered playbooks)
- Ability to build custom HTML widgets/visual reporting tied to automation and case data
- Experience with the marketplace/content ecosystem - evaluating, deploying, and customizing pre-built integrations vs. building from scratch
Best Regards
Abdul Samad