Senior Security Operations Engineer
Resilience
This job is no longer accepting applications
See open jobs at Resilience.See open jobs similar to "Senior Security Operations Engineer" General Catalyst.Operations
New York, NY, USA
Responsibilities:
- Develop dashboards, automations, and SOAR playbooks to triage security alerts.
- Serve as a system owner and subject matter expert for the SIEM.
- Manage the ingestion of appropriate logging into the SIEM.
- Participate in the alert review process to identify tuning and automation opportunities.
- Refine inbound and outbound logging and tasking workflows with teams such as IT, DevOps, Threat Intelligence, Risk Operations Center, and Business Operations.
- Maintain written documentation for security logging ingest and automation which can be communicated and shared with partner teams that need to implement them.
- Participate in security architecture and integration reviews, as required.
- Participate in security investigations when required.
- Integrate security and business intelligence tools into detection, response, and GRC workflows and tooling.
Qualifications:
- A desire and ability to work in a highly skilled, cross-functional, and growing team, including learning new technologies where required.
- Bachelor's degree or higher, or equivalent work experience of 5-10 years.
- Intermediate or better knowledge of scripting languages like Python and Bash as it relates to automation and knowledge of log formats, parsing, and collection.
- Experience maintaining or being a power user of a SIEM. Experience with SumoLogic is preferred but other leading platforms are a plus.
- Strong writing and communications skills to both business and technical stakeholders.
- Experience with Endpoint Detection and Response (EDR) such as Crowdstrike.
- Experience with Amazon Web Services and other public clouds.
- Experience securely integrating systems via APIs via both “off-the-shelf” integrations exist and writing custom ones when required.
- Experience with SOAR playbook development is highly desirable.
- A desire and ability to work in a highly skilled, cross-functional, and growing team, including learning new technologies where required.
- Experience working in a Security Operations Center (SOC) is highly desirable.
- Certifications relevant to Security Operations, Automation, and Digital Forensics are desirable but not required. Ex. GPYC, GCFR, GEIR, AWS Certified Security - Specialty.
This job is no longer accepting applications
See open jobs at Resilience.See open jobs similar to "Senior Security Operations Engineer" General Catalyst.