Unknown Company

Security Information and Event Management (SIEM) Integration Engineer

washington, dc • Posted 1 weeks ago
Onsite Full Time General

Security Information and Event Management (SIEM) Integration EngineerSecurity Information and Event Management (SIEM) Integration Engineer will focus on implementation of the McAfee SIEM and associated appliances (Enterprise Security Manager (ESM), Enterprise Log Manager (ELM), Advanced Correlation Engine (ACE)).The Security Information and Event Management (SIEM) Integration Engineer will possess deep technical knowledge on a number of security technologies; the main area of focus will be the District implementation of the McAfee SIEM and associated appliances (to include Enterprise Security Manager (ESM), Enterprise Log Manager (ELM), Advanced Correlation Engine (ACE)). The ideal candidate will have a demonstrated understanding of information security and networking and extensive experience interacting with customer.Specific TasksAct as the lead for Operations and Maintenance and Configuration Management for all Security Operations Center (SOC) and Security Information and Event Management (SIEM) tools.Analysis, design, configuration, implementation, documentation and operation of McAfee SIEM and associated appliances (to include Enterprise Security Manager (ESM), Enterprise Log Manager (ELM), Advanced Correlation Engine (ACE)).Responsible for SIEM security design review and recommendations, technical data gathering, security and policy review and configuration, security device implementation planning, configuration and implementation of security products and technical quality assurance.Lead technical troubleshooting efforts for complex network environments to identify and eliminate network or security configuration issues for SIEM data collection.Manage system deployments, upgrades, ongoing maintenance and operations.Configuration and operation of security device authentication, management & logging platforms.Provide Tier3 support to SOC Analyst personnel utilizing the SIEM to respond to security incidents and events.Identify, troubleshoot, and resolve complex network connectivity issues as well as advise on network security related issues.Understanding of network and endpoint security tools and how they integrate into the SIEM and provide a cohesive view of network incidents and security.Configure backups, verify custom reports, manage log source groups and validate log sources.Provide occasional off-hours support for planned maintenance work and unplanned support issues. May occasionally require on-site work at a data center during off-hours.Required Qualification and skillsBachelor of Science in Electrical Engineering, Computer Science, Information Technology, or equivalent data security and networking experience requiredCISSP, CISM, or relevant IPS Vendor training/certification preferredProfessional certifications related to core expertise (McAfee preferred)Minimum 5 years McAfee ESM administration experience requiredMinimum 5 years' experience as a SOC Analyst Level 2 or SOC Team LeadMinimum 3 years' experience scripting in regular expression for SIEM signaturesServer Administration background – Windows and/or Linux/UnixSkills Required:Bachelor of Science in Electrical Engineering, Computer Science, Information Technology, or equivalent data security and networking experienceISC^2 Related Certification (CISSP, CISM) OR relevant Intrusion Prevention System Vendor training/certification (McAfee)McAfee ESM administrationExperience as a SOC Analyst Level 2 or SOC Team LeadExperience scripting in regular expression for SIEM signaturesServer Administration background – Windows and/or Linux/UnixExperience in network/system level administration and or cybersecurity16+ yrs planning, coordinating, and monitoring project activities16+ yrs leading projects, ensuring they are in compliance with established standards/procedures

Back to Job Search