
SIEM/SOAR Engineer - Cloud Sec Spec 3
SoftThink Solutions Inc
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
- US persons only (ITAR / export control): a legal requirement, not employer policy.
Job description
SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Washington, DC
Work Authorization: US Citizen
Role Summary
The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
Roles & Responsibilities
-
Configure ingestion pipelines and validate end‑to‑end log flow.
-
Implement Google curated detections and build custom detection rules.
-
Develop SOAR playbooks for SBA’s top incident categories.
-
Integrate threat intelligence sources (Mandiant, Virus Total).
-
Tune detections to meet false‑positive thresholds.
-
Support UEBA dashboard configuration and risk scoring.
-
Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
-
10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
-
Experience building detection rules, automation workflows, and parser validation.
-
Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
-
Experience with threat intelligence integration.
Educational Qualification
- Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications
- Google SecOps, GIAC, CISSP, or equivalent preferred.