
Cybersecurity Engineer II – SIEM, EDR
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
• Oversee the daily operational integrity of EDR and SIEM systems.
• Analyze standard activity baselines and reduce alerting noise.
• Refine security use cases to ensure high-fidelity alerts.
• Create tailored security use cases, log correlations, and detection rules.
• Utilize event data to enhance current security use cases and models.
• Design and set up dashboards for monitoring event trends and alerts.
• Configure reports for essential metrics and trends.
• Work in conjunction with external teams to integrate new SIEM data sources.
• Confirm the extraction, parsing, and formatting of event data.
• Develop custom field extractions utilizing RegEx.
• Diagnose and address issues during service interruptions.
• Set up antivirus exceptions and blocks.
• Keep service documentation updated.
• Configure and incorporate cybersecurity systems to mitigate risks.
• Address escalated incidents.
• Design, establish, configure, maintain, and monitor cybersecurity threat defense capabilities as well as user access management.
• Manage integration with managed security service providers.
• Investigate incidents and propose corrective measures.
• Minimum of 2 years of experience in cybersecurity.
• At least 1 year of experience specifically with SIEM or EDR platforms like Cortex XSIAM, Splunk, or CrowdStrike.
• Familiarity with networking infrastructure concepts, technologies, and protocols.
• Capability to identify gaps in logging, monitoring, and endpoint protection while recommending solutions.
• Ability to connect with both technical and non-technical stakeholders.
• Excellent interpersonal, teamwork, and communication skills.
• Security+ certification along with SIEM vendor certification, and EDR vendor certification, or equivalent credentials (preferred).
• Experience in Incident Response / SOC (preferred).
• Familiarity with cloud-based platforms such as Azure or GCP (preferred).
• Experience with Linux/Unix administration (preferred).
• Proficient in writing formal reports (preferred).
• Must be at least 18 years old.
• Must have legal authorization to work in the United States.
• Bachelor's degree or equivalent in a related field, or equivalent acquired knowledge, skills, and abilities.
• Capability to troubleshoot and resolve cybersecurity incidents.
• Ability to design, configure, maintain, monitor, and integrate cybersecurity systems.
• Remote/Virtual work arrangement.
• No travel required.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.