SIEM/SOAR Engineer - Cloud Sec Spec 3
Job Description
Job DescriptionSIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Washington, DC
Work Authorization: US Citizen
Role Summary
The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
Roles & Responsibilities
· Configure ingestion pipelines and validate end‑to‑end log flow.
· Implement Google curated detections and build custom detection rules.
· Develop SOAR playbooks for SBA’s top incident categories.
· Integrate threat intelligence sources (Mandiant, Virus Total).
· Tune detections to meet false‑positive thresholds.
· Support UEBA dashboard configuration and risk scoring.
· Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
· 10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
· Experience building detection rules, automation workflows, and parser validation.
· Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
· Experience with threat intelligence integration.
Educational Qualification
· Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications
· Google SecOps, GIAC, CISSP, or equivalent preferred.