- Company Name
- The Intersect Group
- Job Title
- Cyber Security Engineer
- Job Description
-
Job Title: Cyber Security Engineer
Role Summary:
Designs, implements, and operates SIEM and SOAR platforms to protect critical healthcare applications and infrastructure. Performs incident detection, investigation, and response while maintaining system reliability and reducing false positives. Works cross‑functionally to align security operations with enterprise strategy and compliance frameworks.
Expectations:
- Maintain SIEM/SOAR platforms to meet security standards and availability requirements.
- Provide subject‑matter expertise and escalation support for incident response and platform issues.
- Deliver timely security gap reporting and strategic recommendations to leadership.
- Develop correlation rules, dashboards, and automation to improve detection accuracy.
- Support change management and deployment of security solutions.
- Communicate findings and training materials clearly to technical and non‑technical audiences.
Key Responsibilities:
1. Operate and support SIEM/SOAR environments, ensuring proper ingestion of logs from Linux, Windows, and cloud sources.
2. Troubleshoot and resolve platform incidents, perform root‑cause analysis, and implement restoration procedures.
3. Develop and tune correlation rules, dashboards, metrics, and reports aligned with MITRE ATT&CK, CIS, NIST, or equivalent frameworks.
4. Conduct investigations and forensic analysis during security incidents, providing recommendations for remediation.
5. Collaborate with security, governance, and IT teams to integrate new data sources and commercial security tools.
6. Manage access requests, security exceptions, and change requests in line with established procedures.
7. Participate in on‑call or after‑hours incident response as needed.
8. Produce documentation: incident reports, training materials, slide decks, and architecture diagrams.
9. Represent the organization in internal and external risk and information security groups.
Required Skills:
- SIEM design, configuration, and management.
- SOAR orchestration and automated playbook development.
- Intermediate Linux CLI and scripting (Python, PowerShell).
- Cloud log ingestion and monitoring of AWS, Azure, or GCP environments.
- Proficiency in MITRE ATT&CK, CIS Top 20, NIST SP 800‑53, or similar frameworks.
- Incident response, forensic analysis, and threat hunting.
- Risk assessment and mitigation techniques.
- Strong verbal and written communication; ability to interact across departments.
- Experience with vulnerability assessment and security monitoring tools.
- Ability to resolve problems independently and adhere to governance processes.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
- 4+ years IT experience, 3+ years focused on SIEM/SOAR.
- GIAC-GCED, GCDA, GDSA, GMON, or other recognized security certifications preferred.
Dallas-fort worth metroplex, United states
On site
Junior
18-09-2025