Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
A leading company is seeking a Senior Detection Engineer to enhance security operations by developing SOAR playbooks and collaborating with cybersecurity teams to optimize incident response. This role requires expertise in security architecture and strong analytical skills to manage and improve SIEM system capabilities while supporting overall cybersecurity initiatives.
Description
Senior Detection Engineer
The Cybersecurity Engineering function is responsible for supporting the design and implementation of Security Architecture patterns into functioning platforms and systems within Comerica. This includes the engineering, deployment, and advanced support of critical control systems, security platforms, and associated workstreams or processes. The Cyber Engineering teams collaborate closely with peers within the Cyber Defense Organization and Technology teams to enable and support Comerica's systems.
The Senior Detection Engineer is responsible for Create SOAR playbooks, workflows and integrations to automate tasks like threat detection, incident response and security operations. Maintain SOAR playbooks by creating detailed step by step instructions for security analysts to follow during incidents.
Collaborate closely with SOC, Threat Detection and Intel teams to understand operational requirements and tailor automation solutions. Provide technical expertise and support for SOAR-related problems and configurations.
As well as, assist clients to fully optimize SIEM system capabilities and the audit and logging features of event log sources. Creation of technically detailed reports on the status of the SIEM to include metrics on items such as number of logging sources. Working alongside the SOC, Threat Detection and Threat Intel teams for configuring, maintaining, tuning and enhancing the SIEM platform. Be responsible for the investigation and delivery of defect resolutions through engineering into the production environment without impacting the live service. Monitor and manage the performance of the SIEM infrastructure. Support security engineering requirements for projects, transitions, and transformations. Provide periodic status updates and technical presentations.
Position Responsibilities:
Cybersecurity Engineering
Communication and Collaboration
Planning and Administration