SIEM Engineer
Remote
Job Id:
132594
Job Category:
Job Location:
Remote
Security Clearance:
None
Business Unit:
Piper Companies
Division:
Piper Enterprise Solutions
Position Owner:
Devan Rook
Piper Companies is seeking a SIEM Engineer to join a fast growing, highly reputable cyber security company with 100% remote work. The SIEM Engineer will work closely with the technical lead to ensure that all the relevant log sources are onboarded and ingested into XSIAM in accordance with industry best practices.
Responsibilities of the SIEM Engineer will include:
• Work with technical lead to develop log ingestion strategy
• Contribute to detection strategy based on industry best practices
• Detail step by step process to ingest high quality log sources
• Perform log source monitoring and optimization
• Create high quality correlation rules
• Tune log sources and correlation rules
• Be an SME for SIEM, Correlation and Log Source Ingestion
• Recognize opportunities where automation can improve analyst alert handling
• Create technical documentation detailing SIEM aspects of the engagement
Qualifications for the SIEM Engineer include:
• 4 years’ experience with Security Operation Centers tooling and processes
• Relevant bachelor's degree or industry recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification etc)
• 6+ years of deploying and integrating (SIEM) to enterprise to large enterprise-level
• Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms
• The ability to create and develop correlation and detection rules, within a (SIEM) to support alerting capabilities
• Experience working with and deploying a variety of SIEM technologies (i.e Splunk, IBM QRadar)
• A proven ability to offer suggestions on detection strategy based on customer requirements
• Ability to understand logs, locating and understanding 3rd party documentation where needed
• Familiarity with reports on the status of the SIEM to include metrics on items such as number of logging sources - log collection rate, and other performance metrics
• Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud-based environments
Compensation for the SIEM Engineer include:
• Salary Range: $120,000 - $130,000 | $58.00hr -$64.00hr **depending on experience**
• Comprehensive Benefits: Medical, Dental, Vision, 401K, PTO, Sick Leave as required by law, and Holidays
This job opens for applications on 12/19/24. Applications for this job will be accepted for at least 30 days from the posting date.
Keywords: #LI-DR1 #LI-REMOTE
Cybersecurity, coding, wfh, work from home, remote, python, terraform, infrastructure as code, IAAC, SIEM, Security incident and event management, engineer, AWS, Azure, GCP, splunk, sentinel, chronicle, google chronicle, ELK, security operations, SEC opps, SOC, security operations center, incident response, playbooks, clouds, cloud, log, forensics, log management, SAAS, amazon web services, google cloud provider, customer facing, customer support, customer service, consult, advise, xsoar, python, linux