Overview
The Cyber Security Engineer supports the development and maintenance of a corporate-wide information security program to help protect the organization’s information assets. This role is responsible for the design, implementation, and continuous improvement of Security Information and Event Management infrastructure and data security capabilities. Key responsibilities include strengthening logging, monitoring, alerting, data protection, and compliance practices to support effective incident detection, response, forensic investigations, and risk management. The position partners closely with IT, compliance, and business teams to ensure security capabilities are reliable, scalable, and aligned with organizational and regulatory requirements.
Responsibilities
- SIEM Infrastructure & Operations
- Engineer, build, and maintain logging infrastructure to support SIEM and Security Operations teams.
- Monitor and manage SIEM performance, ensuring optimal data ingestion, correlation, and alerting.
- Tune and configure SIEM rules to reduce noise and improve detection accuracy.
- Security Monitoring & Incident Response
- Investigate security incidents and lead response efforts as applicable
- Monitor and analyze security logs and events from diverse sources (cloud, network, endpoint)
- Create technically detailed reports on SIEM Status, metrics, and incident trends.
- Data Security
- Familiarity with data classification, DLP, and governance solutions.
- Support data classification, labeling, and handling requirements.
- Assist with DLP policy tuning, monitoring, and alert triage.
- Support data discovery, sensitive data inventory, or DSPM-related activities.
- Partner with business and technology teams to improve data protection controls.
- Support data security metrics, reporting, and governance activities.
- Compliance & Governance
- Ensure SIEM logging standards meet regulatory and internal compliance requirements.
- Collaborate with IT Governance, Risk, and Compliance teams to define log retention, access controls, and masking/encryption policies.
- Collaboration & Enablement
- Work with application developers and system owners to ensure proper log generation and forwarding
- Assist internal teams and business partner in optimizing SIEM capabilities and workflows
Qualifications
- 5+ years of experience in security engineering, with a focus on SIEM platforms
- Experience with SIEM/DSPM/DLP and related security tools and technologies.
- Strong understanding of intrusion detection/prevention systems, firewalls, and endpoint protection.
- Hands-on experience with Linux OS
- Experience with scripting and automation to optimize SIEM workflows
- Certifications such as CISSP, CISM, CEH, or GIAC are preferred.
- Knowledge of network infrastructure, including routers, switches, firewalls and associated network protocols and concepts.
- Ability to interact with personnel at all levels and across all business units / organizations, and to understand business imperatives.
Additional Qualifications
- Proven trustworthiness and history of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating well.
- Analytical and problem-solving mindset.
- Highly organized and efficient
CompensationThe base pay range for this position is USD $115,000.00/Yr. - USD $160,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.