Cloud SIEM Engineer
Locations: Chicago, IL / Denver, CO / Washington, DC - 3X A WEEK ON-SITE
$80/hour on W2
W2 ONLY
Unable to work C2C
Join our team as a Cloud SIEM Engineer and play a crucial role in enhancing our security posture. We seek a dedicated professional passionate about security and innovation to help protect our assets from evolving cyber threats.
Key Qualifications:
- Cloud Experience: Proficient in AWS and/or Azure.
- Tools: Familiarity with WIZ for security posture management.
- SIEM Experience: Proficient in Splunk querying and tools like Microsoft Sentinel, IBM Qraded, Securonix, Exabeam Fusion, and LogRhythm SIEM. Experience with Anvilogic is a plus.
Responsibilities:
- Collaboration: Work as an Individual Contributor with a talented team to drive Detection Engineering in SIEM or SOAR within AWS environments, utilizing tools like AWS GuardDuty, CloudWatch, and SecurityHub.
- Development: Enhance SIEM and SOAR capabilities by coding, testing, and deploying custom applications. Integrate various data sources and security tools to improve threat detection and response.
- Incident Management: Develop strategies for proactive threat detection and efficient incident response. Analyze security incidents and collaborate with the Incident Response team to refine procedures.
- Performance Optimization: Monitor and optimize SIEM and SOAR systems, implementing upgrades to support growing data volumes and conducting load testing to ensure performance.