What are the responsibilities and job description for the SIEM ENGINEER/SOAR SME position at NorthHill Technology?
NorthHill Technology Resources has an immediate need for a SIEM Engineer/SOAR SME to support a Federal Program in Leesburg, VA. This is a direct-hire role with our client, a fast-growing Federal Integrator. It is hybrid, 3 days onsite in Leesburg and 2 days remote. US Citizenship and an active Secret Clearance are required/
SIEM Engineer – SOAR SME
Our client seeking a SIEM Engineer/SOAR SME opportunity in Leesburg, VA. This is a hybrid opportunity requiring three days onsite but allowing for two days remote.
The ideal candidate will have experience working in a network security environment, such as a Security Operations Center (SOC), Computer Emergency Response Team (CERT), Computer Incident Response Team (CIRT), Computer Incident Response Center (CIRC) or Cyber Security Incident Response Center (CSIRC). All applicants must have a Secret or higher clearance.
Job Description
- Provide SIEM engineering efforts and provide direct support to SOC operations.
- Serve as the lead for all Security Orchestration, Automation, Response (SOAR) activities within the SOC.
- SOAR activities include:
- Demonstrate SOAR capabilities via SIEM and ticketing system.
- Demonstrate SOAR capabilities via SIEM and remediation activities.
- Demonstrate areas where the application of SOAR will provide immediate return on investment.
- Implement solutions to enable or improve SOAR capabilities.
- Must be able to demonstrate integration and automation capabilities.
- Ensure availability of the SIEM and provide administrative oversight of the tool.
- Responsible for the implementation, operations, maintenance, and lifecycle management of the SIEM tool
- Revise and develop processes to strengthen the current operational activities; review policies and recommend changes to improve tool usage and governance.
- Coordinate with stakeholders to build and maintain positive working relationships.
- Excellent analytical and communicative skills along with collaborative, teaming, and interpersonal skills
Minimum Requirements
- Minimum seven (7) years of experience in the role of SIEM/SOAR Content Development
- Splunk experience.
- BS Degree or higher degree
- Active Secret or higher clearance
- Python scripting experience desired