SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Washington, DC
Work Authorization: US Citizen
Location: Washington, DC
Work Authorization: US Citizen
Role Summary
The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA鈥檚 enterprise security operations.
Roles & Responsibilities
路聽 聽 聽 聽 Configure ingestion pipelines and validate end鈥憈o鈥慹nd log flow.
路聽 聽 聽 聽 Implement Google curated detections and build custom detection rules.
路聽 聽 聽 聽 Develop SOAR playbooks for SBA鈥檚 top incident categories.
路聽 聽 聽 聽 Integrate threat intelligence sources (Mandiant, Virus Total).
路聽 聽 聽 聽 Tune detections to meet false鈥憄ositive thresholds.
路聽 聽 聽 聽 Support UEBA dashboard configuration and risk scoring.
路聽 聽 聽 聽 Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
路聽 聽 聽 聽 10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
路聽 聽 聽 聽 Experience building detection rules, automation workflows, and parser validation.
路聽 聽 聽 聽 Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
路聽 聽 聽 聽 Experience with threat intelligence integration.
Educational Qualification
路聽 聽 聽 聽 Bachelor鈥檚 degree in Cybersecurity, IT, or related field.
Certifications
路聽 聽 聽 聽 Google SecOps, GIAC, CISSP, or equivalent preferred.
Learn more about this Employer on their Career Site
