Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc.

Orlando (FL)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A major restaurant chain seeks a Cybersecurity Engineer to lead the design and implementation of security monitoring capabilities. Responsibilities include managing SIEM infrastructure and developing security automation workflows, with a focus on enhancing incident detection and response. Candidates should possess a degree in computer science or cybersecurity and relevant experience in security engineering. This role offers the opportunity to collaborate with various teams to fortify the organization's cybersecurity posture.

Qualifications

  • 5+ years of experience in cybersecurity, focusing on security engineering roles.
  • Hospitality industry product development experience is a plus.
  • Hands-on experience with cross-functional execution.

Responsibilities

  • Design and maintain enterprise SIEM infrastructure focused on performance optimization.
  • Collaborate with SOC analysts to investigate alerts and conduct forensic analysis.
  • Develop automation workflows for operational security tasks.

Skills

Elasticsearch expertise
Incident response management
Security automation
Cross-functional collaboration
Threat detection

Education

Bachelor's degree in computer science or cybersecurity

Tools

Elastic Stack
Python
PowerShell
Azure Sentinel

Job description

Overview

Serve as a senior member of the Cybersecurity Engineering team responsible for designing, implementing, and optimizing enterprise security monitoring and automation capabilities. Led the architecture and operational maturity of the organization's SIEM platform with a focus on Elasticsearch and security automation to improve threat detection, incident response, and visibility across enterprise infrastructure. Partnered with product, platform, DevOps, and security teams to integrate security telemetry, automate workflows, and strengthen the organization's overall cybersecurity posture.

ESSENTIAL/PRIMARY DUTIES, FUNCTIONS, AND RESPONSIBILITIES
  • Design, implement, and maintain enterprise SIEM infrastructure, including Elasticsearch clusters, log pipelines, indexing strategies, and data ingestion from cloud, network, endpoint, and application sources.
  • Develop and maintain SIEM detection content, including correlation rules, dashboards, threat detection use cases, and alerting frameworks to improve security monitoring and incident detection.
  • Lead the Elasticsearch roadmap and platform strategy, ensuring scalability, high availability, performance optimization, and alignment with enterprise security initiatives.
  • Built security automation workflows and scripts to streamline incident response, threat hunting, log enrichment, and security operations processes.
  • Integrate SIEM/SOAR capabilities with security technologies including EDR, threat intelligence platforms, vulnerability scanners, identity systems, and network security tools to create a unified security monitoring ecosystem.
  • Tune and optimized detection logic and log pipelines to reduce false positives and improve signal-to-noise ratio across security monitoring platforms.
  • Collaborate with SOC analysts and incident response teams to investigate alerts, conduct forensic analysis, and identify root causes of security incidents.
  • Ingest and operationalized threat intelligence feeds to enhance detection capabilities and proactively identify emerging threats.
  • Implement monitoring and alerting frameworks to ensure health, performance, and availability of SIEM and Elasticsearch infrastructure.
  • Analyze network, system, and application logs to identify security incidents, anomalies, and threat activity trends.
  • Partner with cross-functional IT teams to integrate security telemetry from cloud platforms (Azure/AWS), Linux and Windows servers, networking systems, and enterprise applications.
  • Develop automation workflows for operational security tasks, including vulnerability management, patch validation, and configuration monitoring.
  • Support incident response planning and execution, leveraging SIEM analytics and automation to accelerate investigation and containment.
  • Generate security metrics and reporting on incident trends, detection effectiveness, and operational KPIs for leadership and governance reporting.
  • Assist with cybersecurity audits, vulnerability assessments, and penetration test remediation efforts.
  • Contribute to the development and improvement of security architecture standards, policies, and governance frameworks.
  • Evaluate emerging security technologies and recommend improvements to security monitoring, automation, and detection capabilities.
  • Provide mentorship and guidance to junior security engineers and analysts while promoting security engineering best practices across teams.
JOB REQUIREMENTS (SKILLS & EXPERIENCE)
EDUCATION AND BUSINESS EXPERIENCE
  • Bachelor's degree (B.A. or B.S.) in computer science, cybersecurity or a related field from a four-year college or university
  • At least 5 years of experience in cybersecurity, especially in a security engineering role.
  • Three or more years of progressive technology management experience in cross-functional teams
  • Strong familiarity with project and program management disciplines, methodologies, and processes
  • Familiarity with the functioning of a program management office and governance frameworks
  • Hands on experience with cross-functional execution
  • Hospitality industry product development experience is a plus
TECHNICAL EXPERIENCE
  • SIEM Platforms: Elastic Stack (Elasticsearch, Logstash, Kibana), Azure Sentinel
  • Automation & Scripting: Python, PowerShell, Bash, Ansible
  • Security Technologies: EDR, CASB, SASE, SWG, ZTNA, DLP, IAM, PAM/PIM, WAF, IDS/IPS
  • Infrastructure: Linux, Windows Server, Cloud (Azure/AWS/GCP), network security devices
  • Logging & Data Processing: Syslog, log parsing, regex/grok pipelines, data normalization
  • Security Domains: Threat detection, incident response, threat intelligence integration, log analytics, security automation
KNOWLEDGE, SKILLS, AND ABILITIES
  • Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
  • Strong problem-solving and trouble-shooting skills.
  • Deep understanding of current and emerging cybersecurity technologies and how other enterprises are employing them to drive digital business, and how they may be applied to drive digital business.
  • Strong customer service orientation in combination with persuasive skills and diplomacy to lead change and guide decisions.
  • Highly self-motivated and directed.
  • Team oriented and skilled in working within a collaborative environment
  • Ability to appropriately prioritize and execute tasks in a fast-paced, service-intensive environment.
  • Effective oral and written communication skills, including the ability to explain digital concepts and technologies to business leaders, as well as business concepts to technologists.
  • Ability to effectively interact with all levels of management, from individual contributors to the executive team.
CERTIFICATIONS AND/OR LICENSES
  • Certified information systems security professional (CISSP) desired but not required.
  • Additional certifications such as GIAC, CEH, or SIEM platform certifications are beneficial.
WORK ENVIRONMENT AND PHYSICAL DEMANDS
  • Ability to stand, bend, stoop, sit, walk, twist, and turn.
  • Ability to lift up to 25 pounds occasionally.
  • Ability to use a computer keyboard and calculator.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Jobtailor • Palo Alto (CA)

On-site
USD 180,000 - 260,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Engineer - SIEM Platform Engineering & Operations
Senior Engineer - SIEM Platform Engineering & Operations

Koitecc Solutions • Addison (TX)

On-site
USD 150,000 - 191,000
Senior Engineer - SIEM Platform Engineering & Operations
Senior Engineer - SIEM Platform Engineering & Operations

Koitecc Solutions • Charlotte (NC)

On-site
USD 150,000 - 191,000
Benefits eligible
Elasticsearch Lead Engineer - SIEM Platform
Elasticsearch Lead Engineer - SIEM Platform

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Security Engineer
Security Engineer

Liberty Personnel Services, Inc. • Feasterville-Trevose

Hybrid
USD 90,000 - 120,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000
Senior SIEM Analyst
Senior SIEM Analyst

theserverlab • United States

On-site
USD 80,000 - 100,000
Medical benefits
Dental benefits
Vision benefits
+2
Security Analyst
Security Analyst

The Phoenix Group • New York (NY)

On-site
USD 65,000 - 95,000
Senior Security Engineer
Senior Security Engineer

SourcePro Search • Los Angeles (CA)

On-site
USD 140,000 - 210,000