Job ID: 16337 Alternate Locations: Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco, Coleman, Oster, Rubbermaid, Sharpie and Yankee Candle - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact—supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day.Position Title: Senior CyberSecurity Specialist - Engineer (SIEM/SOAR)Location: RemoteReports To: Senior Manager, Security EngineeringCompany OverviewNewell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Paper Mate, Sharpie, Dymo, EXPO, Parker, Elmer’s, Coleman, Marmot, Oster, Sunbeam, FoodSaver, Mr.
Coffee, Rubbermaid Commercial Products, Graco, Baby Jogger, NUK, Calphalon, Contigo, Mapa, Spontex and Yankee Candle. Newell Brands is committed to enhancing the lives of consumers around the world with planet friendly, innovative, and attractive products that create moments of joy and provide peace of mind.Job SummaryThe Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. This role owns the full lifecycle of detection engineering – from ingestion and correlation through automated response – and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.Key ResponsibilitiesOwn SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mappingServe as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experienceManage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillmentServe as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes and processing pipelines across cloud and on-premises worker groupsLead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositoriesBuild and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platformsDevelop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumersContinuously measure and report detection coverage gaps and use-case performance (false positive rate)Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycleDevelop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response pathIntegrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feedsDocument all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineerDefine and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distributionLead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generationEvaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance frameworkPartner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirementsOwn MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership Support incident response by providing platform-level investigation capability and post-incident forensic log reviewParticipate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputsRequired Qualifications5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment and detection rule development3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case managementDemonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent)Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technologyProficiency in at least one scripting or query language such as Python or PowershellExpert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratchWorking knowledge of MITRE ATT&CK framework and application to detection use case developmentExperience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIsStrong written communication: ability to document technical logic, playbooks, and runbooks to an operational standardBachelor's degree in Computer Science, Information Security, or equivalent practical experiencePreferred QualificationsExperience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environmentExposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflowsFamiliarity with non-human identity (NHI) monitoring and agentic risk controlsExperience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposureCertifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalentFamiliarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deploymentsThe Remote base pay range for this position is from $108,000 to $138,600.
Salary will be based on prior experience related to the skills required for this position.Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer’s, Oster, NUK, Spontex and Campingaz. We are focused on delighting consumers by lighting up everyday moments. Newell Brands and its subsidiaries are Equal Opportunity Employers and comply with applicable employment laws.
EOE/M/F/Vet/Disabled are encouraged to apply.
Lead, Info Security Systems in atlanta at Unknown Company
This position is listed as contract and able to be worked remotely.