SoftThink Solutions Inc logo

SIEM/SOAR Engineer - Cloud Sec Spec 3

SoftThink Solutions Inc

On-siteWashington, DCsenior$94k–$114kPosted 3h ago

Visa & sponsorship

  • The posting says it will not sponsor a visa for this role.
  • US persons only (ITAR / export control): a legal requirement, not employer policy.

Job description

SIEM/SOAR Engineer (Cloud Sec Spec 3)

Location: Washington, DC

Work Authorization: US Citizen

Role Summary

The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.

Roles & Responsibilities

  • Configure ingestion pipelines and validate end‑to‑end log flow.

  • Implement Google curated detections and build custom detection rules.

  • Develop SOAR playbooks for SBA’s top incident categories.

  • Integrate threat intelligence sources (Mandiant, Virus Total).

  • Tune detections to meet false‑positive thresholds.

  • Support UEBA dashboard configuration and risk scoring.

  • Assist with runbook creation, analyst training, and operational transition.

Professional Experience Required

  • 10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).

  • Experience building detection rules, automation workflows, and parser validation.

  • Experience with cloud telemetry ingestion (Azure, AWS, on-prem).

  • Experience with threat intelligence integration.

Educational Qualification

  • Bachelor’s degree in Cybersecurity, IT, or related field.

Certifications

  • Google SecOps, GIAC, CISSP, or equivalent preferred.