Sr Advanced Cyber Security Architect Engineer

Honeywell Technologies

Duluth (GA)

Hybrid

USD 120,000 - 180,000

Full time

2 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision, LifeInsurance
401(k) match
Paid Holidays

Job summary

Honeywell Technologies in Duluth, GA is seeking an experienced cyber security professional to join the Industrial Cyber-Security team. You will deliver and develop cyber security services for global industrial customers and report to the Global Security Operation Center Manager and Incident Response Lead in a hybrid work setting.

You will work with SIEMs and SOAR platforms, evaluate incidents, and provide context enrichment before escalation to Level 3 IR as needed.

Qualifications

  • 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
  • 5+ years in a Security Operations Center (SOC) or related security function.
  • 5+ years with SIEM or SOAR technologies.
  • 5+ years developing or implementing security automation using Python or SOAR platforms.

Responsibilities

  • Monitors SIEM, trouble tickets / email notifications and escalations, logs from ICs infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices.
  • Design, implement, test Security Orchestration, Automation and Response processes and procedures.
  • SOAR playbook development and troubleshooting automation capabilities.
  • Examine escalated tickets to determine true positives or false positives.

Skills

Senior IT/cybersecurity experience
SOC/IR operations
SIEM/SOAR proficiency
Security automation with Python

Education

Bachelor’s degree in CS/IS/ Electronics
ITIL Foundation or cybersecurity certification (e.g., Security+, GCIH, CCNA, GCFA, CEH)

Tools

Swimlane
Sentinel
Google Cloud SECOPS

Job description

Job Description

This position will be a part of the Industrial Cyber-Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team.

You will report directly to our Sr. Cyber Security Manager and you'll work out of our Duluth, GA. location on a Hybrid work schedule. The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed.

Responsibilities
KEY RESPONSIBILITIES
  • Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICs infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS;
  • Design, implement, test Security Orchestration, Automation and Response processes and procedures;
  • SOAR playbook development and troubleshoot automation capabilities;
  • Examine the escalated tickets to determine if they are true positive or false positives.
  • Performs malware analysis, threat hunting and threat modeling activities;
  • Assist forensic investigation by providing reports and other information;
  • Reviews and suggests improvements to control deployment process and installation procedures
  • Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff;
  • Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions;
  • Participates in root cause analysis and helps with the orchestration of remediation;
  • Understand defense in depth strategies and apply those to Client's environment;
  • Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities);
  • Acts as L2 Escalation layer in the SOC.
  • Mentors Level 1 SOC Analysts;
  • Creates manuals, guides and knowledge base entries;
  • Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers;
  • Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings.
Qualifications
YOU MUST HAVE
  • 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
  • 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function.
  • 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies.
  • 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies.
WE VALUE
  • Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field.
  • ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH.
  • Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS.
Benefits Of Working For Honeywell

In addition to a competitive salary, leading-edge work, and developing solutions side-by-side with dedicated experts in their fields, Honeywell employees are eligible for a comprehensive benefits package. This package includes employer subsidized Medical, Dental, Vision, and Life Insurance; Short-Term and Long-Term Disability; 401(k) match, Flexible Spending Accounts, Health Savings Accounts, EAP, and Educational Assistance; Parental Leave, Paid Time Off (for vacation, personal business, sick time, and parental leave), and 12 Paid Holidays. Learn more (https://benefits.honeywell.com/)

The application period for the job is estimated to be 40 days from the job posting date; however, this may be shortened or extended depending on business needs and the availability of qualified candidates.

About Honeywell

Honeywell International Inc. (Nasdaq: HON) invents and commercializes technologies that address some of the world's most critical challenges around energy, safety, security, productivity, and global urbanization. We are a leading software-industrial company committed to introducing state of the art technology solutions to improve efficiency, productivity, sustainability, and safety in high growth businesses in broad-based, attractive industrial end markets. Our products and solutions enable a safer, more comfortable, and more productive world, enhancing the quality of life of people around the globe. Learn more (https://www.honeywell.com/us/en)

U.s. Person Requirements

Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization.

About Us

Honeywell Technologies is a global, pure-play automation company with a legacy of innovating to help solve the world’s most mission-critical challenges, enhancing the quality of life for people and communities around the world. We serve the building, industrial and process sectors with a broad portfolio of services, solutions and products, underpinned by our Honeywell Technologies Accelerator operating system and Honeywell Technologies Forge intelligence layer. By combining the deep domain expertise of our more than 50,000 employees with decades of data from our global installed base, we are uniquely positioned to lead the industrial sector’s transition from automation to autonomy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Advanced Cyber Security Architect Engineer
Sr Advanced Cyber Security Architect Engineer

Honeywell INC. in • Duluth (GA)

Hybrid
USD 140,000 - 200,000
Hybrid work schedule
Comprehensive benefits package
Cyber Security Supervisor
Cyber Security Supervisor

Honeywell Technologies • Duluth (GA)

Hybrid
USD 120,000 - 170,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Cyber Security Supervisor
Cyber Security Supervisor

Honeywell INC. in • Duluth (GA)

Hybrid
USD 110,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+9
Advanced Software Engineer - Developer Experience
Advanced Software Engineer - Developer Experience

Honeywell Technologies • Town of Pittsford (NY)

Hybrid
USD 121,000 - 151,000
Medical insurance
Dental insurance
Vision insurance
+3
Global Sales Director - Cybersecurity
Global Sales Director - Cybersecurity

Honeywell INC. • Atlanta (GA)

Hybrid
USD 180,000 - 280,000
Software Engineer II
Software Engineer II

Honeywell Technologies • Atlanta (GA)

Hybrid
USD 120,000 - 160,000
Medical Insurance
Dental & Vision
401(k) match
+1
Global Sales Director - Cybersecurity
Global Sales Director - Cybersecurity

Socket.dev • Atlanta (GA)

Hybrid
USD 250,000 - 350,000
Field Service Engineer I
Field Service Engineer I

Honeywell Technologies • Canton (MA)

Hybrid
USD 71,000 - 89,000
Medical, Dental, Vision
401(k) match
Paid time off
+1
Field Service Engineer I
Field Service Engineer I

Honeywell INC. in • Canton (MA)

Hybrid
USD 71,000 - 89,000
Medical, Dental, Vision
Life Insurance
Disability Insurance
+2
Principal Cyber Sec Archt/Engr
Principal Cyber Sec Archt/Engr

Honeywell INC. • North Branford (CT)

Hybrid
USD 224,000 - 337,000
Medical insurance
Dental & Vision
401(k) match
+1