SIEM/SOAR Engineer - Cloud Sec Spec 3

Softthink Solutions

  • Washington, District of Columbia
  • 8 days ago

    Highlights

    Role Summary The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations. In an industry that’s constantly reinventing itself, STSI challenges its team members and consultants with engagements that involve specialized services and advanced IT solutions – applying agile development principles, methodical planning, creative thinking, and continuous learning.

    Numbers & Facts

    LocationWashington, District of Columbia
    Websitewww.softthink.com

    Description

    SIEM/SOAR Engineer (Cloud Sec Spec 3)
    Location: Washington, DC
    Work Authorization: US Citizen


    Role Summary
    The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
    Roles & Responsibilities
    ·        Configure ingestion pipelines and validate end‑to‑end log flow.
    ·        Implement Google curated detections and build custom detection rules.
    ·        Develop SOAR playbooks for SBA’s top incident categories.
    ·        Integrate threat intelligence sources (Mandiant, Virus Total).
    ·        Tune detections to meet false‑positive thresholds.
    ·        Support UEBA dashboard configuration and risk scoring.
    ·        Assist with runbook creation, analyst training, and operational transition.
    Professional Experience Required
    ·        10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
    ·        Experience building detection rules, automation workflows, and parser validation.
    ·        Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
    ·        Experience with threat intelligence integration.
    Educational Qualification
    ·        Bachelor’s degree in Cybersecurity, IT, or related field.
    Certifications
    ·        Google SecOps, GIAC, CISSP, or equivalent preferred.
    Compensation: $45.00 - $55.00 per hour




    Similar Jobs

    See more jobs