Role: Senior Security Automation & Detection Engineer (SIEM/SOAR)
Location: Remote + Occasional Travel
Job Description:
- Logging
- Experience with deploying log pipeline solutions (e.g., Bindplane, Cribl, Databahn, forwarder agents) and troubleshooting performance
- Experience using webhooks and an understanding of common cloud & security tooling platforms such as AWS, Azure, Microsoft Defender, Crowdstrike, and more.
- Experience using and/or understanding security logs, understanding the difference between security and operational logs, and the fields that matter from a security perspective within security logs
- Ability to understand common logging formats (syslog, JSON, KV, CEF, etc.)
- Experience with creating parsers to normalize log data from disparate formats, ensuring that downstream security needs are met
- Ability to create monitoring/health dashboards across a variety of solutions for scenarios such as silent log sources
- Detections
- Ability to author and tune risk based alerts and machine based learning techniques (beyond what platforms natively support such as XSIAM or Google SecOps)
- Experience in leading SIEM technologies such as Google SecOps or Palo XSIAM
- Experience in upstream tools with detection suites like CrowdStrike, MSFT Defender, Wiz, Proofpoint, Obsidian
- SOAR
- Experience in leading SOAR platforms such as Google SecOps SOAR, Palo Alto XSOAR (Demisto), Swimlane, Splunk SOAR (Phantom), etc
- Ability to design, build, and maintain automated playbooks/workflows that orchestrate detection, enrichment, and response actions
- Ability to build and maintain custom integrations/connectors (Python, REST APIs) to extend platform functionality beyond out-of-the-box content
- Experience building and maintaining scheduled Jobs (recurring/batch automation independent of case-triggered playbooks)
- Ability to build custom HTML widgets/visual reporting tied to automation and case data
- Experience with the marketplace/content ecosystem - evaluating, deploying, and customizing pre-built integrations vs. building from scratch
Educational Qualifications:
- Required - Bachelor’s degree in Computer Science, Information Technology, Computer Engineering or closely related or equivalent.
- Preferred - Master’s degree in Management Information Systems (MIS), Computer Science, Big Data or Analytics or equivalent.
Travel:: Open to travel based up on the nature of the engagement.