SIEM/SOAR Engineer - Cloud Sec Spec 3

Softthink Solutions Inc

SIEM/SOAR Engineer - Cloud Sec Spec 3

Washington, DC
Full Time
Paid
  • Responsibilities

    Job Title: SIEM/SOAR Engineer (Cloud Sec Spec 3) Location: Remote Work authorization: US Citizen

    Role Summary The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.

    Roles & Responsibilities • Configure ingestion pipelines and validate end to end log flow. • Implement Google curated detections and build custom detection rules. • Develop SOAR playbooks for SBA’s top incident categories. • Integrate threat intelligence sources (Mandiant, VirusTotal). • Tune detections to meet false positive thresholds. • Support UEBA dashboard configuration and risk scoring. • Assist with runbook creation, analyst training, and operational transition.

    Professional Experience Required • Must have public trust clearance • 5+ years of experience with SIEM/SOAR platforms (Google SecOps preferred). • Experience building detection rules, automation workflows, and parser validation. • Experience with cloud telemetry ingestion (Azure, AWS, on-prem). • Experience with threat intelligence integration.

    Educational Qualification • Bachelor’s degree in Cybersecurity, IT, or related field.

    Certifications • Google SecOps, GIAC, CISSP, or equivalent preferred.