SIEM/SOAR Engineer

BreakPoint Labs LLC

Charleston, Northern (SC, KY)

Hybrid

USD 90,000 - 130,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BreakPoint Labs LLC is seeking a SIEM/SOAR Engineer to manage and maintain the CSSP’s SIEM and SOAR platforms, including Elastic and Splunk. The role focuses on reliability, performance, and security of enterprise systems and data ingestion pipelines.

Requirements include 3+ years managing Elastic clusters, Elasticsearch Enterprise (Logstash/Kibana), DoD 8570 IAT Level II, CSSP Auditor compliance, and strong Python/PowerShell scripting. RHEL Linux expertise and team collaboration are essential.

Qualifications

  • Minimum of 3 years maintaining an enterprise Elastic cluster.
  • Experience with Elasticsearch Enterprise (Logstash/Kibana) for SIEM operations.
  • DoD 8570 IAT Level II and CSSP Auditor compliant certification.
  • Bachelor’s Degree in related field.
  • Strong scripting in Python or PowerShell for automation.
  • Experience with threat detection and incident response processes.
  • Extensive Linux (RHEL) administration experience.
  • Ability to collaborate in a team and on-call rotation.

Responsibilities

  • Design, implement, and maintain SIEM and SOAR infrastructure (Elastic and Splunk).
  • Manage enterprise Elastic cluster to support CSSP SIEM operations.
  • Monitor and analyze security events to protect assets.
  • Develop and maintain use cases, rules, and alerts for threat detection.
  • Integrate SIEM/SOAR with other security tools and data sources.
  • Automate security workflows and incident response using SOAR platforms.
  • Perform health checks, tuning, and capacity planning for SIEM/SOAR.
  • Manage data ingestion pipelines for security events.
  • Update, patch, and upgrade SIEM/SOAR systems regularly.
  • Create documentation for configurations and SOPs.
  • Collaborate with analysts and other CSSP teams on tool usage.

Skills

SIEM/SOAR operations
Elastic cluster
Python/PowerShell scripting
Linux administration

Education

Bachelor's degree in related field

Tools

Elasticsearch Enterprise (Logstash/Kibana)
Splunk

Job description

BreakPoint Labs is seeking a SIEM/SOAR Engineer to manage and maintain the CSSP’s Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. This role is responsible for administering an enterprise Elastic cluster while ensuring the performance, availability, and security of these critical systems. The engineer will leverage strong communication, analytical, and problem-solving skills to identify, communicate, and resolve issues, ultimately maximizing the effectiveness and value of CSSP security system investments.

Responsibilities include:
  • Design, implement, and maintain the SIEM and SOAR infrastructure (Elastic and Splunk).
  • Manage and maintain an enterprise Elastic cluster to support SIEM operations for the CSSP.
  • Monitor and analyze security events and incidents to protect information assets.
  • Assist in the develop and maintain use cases, rules, and alerts for threat detection and response.
  • Integrate SIEM and SOAR systems with other security tools and data sources.
  • Automate security operations workflows and incident response procedures using SOAR platforms.
  • Perform regular system monitoring and health checks to ensure the integrity and availability of SIEM and SOAR systems.
  • Conduct performance tuning, capacity planning, and scalability assessments for SIEM and SOAR solutions.
  • Implement and manage data ingestion pipelines for security event data.
  • Perform regular updates, patches, and upgrades for SIEM and SOAR systems.
  • Create and maintain documentation for system configurations, processes, and standard operating procedures.
  • Collaborate with security analysts, operations analysts, incident responders, and other CSSP teams to ensure effective use of SIEM and SOAR capabilities.
  • Provide guidance and support to operations analysts on the use of SIEM and SOAR tools.
  • Stay updated with the latest trends, tools, and best practices in SIEM and SOAR technologies.
  • Conduct research and recommend improvements to enhance the effectiveness of the SIEM and SOAR solutions.
Required Experience:
  • Minimum of 3 years of experience in maintaining an enterprise Elastic cluster.
  • Proficiency in managing and maintaining SIEM and SOAR solutions.
  • Experience with Elasticsearch Enterprise (including Logstash and Kibana) for SIEM operations.
  • Understanding of security event and incident management processes.
  • Knowledge of scripting languages (e.g., Python, PowerShell) for automation and integration.
  • Experience with threat detection and response methodologies.
  • Extensive experience with Linux Administration of RHEL Operating Systems.
  • Strong experience with networking protocols, solutions, and methodologies.
  • Excellent troubleshooting and problem-solving skills.
  • Strong communication and interpersonal skills.
  • Ability to work in a team-oriented, collaborative environment.
  • Ability to prioritize and execute tasks in a high-pressure environment.
  • Available for on-call after-hours rotational support as needed.
Certifications Required:

DoD 8570 IAT Level II and DoD 8140 CSSP Auditor compliant

Security Clearance Required:

Secret

Education required:

Bachelor’s Degree in related field.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM/SOAR Engineer (Elastic & Splunk)
Senior SIEM/SOAR Engineer (Elastic & Splunk)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 90,000 - 130,000
SIEM/SOAR Engineer
SIEM/SOAR Engineer

Valiant Solutions • South Carolina

On-site
USD 90,000 - 120,000
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Tier 1 Defensive Cyber Operations (DCO) Analyst
Tier 1 Defensive Cyber Operations (DCO) Analyst

BreakPoint Labs LLC • Hawaii

On-site
USD 70,000 - 95,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Splunk Administrator / SIEM Analyst
Splunk Administrator / SIEM Analyst

Spatial Front, Inc. • United States

Hybrid
USD 110,000 - 150,000
Linux SIEM System Engineer
Linux SIEM System Engineer

D2 Technical Services • Springfield (VA)

On-site
USD 135,000 - 145,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Columbus (OH)

On-site
USD 150,000 - 160,000
Cybersecurity Engineer – SIEM / Splunk
Cybersecurity Engineer – SIEM / Splunk

Electrosoft • Richmond (VA)

On-site
USD 150,000 - 160,000