Everforth ECS is seeking a Senior Security Engineer to work remotely. The role involves supporting the engineering, implementation, and optimization of security technologies to enable effective enterprise security monitoring and incident response operations.
Responsibilities:
- Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies
- Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms
- Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives
- SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection
- Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times
- Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities
- Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment
- Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines
- Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations
- Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC
Requirements:
- Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree
- Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies
- Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms
- Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives
- Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection
- Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times
- Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities
- Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment
- Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines
- Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations
- Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC