We are seeking an experienced Cybersecurity Engineer with expertise in SIEM administration, observability platforms, endpoint security, and threat detection. The ideal candidate will have hands-on experience managing enterprise security tools, analyzing security events, supporting incident response, and optimizing data pipelines for security operations.
Key Responsibilities
- Administer and maintain Elastic Search or a comparable search and analytics platform.
- Configure, manage, and optimize Cribl observability and data pipeline solutions or similar technologies.
- Monitor, investigate, and respond to security alerts generated by XDR, SIEM, and endpoint security platforms.
- Analyze malware, phishing emails, and suspicious files using sandbox environments and threat analysis tools.
- Support endpoint security and data protection initiatives using modern endpoint detection and response (EDR/XDR) technologies.
- Develop and optimize ES|QL or equivalent queries for data filtering, threat hunting, and security investigations.
- Implement and maintain API integrations for telemetry collection and data sharing between security platforms.
- Collaborate with security operations teams to improve detection capabilities and incident response processes.
- Document configurations, procedures, and security recommendations.
Required Qualifications
- Minimum 3 years of recent experience administering Elastic Search or a comparable enterprise search platform.
- Minimum 2 years of recent experience managing Cribl observability and data pipeline solutions or similar technologies.
- Minimum 4 years of experience in malware analysis, threat intelligence, sandbox analysis, or related cybersecurity functions.
- Minimum 2 years of experience developing API integrations for telemetry collection and data exchange.
- Minimum 2 years of experience creating and optimizing ES|QL or similar queries for data analysis.
Preferred Technical Skills
- Elastic Search administration
- Cribl administration
- Endpoint Detection and Response (EDR/XDR)
- Security Information and Event Management (SIEM)
- Threat Hunting
- Malware Analysis
- Phishing Investigation
- API Integrations
- Security Monitoring
- Email Security Solutions
- Endpoint Security Technologies
Preferred Experience
Experience with one or more of the following technologies is highly desirable:
- CrowdStrike Falcon (Endpoint Security, SaaS Security, Next-Gen SIEM)
- SecureWorks or comparable XDR platforms
- Proofpoint Email Security
- Abnormal Security or comparable email security solutions
Education & Certifications
- Cribl Certified User (CC User) certification preferred.
- Relevant cybersecurity certifications are a plus.