Threat Detection Engineer / SIEM Administrator
hace 10 horas
Long Beach
STAND 8 provides end to end IT solutions to enterprise partners across the United States and with offices in Los Angeles, New York, New Jersey, Atlanta, and more including internationally in Mexico and India. We are seeking a highly skilled Threat Detection Engineer / SIEM Administrator to join our Cyber Operations Team. In this role, you will operate and enhance the organization's analytics and detection infrastructure, ensuring strong threat monitoring, alerting, and incident response capabilities. You will serve as the subject matter expert for SIEM design, deployment, and maintenance-building scalable systems with a high signal-to-noise ratio that empower effective threat detection. This position requires deep technical expertise in SIEM engineering, an analytical mindset, and experience with Tier 2+ incident response. Responsibilities • SIEM Engineering & Administration, • Design, engineer, and maintain large-scale, distributed cybersecurity systems., • Aggregate, normalize, and enrich log and event data from multiple sensor sources., • Develop, test, and optimize new detection rules, correlation logic, and heuristic models., • Build dashboards, search filters, and monitoring tools to support threat detection., • Tune data pipelines, event logic, and alert thresholds to improve accuracy., • Optimize data warehouse performance and ingestion workflows., • Integrate diverse cyber threat intelligence feeds into the SIEM., • Threat Detection & Analysis, • Curate and integrate high-value observables from network and host sensors., • Evaluate data sources for relevance and utility in threat detection and incident analysis., • Support Tier 2 incident analysis, investigation, and remediation when needed., • Advanced Competencies (at least one required), • Network/system forensics & intrusion analysis, • Incident timeline reconstruction & root cause analysis, • PCAP analysis, • Malware analysis or reverse engineering, • Advanced scripting & automation, • Network penetration testing, • Strong self-motivation, ownership of responsibilities, and organizational discipline., • Excellent communication skills and the ability to collaborate across teams., • Experience gathering data requirements across multiple organizational boundaries., • Ability to analyze business processes, data flows, host systems, and applications., • Strong analytical problem-solving skills with high attention to detail., • Ability to manage multiple assignments and work effectively in dynamic environments., • Bachelor's degree in Computer Science, Information Systems, or related field (Master's preferred)., • 4+ years of hands-on experience in:SIEM administration,Threat hunting,Security engineering, Network security., • At least one relevant certification: Certified SIEM Integrator/Administrator (various SIEM technologies), Certified Ethical Hacker (CEH) ,CompTIA Security+, PenTest+, or CySA+, • Strong experience developing SIEM rules, queries, dashboards, filters, and reports., • Deep knowledge of log formats, event sources, and SIEM ingestion pipelines., • Skilled in troubleshooting and resolving SIEM integration and performance issues., • Understanding of common protocols: DHCP, LDAP, SNMP, SMTP, HTTP, SSL., • Knowledge of networking devices and security tools (routers, switches, firewalls, web filters)., • Strong understanding of industry-standard security concepts and practices., • Work with cutting-edge detection technologies and security platforms., • Collaborate with highly skilled cybersecurity professionals., • Play a critical role in strengthening enterprise-wide security posture., • Medical coverage and Health Savings Account (HSA) through Anthem, • Dental/Vision/Various Ancillary coverages through Unum, • 401(k) retirement savings plan, • Paid-time-off options, • Company-paid Employee Assistance Program (EAP)