Cybersecurity SIEM Engineer

Edgewater Federal Solutions, Inc.Golden, CO
2hHybrid

About The Position

Edgewater Federal Solutions is seeking a Cybersecurity SIEM Engineer to support our team in Golden, CO. The Cybersecurity SIEM (Security Information Event Management) Engineer administers and tunes the technology required to detect and analyze cybersecurity threats for maximum value and effectiveness. The ideal candidate is a self-starter and strong collaborator with multiple years’ experience installing and maintaining SIEMs and related components such as log aggregators and forwarders. Prior experience and/or familiarity with cybersecurity testing, incident response, or analysis is a plus. This position is located on NLR's Golden, CO campus or remote.

Requirements

  • Related Bachelor's Degree and 5 or more years of experience. Or, related Master's Degree and 3 or more years of experience. Or, equivalent related education or experience.
  • Ability to perform research, read documentation, and independently learn new skills.
  • Must be a self-starter
  • Ability to work both alone and as part of a collaborative team
  • Demonstrated skills in critical thinking and problem solving
  • Excellent written and verbal communication skills, including active listening, ability to prepare and deliver presentations, and clear written correspondence and documentation
  • HSPD-12 compliant credential required.

Nice To Haves

  • Experience includes at least 3 years in an Information Technology role working specifically in a SIEM engineering role, or a role that includes significant time performing SIEM engineering (tool selection, installation, and maintenance)
  • One or more professional security and/or systems engineering certifications, such as GIAC (SANS) certifications, Security+, CISSP, or training evidencing effort to attain future certification
  • Technical background in multiple disciplines, including experience with: Windows and Linux server and workstation system administration; TCP/IP networking concepts, Bash command-line expertise, network protocols and architecture; security measures/defense-in-depth
  • Experience managing, and troubleshooting tools and significant infrastructure in a production (live) environment
  • Experience dealing with common cyber security concepts and threats and describing them to others
  • Intermediate scripting/programming ability with various languages, preferably Python, in support of security orchestration and automation
  • Technology-specific experience or training/certifications with Splunk SIEM and Cribl is a plus
  • Understanding of cloud security architecture(AWS/Azure/Google Cloud), event collection and aggregation a plus

Responsibilities

  • Operates and maintains SIEM tools and components, such as log aggregators, forwarders, and data observability systems
  • Tests, implements, and tunes new on-premises and cloud-based technical environments that support infrastructure visibility, analysis, automation, and secure data retention.
  • Develops content that enables cybersecurity personnel to take maximum advantage of existing tool capabilities, including workflows, integrations, and automated tasks.
  • Collaborates across Information Technology Services teams to integrate SIEM components with cybersecurity enrichment and analysis platforms and system management tools.
  • Creates and maintains architectural documentation and operational procedures that describe the scope, purpose, configuration, use, and maintenance of the SIEM tools and environments
  • Contributes to projects (as assigned or independently) that improve the effectiveness and efficiency of NLR’s cybersecurity program, including but not limited to workflow improvements, automation expansion, management tool enhancements, program or NLR strategic initiatives, and user awareness training
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service