Security Engineer ensuring clients' cybersecurity through effective management of SIEM platforms and onboarding processes. Supporting the development of Managed Sentinel SIEM service with a global team focus.
Responsibilities
Support Intake process including coverage for Eastern Standard Time Business Hours
Assist with day-to-day administration, health monitoring, and maintenance of the SIEM platform
Onboard new log source by following standard operating procedures: (validate connectivity, ensure correct parsing, and confirm events are visible and searchable in SIEM)
Implement and maintain basic SIEM content, including searches, dashboards, alerts, and reports, under guidance from senior engineers or team leads.
Monitor SIEM alerts and dashboards to identify notable events, perform initial triage, and escalate potential security incidents to the appropriate teams with clear documentation.
Help maintain and improve SIEM use cases by documenting false positives, data quality issues, and providing feedback to senior engineers for tuning.
Contribute to documentation (runbooks, standard operating procedures, onboarding checklists) for SIEM operations and use cases.
Follow change management processes for SIEM configuration changes and assist with testing in lower environments when applicable.
Stay current on SIEM best practices, logging standards, and relevant security trends; participate in internal training and knowledge‑sharing sessions.
Utilize tools and analytical skills to investigate the root cause of issues across technologies.
Requirements
Diploma or bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field.
Two years of experience in IT security, IT operations, or SOC environment, with working knowledge of SIEM.
Basic understanding of operating systems and standard server/application logs, networking fundamentals (TCP/IP, ports, protocol, firewalls, proxies), and core security concepts (common attack types, authentication/authorization)
Familiarity with at least one SIEM (Splunk, CS NG-SIEM, Palo Alto XSIAM)
Basic query or scripting skills (KQL, SPL, PowerShell, Python)
Strong analytical and problem-solving skills with attention to detail.
Practical written and verbal communication skills for both technical and non-technical audiences
Understanding of the MITRE ATT&CK framework
Experience within a MSSP environment & customer-facing.
Any relevant security certifications or training, such as Security+, SC-200, Splunk/CS NG-SIEM/Palo Alto XSIAM, or similar.
Commercial Security Service Sales Executive promoting and selling security services at Johnson Controls. Building relationships and delivering solutions to protect people and property within assigned territories.
Security Incident Responder in a leading IT service company in Germany, responsible for analyzing and responding to IT security incidents while developing technological solutions.
Deputy ISSO leading compliance and security activities for NOAA systems at RCG. Requires active Secret clearance and CISSP certification with 8+ years of experience.
Technical Recruiter hiring for Snap Inc.'s security and machine learning teams. Full life cycle recruiting support for technical talent across Snap's innovations.
Cloud Security Architect integrating cyber defense strategies across cloud platforms for Elevance Health. Lead collaboration with infrastructure and engineering teams to enhance security in cloud environments.
Senior Security Advisor designing advanced security solutions for Optiv’s clients. Driving sales and building relationships in a competitive cyber security landscape.
Personnel Security Specialist leading intake operations at PSI. Focused on case coordination, quality assurance, and team training for security suitability tasks.
Security Coordinator overseeing supervision and training of security personnel for BronxWorks' homeless services programs. Ensuring compliance, safety, and coordination with social services directors in Bronx area.
Part - Time Security Officer safeguarding personnel and property at Kaman Air Vehicles. Providing access control, monitoring systems, and responding to incidents in Bloomfield, CT.