3 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
IT Security Engineer
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
IT Security Engineer (SIEM/Cybersecurity): Managing SIEM operations and investigating security incidents across network traffic, logs, and security controls with an accent on incident triage, threat detection, and vulnerability monitoring. Focus on automating security investigations with Python and shell scripting, analyzing PCAP and forensic data, and reducing false positives through reporting and SIEM tuning.
Location: Dallas, Texas, United States; office environment
Company
Corporation operates in the energy and utility sector.
What you will do
- Manage the SIEM environment, including agent installation, alert and rule configuration, reporting, and system health.
- Analyze network traffic, logs, and incidents from multiple sources to assess severity and risk.
- Identify, investigate, report, and resolve security incidents while coordinating the required response resources.
- Deploy and maintain network security controls, compose security alerts, and advise incident responders.
- Develop incident metrics, trend analyses, and tuning initiatives to reduce false positives.
- Write scripts and programs to automate security triage and support coordination between users, IT engineering, and security operations.
Requirements
- Bachelorβs degree in Computer Science or a closely related field and four years of related information security experience, or equivalent.
- Experience with CIRT, CERT, CSIRC, or SOC operations and security incident response.
- Experience with SIEM, antivirus, intrusion detection and prevention, firewalls, vulnerability assessment, vulnerability management, and log monitoring tools.
- Shell scripting with Unix tools and Python; familiarity with operating systems, networking, TCP/IP, LDAP, 802.1x, SNMP, SSL, TLS, and IPSEC.
- Knowledge of PCAP analysis, digital forensics, forensic tools such as Volatility or EnCase, the Lockheed kill chain, and NIST.
- Availability to respond to emergency security incidents outside normal business hours.
Nice to have
- Professional security certification such as CEH, CISSP, SSCP, or GIAC.
- Experience with PCI compliance, government agencies, digital media analysis, or computer forensics.
- Knowledge of LogRhythm or comparable SIEM technologies and scripting with PowerShell or Bash.
Culture & Benefits
- Office-based work environment.
- Regular communication with internal and external customers and senior management on technical and complex security matters.
- Opportunity to participate in contracted security monitoring and analytical services with external vendors.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β
ΠΠΎΡ ΠΎΠΆΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
22 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
Application Security Engineer (AI)
2 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
Senior Cybersecurity Analyst (SOC)
15 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
Security Engineer (Microsoft Security)
1 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄
System Security Engineer
4 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Cyber Security Engineer (IAM)
4 Π΄Π½Ρ Π½Π°Π·Π°Π΄