Job Title: SIEM/SOAR Engineer (Cloud Sec Spec 3) Location: Remote Work authorization: US Citizen
Role Summary The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
Roles & Responsibilities • Configure ingestion pipelines and validate end to end log flow. • Implement Google curated detections and build custom detection rules. • Develop SOAR playbooks for SBA’s top incident categories. • Integrate threat intelligence sources (Mandiant, VirusTotal). • Tune detections to meet false positive thresholds. • Support UEBA dashboard configuration and risk scoring. • Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required • Must have public trust clearance • 5+ years of experience with SIEM/SOAR platforms (Google SecOps preferred). • Experience building detection rules, automation workflows, and parser validation. • Experience with cloud telemetry ingestion (Azure, AWS, on-prem). • Experience with threat intelligence integration.
Educational Qualification • Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications • Google SecOps, GIAC, CISSP, or equivalent preferred.