Work Arrangement: Hybrid – 3 days on-site per week
Duration: 18-month contract
Employment Type: W2 Only
***W2 ONLY NO SPONSORSHIP AVAILIBLE***
About the Role
We are seeking a Senior SIEM/SOAR Security Engineer to support critical enterprise security platforms in a production environment. This position requires strong expertise in SIEM/SOAR administration, Splunk, security operations, and production support.
The ideal candidate will serve as a technical SME while partnering with infrastructure, engineering, security, and application teams to maintain secure, reliable, and highly available platforms.
Key Responsibilities
- Provide production support for SIEM, SOAR, Splunk, and enterprise security platforms.
- Serve as a Splunk SME, developing and maintaining searches, dashboards, alerts, and playbooks.
- Troubleshoot critical production issues and restore services efficiently.
- Support security infrastructure initiatives, including platform design, planning, and implementation.
- Monitor system health and respond to security and production incidents.
- Perform root cause analysis and implement solutions to prevent recurring issues.
- Partner with infrastructure, security, engineering, and application teams.
- Participate in incident, change, and problem management processes.
- Support on-call responsibilities as needed.
- Ensure platforms and processes align with security, regulatory, and banking requirements.
Skills & Qualifications
- 5+ years of experience in SIEM/SOAR administration and security operations; 7+ years preferred.
- Strong hands-on Splunk experience in an enterprise production environment, including searches, dashboards, alerts, and playbooks.
- 10+ years of hands-on Identity & Access Management (IAM) experience.
- Strong knowledge of Windows and Red Hat Linux environments.
- Experience with SQL and/or Oracle databases.
- Strong PowerShell and/or Unix shell scripting skills.
- Proven experience in production support, troubleshooting, incident response, and root cause analysis.
- Working knowledge of ITIL processes and best practices.
- Experience working within regulated banking or financial services environments.
- Strong communication, collaboration, and problem-solving skills.
- Experience with cloud technologies, OpenShift, GitHub, Ansible, Jenkins, Dynatrace, JIRA, or Remedy/ITSM is a plus.
- Experience with Tower, BladeLogic, and network technologies is a plus.
- Knowledge of SRE/DevOps practices and cybersecurity operational controls is a plus.
- CISSP or comparable security certification is a plus.
- Ability to participate in on-call support.
- Ability to work onsite 3 days per week in Chandler, AZ or Charlotte, NC.