Security Engineer

Ampcus, Inc

Tustin (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A global technology consulting firm in Tustin, CA, is seeking a Security Engineer to enhance their log management and detection strategies. The role involves collaborating with technical leads, developing ingestion strategies, and creating correlation rules to strengthen security. Candidates must possess extensive experience with SIEM technologies like Splunk and IBM QRadar, strong communication skills, and relevant qualifications. This position offers opportunities for professional growth and impact through innovation.

Qualifications

  • 6+ years of deploying and integrating SIEM solutions to large enterprises.
  • Experience with event collection, log management, and compliance automation using SIEM platforms.
  • Ability to tune log sources and create high-quality correlation rules.

Responsibilities

  • Work with technical lead to develop log ingestion strategy.
  • Contribute to detection strategy based on industry best practices.
  • Create technical documentation detailing SIEM aspects of the engagement.

Skills

Strong communication skills
Fluent English
SIEM integration experience
Ability to develop correlation rules
Knowledge of Security Analysis & Response

Education

Relevant bachelor's degree or industry recognized qualifications

Tools

Splunk
IBM QRadar

Job description

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Job Title:

Security Engineer

Location(s):

Tustin, CA

Job Description:

As a SIEM Engineer for Cortex XSIAM, you will be responsible for assisting with the log migration and detection strategy of our customers. You will work closely with the technical lead to ensure that all of the relevant log sources are on boarded and ingested into XSIAM in accordance with industry best practices and customer requirements. You will then work to determine a suitable detection strategy, helping to protect customers from threats, by designing and implementing correlation rules.

Your Impact
  • Work with technical lead to develop log ingestion strategy
  • Contribute to detection strategy based on industry best practices
  • Detail step by step process to ingest high quality log sources
  • Perform log source monitoring and optimization
  • Create high quality correlation rules
  • Tune log sources and correlation rules
  • Be an SME for SIEM, Correlation and Log Source Ingestion
  • Recognize opportunities where automation can improve analyst alert handling
  • Collaborate with internal and external teams to ensure product adoption
  • Create technical documentation detailing SIEM aspects of the engagement
  • Travel to customer meetings and workshops as needed (10%)
Your Experience
  • Strong communication (written and verbal) and presentation skills, both internally and externally
  • Fluent English is a requirement - Any other language is a plus
  • 6+ years of deploying and integrating (SIEM) to enterprise to large enterprise-level
  • Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms
  • The ability to create and develop correlation and detection rules, within a (SIEM) to support alerting capabilities
  • Experience working with and deploying a variety of SIEM technologies (i.e Splunk, IBM QRadar)
  • A proven ability to offer suggestions on detection strategy based on customer requirements
  • Ability to understand logs, locating and understanding 3rd party documentation where needed
  • Familiarity with reports on the status of the SIEM to include metrics on items such as number of logging sources - log collection rate, and other performance metrics
  • Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud based environments
  • 4 years' experience with Security Operation Centers tooling and processes
  • Relevant bachelor's degree or industry recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification etc)
  • Ability to read and understand technical design documentation

Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identify, national origin, age, protected veterans or individuals with disabilities.

Helping all candidates find great careers is our goal. The information you provide here is secure and confidential.

We are now directing you to the original job posting. Please apply directly for this job at the employer’s website.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Technical Lead
Security Technical Lead

Ampcus, Inc • Fort Mill (SC)

On-site
USD 120,000 - 160,000
XSIAM Engineer
XSIAM Engineer

Entelligence • United States

On-site
USD 80,000 - 100,000
Competitive base salary
Medical, dental, vision and life insurance
Vacation, sick time and paid holidays
+1
XSIAM Consultant - EMEA 2
XSIAM Consultant - EMEA 2

Entelligence • Germany (OH)

On-site
USD 80,000 - 120,000
Competitive base salary
Medical, dental, vision, and life insurance
Vacation, sick time, and paid holidays
+1
Detection Engineer
Detection Engineer

Ampcus, Inc • Jacksonville (FL)

On-site
Senior Cyber Security Engineer
Senior Cyber Security Engineer

CSC • Wilmington (DE)

Hybrid
USD 100,000 - 130,000
Annual leave
Tuition reimbursement
Referral bonuses
+1
XSIAM Engineer
XSIAM Engineer

Entelligence • Virginia (MN)

On-site
USD 90,000 - 120,000
Competitive base salary
Medical, dental, vision, and life insurance
Vacation, sick time, and paid holidays
+1
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Ampcus, Inc • Richmond (VA)

On-site
USD 120,000 - 160,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Visa Hunt • United States

Hybrid
USD 120,000 - 180,000
Security Engineer
Security Engineer

Ampcus, Inc • California (MO)

Hybrid
USD 110,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Ampcus Inc • Richmond (VA)

On-site
USD 110,000 - 160,000