Job Title: SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Remote
Work authorization: US Citizen
Role Summary
The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
Roles & Responsibilities
• Configure ingestion pipelines and validate end to end log flow.
• Implement Google curated detections and build custom detection rules.
• Develop SOAR playbooks for SBA’s top incident categories.
• Integrate threat intelligence sources (Mandiant, VirusTotal).
• Tune detections to meet false positive thresholds.
• Support UEBA dashboard configuration and risk scoring.
• Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
• Must have public trust clearance
• 5+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
• Experience building detection rules, automation workflows, and parser validation.
• Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
• Experience with threat intelligence integration.
Educational Qualification
• Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications
• Google SecOps, GIAC, CISSP, or equivalent preferred.