- Company Name
- O Partners
- Job Title
- Security Engineer
- Job Description
-
**Job Title:** Security Engineer
**Role Summary:**
Hands‑on security professional responsible for managing, tuning, and optimizing enterprise security tools (SIEM, EDR/XDR, vulnerability management) to enhance detection quality and automate response in a large, global environment. Works closely with Security Architecture and SOC teams to ensure defensive controls are effective against real‑world threats.
**Expectations:**
- Deliver robust, scalable security tooling solutions across cloud and on‑premise infrastructure.
- Continuously improve detection rules, alert fatigue, and automation workflows.
- Collaborate cross‑functionally with architecture, SOC, and IT operations.
- Maintain up‑to‑date knowledge of emerging threats and security technologies.
**Key Responsibilities:**
- Administer and fine‑tune SIEM, EDR/XDR, and vulnerability management platforms.
- Engineer detection logic, develop and refine alerting rules, and implement response automation (playbooks, scripts).
- Conduct regular tool performance reviews and optimization initiatives.
- Integrate security solutions with cloud services (AWS, Azure, GCP) and enterprise networks.
- Work with Security Architecture to align tooling with security frameworks and controls.
- Support SOC analysts with investigations, triage, and incident response.
- Produce documentation, reporting, and metrics on security tool efficacy.
**Required Skills:**
- 3‑7 years of security engineering experience in enterprise environments.
- Deep knowledge of SIEM (e.g., Splunk, QRadar, Elastic) and EDR/XDR solutions (e.g., CrowdStrike, SentinelOne, Microsoft Defender).
- Proficiency in detection engineering, alert tuning, and automation (Python, PowerShell, REST APIs).
- Experience with vulnerability management platforms (e.g., Tenable, Qualys, Rapid7).
- Strong understanding of cloud security concepts and services (IAM, CSPM, logging).
- Ability to analyze logs, network traffic, and threat intel to develop effective detections.
- Excellent problem‑solving, communication, and teamwork skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Preferred certifications: CISSP, CISM, GSEC, OSCP, or vendor‑specific certs (e.g., Splunk Core, CrowdStrike Falcon).