Job Title: Cloud SIEM Engineer
Location: Chicago, IL / Denver, CO / Washington, DC – 3x a week hybrid
Job Type: W2 Contract
Duration: 18+ months – potential to convert full time
Must Have:
CSPM - cloud security posture mgmt
DSPM - data sec posture mgmt
SIEM - security event mgmt
Join our dynamic team and make a significant impact on our organization's security posture as our Cloud SIEM Engineer. If you are a dedicated and forward-thinking professional with a passion for security and innovation, we invite you to apply and contribute to our mission of safeguarding our valuable assets and data from evolving cyber threats.
Top 3 requirements:
- Cloud experience - AWS and/or Azure
- WIZ - tool; security posture tool (setting the right permissions in the cloud looks and finds vulnerabilities ) - someone with exp setting this up
- Splunk querying experience - Microsoft sentinal, Splunk ES, IBM Qraded, Securonix, Exabeam Fusion, LogRhythm SIEM (competitors)
- Huge plus: Anvilogic - moving this way, need it implemented in the bank by End of Q1 (someone with this experience is ideal)
Key Qualifications:
- Cloud Experience: Proficient in AWS and/or Azure.
- Tools: Familiarity with WIZ for security posture management.
- SIEM Experience: Proficient in Splunk querying and tools like Microsoft Sentinel, IBM Qraded, Securonix, Exabeam Fusion, and LogRhythm SIEM. Experience with Anvilogic is a plus.
Responsibilities:
- Collaboration: Work as an Individual Contributor with a talented team to drive Detection Engineering in SIEM or SOAR within AWS environments, utilizing tools like AWS GuardDuty, CloudWatch, and SecurityHub.
- Development: Enhance SIEM and SOAR capabilities by coding, testing, and deploying custom applications. Integrate various data sources and security tools to improve threat detection and response.
- Incident Management: Develop strategies for proactive threat detection and efficient incident response. Analyze security incidents and collaborate with the Incident Response team to refine procedures.
- Performance Optimization: Monitor and optimize SIEM and SOAR systems, implementing upgrades to support growing data volumes and conducting load testing to ensure performance.