Security Engineer - SIEM (Splunk) Platform & Operations

Samsung SDS America Inc

  • San Jose, CA
  • 30+ days ago

    Highlights

    Responsibilities: Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats. Position Summary: As Security Engineer, youll join the Cybersecurity Operations team, where youll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace.

    Numbers & Facts

    LocationSan Jose, CA

    Description

    Samsung SDS America (SDSA) serves as the U.S. technology and innovation hub for Samsungs global enterprise solutions, delivering secure, scalable, and high-performance IT services that support some of the worlds most complex business environments. As SDSA continues to expand its cloud, mobility, analytics, and cybersecurity capabilities, maintaining a resilient security operations foundation is essential to protecting the companys digital assets and ensuring uninterrupted service delivery.

    Position Summary:

    As Security Engineer, youll join the Cybersecurity Operations team, where youll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace. Youll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high-fidelity alerts. Leveraging your experience SOC environments, youll lead deep incident investigations, spearhead proactive threat-hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: youll partner with global engineers, cloud specialists, and incident-response teams to continuously improve our security posture and document best-practice playbooks.

    Responsibilities:

    • Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats.
    • Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform.
    • Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards
    • Support the onboarding and integration of logs from enterprise systems into the Splunk environment.
    • Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure
    • Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification.
    • Conduct in-depth investigations of security incidents and recommend remediation and containment actions.
    • Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls.
    • Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives.
    • Prioritize remediation efforts based on risk, severity, and business impact.
    • Participate in incident response activities and support threat hunting initiatives as needed.
    • Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture.
    • Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards.

    Similar Jobs

    See more jobs