Source description
About the role
Responsibilities Define overall NG SIEM and SOAR strategy, roadmap, and architecture. Govern onboarding, ingestion structures, and quality standards using Cribl, cloudnative pipelines, and routing rules. Establish Fusion correlation strategypriority rule sets, enrichment patterns, MITRE coverage, noise control. Lead the enterprise Case Management program (workflow, SLA, severity model, automation). Own SOAR strategyautomation roadmap, playbook standards, orchestration framework, KPIs. Partner with IR, Threat Hunting, CTI, Cloud Security, and Network teams to design multilayer detection logic. Review and approve critical detection content, correlation logic, and data models. Oversee ingestion performance, retention, licensing, and cost optimization. Manage a team of Staff, Senior Engineers, and Automation Engineers. Present metrics and maturity dashboards to leadership: ingestion health correlation performance case SLA adherence automation success rate. Drive continuous improvement, runbooks, SOPs, and audit readiness. Experience or exposure to AIpowered SOC features such as Charlotte AI, Sentinel Copilot. Ability to leverage AI assistants for query generation (SPL/KQL/CQL), alert summarization, detection tuning, and workflow optimization. Familiarity with exploring AI capabilities in SOAR platforms (Fusion, Sentinel, Splunk SOAR) to automate enrichment, case resolution, and noise reduction. Requirements 7+ years in SIEM/SOAR, detection engineering, or security analytics. Expertise in Fusion-like correlation engines, case management frameworks, and SOAR automation. Strong background in security architecture, data modeling, and crossplatform integrations. Experience managing teams and multistakeholder programs. Deep handson knowledge of Cribl, cloudnative pipelines, Falcon NGSIEM, Sentinel, ADX, Splunk, LogScale. Strong communication and executive presentation skills. Responsibilities Define overall NG SIEM and SOAR strategy, roadmap, and architecture. Govern onboarding, ingestion structures, and quality standards using Cribl, cloudnative pipelines, and routing rules. Establish Fusion correlation strategypriority rule sets, enrichment patterns, MITRE coverage, noise control. Lead the enterprise Case Management program (workflow, SLA, severity model, automation). Own SOAR strategyautomation roadmap, playbook standards, orchestration framework, KPIs. Partner with IR, Threat Hunting, CTI, Cloud Security, and Network teams to design multilayer detection logic. Review and approve critical detection content, correlation logic, and data models. Oversee ingestion performance, retention, licensing, and cost optimization. Manage a team of Staff, Senior Engineers, and Automation Engineers. Present metrics and maturity dashboards to leadership: ingestion health correlation performance case SLA adherence automation success rate. Drive continuous improvement, runbooks, SOPs, and audit readiness. Experience or exposure to AIpowered SOC features such as Charlotte AI, Sentinel Copilot. Ability to leverage AI assistants for query generation (SPL/KQL/CQL), alert summarization, detection tuning, and workflow optimization. Familiarity with exploring AI capabilities in SOAR platforms (Fusion, Sentinel, Splunk SOAR) to automate enrichment, case resolution, and noise reduction. Requirements 7+ years in SIEM/SOAR, detection engineering, or security analytics. Expertise in Fusion-like correlation engines, case management frameworks, and SOAR automation. Strong background in security architecture, data modeling, and crossplatform integrations. Experience managing teams and multistakeholder programs. Deep handson knowledge of Cribl, cloudnative pipelines, Falcon NGSIEM, Sentinel, ADX, Splunk, LogScale. Strong communication and executive presentation skills.
More at Jobtailor