Lead, Info Security Systems

Newell BrandsAtlanta, GA
$108,000 - $138,600Remote

About The Position

The Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. This role owns the full lifecycle of detection engineering – from ingestion and correlation through automated response – and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.

Requirements

  • 5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment and detection rule development
  • 3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case management
  • Demonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent)
  • Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technology
  • Proficiency in at least one scripting or query language such as Python or Powershell
  • Expert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratch
  • Working knowledge of MITRE ATT&CK framework and application to detection use case development
  • Experience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIs
  • Strong written communication: ability to document technical logic, playbooks, and runbooks to an operational standard
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience

Nice To Haves

  • Experience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environment
  • Exposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflows
  • Familiarity with non-human identity (NHI) monitoring and agentic risk controls
  • Experience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposure
  • Certifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalent
  • Familiarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deployments

Responsibilities

  • Own SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mapping
  • Serve as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experience
  • Manage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillment
  • Serve as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes and processing pipelines across cloud and on-premises worker groups
  • Lead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources
  • Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositories
  • Build and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platforms
  • Develop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumers
  • Continuously measure and report detection coverage gaps and use-case performance (false positive rate)
  • Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycle
  • Develop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response path
  • Integrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feeds
  • Document all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineer
  • Define and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distribution
  • Lead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generation
  • Evaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance framework
  • Partner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirements
  • Own MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership
  • Support incident response by providing platform-level investigation capability and post-incident forensic log review
  • Participate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputs

Benefits

  • The Remote base pay range for this position is from $108,000 to $138,600. Salary will be based on prior experience related to the skills required for this position.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service