SIEM/SOAR Engineer - Cloud Sec Spec 3

Softthink Solutions Inc

  • Washington, DC
  • 16 days ago
  • Remote
  • Full-time

Highlights

The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations. • Experience building detection rules, automation workflows, and parser validation.

Numbers & Facts

LocationWashington, DC (
Remote
)
Job TypeFull-time

Description

Job Title: SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Remote
Work authorization: US Citizen

Role Summary

The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.

Roles & Responsibilities
• Configure ingestion pipelines and validate end to end log flow.
• Implement Google curated detections and build custom detection rules.
• Develop SOAR playbooks for SBA’s top incident categories.
• Integrate threat intelligence sources (Mandiant, VirusTotal).
• Tune detections to meet false positive thresholds.
• Support UEBA dashboard configuration and risk scoring.
• Assist with runbook creation, analyst training, and operational transition.

Professional Experience Required
Must have public trust clearance
• 5+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
• Experience building detection rules, automation workflows, and parser validation.
• Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
• Experience with threat intelligence integration.

Educational Qualification
• Bachelor’s degree in Cybersecurity, IT, or related field.

Certifications
• Google SecOps, GIAC, CISSP, or equivalent preferred.

Similar Jobs

See more jobs