Overview
Remote
On Site
Accepts corp to corp applications
Contract - W2
Contract - Independent
Contract - 12+ Month(s)
Skills
python
cybersecurity
Devo
Job Details
Job Title: Senior Cybersecurity Engineer
Location: Remote
Duration: 12+ Months
Your main tasks:
- SIEM Engineering & Development: Design, develop, implement, and optimize advanced correlation rules, use cases, and detection logic within the enterprise SIEM platform.
- Log Source Management: Architect and maintain robust log ingestion pipelines from diverse security and IT systems, ensuring comprehensive data collection, normalization, and parsing.
- Threat Detection & Analysis: Develop and refine high-fidelity security alerts, dashboards, and reports to enhance threat identification, reduce false positives, and provide actionable insights.
- Security Operations Collaboration: Collaborate closely with the Security Operations Center (SOC) to optimize response workflows, improve threat detection capabilities, and provide expert-level support during security incidents.
- Threat Intelligence & Proactive Hunting: Maintain expertise in emerging threats, attack techniques, and security best practices. Proactively hunt for advanced threats and develop new detection methods based on threat intelligence and adversary tactics, techniques, and procedures (TTPs).
- Automation & Scripting: Automate SIEM tasks, workflows, and integrations using scripting languages (e.g., Python, PowerShell) to improve efficiency and scalability.
- Documentation & Knowledge Sharing: Develop and maintain comprehensive SIEM documentation, including system architecture diagrams, data flow diagrams, log source configurations, alert rationale, and incident response procedures.
- SIEM Architecture & Strategy: Contribute to the long-term vision and roadmap for SIEM and threat detection capabilities. Identify gaps and opportunities for improvement in existing detection strategies and recommend solutions.
- Collaboration & Communication: Effectively communicate technical concepts to both technical and non-technical audiences. Interface with other IT teams (network, systems, application development, etc.) to ensure security is integrated throughout the infrastructure.
- Strategic Planning & Budgeting: Collaborate with leadership on strategic planning, budget forecasting, and resource allocation for SIEM-related initiatives.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- Minimum of 5-7 years of experience in information security, with a strong focus on SIEM administration, engineering, and security operations.
- Experience with Devo, Devo SOAR, and/or LogicHub
- Advanced programming/coding in one or more languages (C#, Python, etc).
- Understanding of security concepts, including network security, endpoint security, intrusion detection/prevention systems (IDS/IPS), firewalls, and vulnerability management.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.