обновлено 8 дней назад
Security Operations Platform Engineer (SIEM/SOAR)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Platform Engineer (SIEM/SOAR): Managing and optimizing SIEM/SOAR platforms for security monitoring and incident response with an accent on log ingestion, detection engineering, alert tuning, and security reporting. Focus on building API-based integrations, improving data normalization and pipeline efficiency, and supporting investigations with forensic data retrieval.
Location: Remote from the United States; US PA home office. Travel up to 5 days per year.
Company
is a family-owned manufacturer of personal care, household, packaging, and related products with more than 5,000 team members and manufacturing campuses across the United States and Canada.
What you will do
- Configure, maintain, monitor, upgrade, and optimize SIEM/SOAR platforms, including access controls and data retention.
- Onboard, normalize, and troubleshoot logs from firewalls, endpoints, servers, cloud services, SaaS platforms, and identity providers.
- Build API-based integrations and automation scripts, while improving parsing, data mappings, pipeline performance, and cost efficiency.
- Develop and tune detection rules, alert thresholds, dashboards, reports, KPIs, and security posture metrics.
- Support SOC analysts during investigations with platform assistance, log extraction, and forensic data retrieval.
- Evaluate new integrations, maintain vendor relationships, and recommend improvements to security visibility and coverage.
Requirements
- Remote work from the United States and availability for up to 5 travel days per year.
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field, or equivalent experience.
- At least 3 years of experience managing a SIEM platform; SOAR management experience is preferred.
- Knowledge of network protocols, firewalls, IDS/IPS, EDR, cloud security logs, and formats such as CEF, LEEF, and JSON.
- Experience with SIEM query languages and scripting in Python, PowerShell, or similar technologies.
- Working knowledge of MITRE ATT&CK, threat intelligence, incident response, troubleshooting, and log analysis.
Nice to have
- Experience developing automation and incident response playbooks.
- Familiarity with Azure, AWS, or GCP log configurations.
- Experience supporting NIST, ISO 27001, SOX, HIPAA, or similar compliance frameworks.
- Security+, CySA+, CASP+, GCIA, GCIH, CISSP, or equivalent certification.
Culture & Benefits
- Collaborative environment focused on continuous learning and professional development.
- Competitive base salary and bonus opportunities.
- At least three weeks of paid time off.
- Medical, dental, and vision coverage starting on day one.
- 401(k) with employer match, paid parental leave, tuition assistance, and dependent care support.
- Wellness program with potential insurance premium savings of up to $4,000 per year.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Security Analyst (Cybersecurity)
50 - 65$
12 дней назад
Senior Security Incident Response Analyst (Fintech)
8 дней назад
Manager, Security Operations (Hands On/Technical) (Cybersecurity)
108 000 - 148 000$
13 дней назад
Security Operations Analyst (Aerospace)
8 дней назад
Cybersecurity Engineer (US Federal)
130 200 - 195 400$
14 дней назад
Security Platform Developer, Security Automation (Python, Splunk SOAR)
65 000 - 105 000CAD