Job description
What you’ll be doing…
The Principal SIEM Engineer is a part of our client’s Engineering team. This role is designed to provide senior-level leadership for the design, engineering, and implementation of security event data collection for our managed security service customers related to incident response, threat monitoring, threat intelligence, and operations across the SIEM portfolio. You will be engaged in work related to data identification, assessment, ingestion, normalization, and enrichment activities required for our client’s solution and SOC team to perform proper detection and analytics of cyber threats and response. We have our own SIEM solution called Legion; however, we are looking for someone with strong familiarity with one or more of the following SIEM engines: Splunk, Sentinel, Chronicle, QRadar, and LogRhythm.
Main Responsibilities Include:
- Lead and perform the content development within the SIEM Platform which includes use case creation, dashboard design, tuning of use cases to minimize false positives, development of reporting metrics such as SLA and KPI reports, and log source configuration.
- Threat hunting and independent threat research to augment and feed custom use case creation. You will lead a small SOC team that does this function on a daily basis.
- Work with the customer to incorporate asset landscape details, severity threats campaigns, and data breaches, as well as perform impact and exposure assessments relative to the customer.
- Act as an escalation point for the Security Analysts to assist and advise on the most complex security threat investigations.
- Support and consult vendors and customers to assist in implementing sound and secure logging practices while interfacing with customers in support of their logging requirements.
- Leverage advanced knowledge of security operations, cyber security tools, intrusion detection, and secured networks to integrate with the SIEM platform.
- Determine and report the accomplishments of project initiatives across stakeholder groups, providing consulting and guidance on how to drive business results from the data available.
- Review and enhance logging information flow strategies and technical information flow required for log onboarding; create the work plan required for logging onboarding to include determining the technical details.
- Mentor and support SOC Analysts Tier 1-3.
- Provide prospect and customer demos of our SIEM solution as required. These are online, virtual demos therefore, good presentation skills are required.
Where you’ll be working…
This role is a fully remote / work-from-home role.
What we’re looking for…
You’ll need to have:
- Bachelor’s degree or four or more years of work experience.
- Six or more years of relevant work experience.
- Experience as a SIEM / SEM Engineer with experience creating custom use cases, dashboards, and reporting.
- Six or more years of experience as a SIEM / SEM Engineer and Content Developer for any of the following platforms: Splunk ES, QRadar, Sentinel, Sumo Logic, Chronicle, Sentinel, and LogRhythm.
- SIEM administration, configuration, optimization experience.
- Threat hunting experience.
- Experience with Linux command line.
- Experience with regular expressions and data normalization.
Even better if you have:
- Master’s degree in information security, cyber security, computer science, or a related field.
- Experience with SIEM Logs and as a Network Certified Administrator.
- Strong interpersonal skills and collaborative style to enable success across multiple partners.
- Experience working in a Security Operation Center environment.
- Cloud experience.
- Capability to clearly and succinctly explain highly complex issues to senior executives.
- Strong communication and presentation skills along with the ability to handle multiple priorities in a fast-paced dynamic startup environment.
- Experience preparing and delivering presentations to peers or senior executives.
- Ability to negotiate, when warranted, in order to work with other teams.
- Ability to grasp and assess “big picture” issues and bring them to light in order to foster positive change for a more robust data ingestion platform and process.
Note: This is a contract-to-hire role.
Job Type: Contract
Salary: $30.00 – $60.00 per hour
Schedule:
- 4-hour shift
Work Location: Remote
