Lead Security Engineer (SOAR) - 100% US REMOTE

Allen, TX, United States

Applications have closed

Experian

Experian is committed to helping you protect, understand, and improve your credit. Start with your free Experian credit report and FICO® score.

View company page

Company Description

Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been named in the 100 “World’s Most Innovative Companies” by Forbes Magazine

 

    Job Description

    The Systems Security Engineer Lead is part of the security integrations & Analytics team in the Experian GSO. This role will serve as an engineering leader responsible for the innovation, development, and maintenance of SOAR, SIEM & UEBA systems. Specific focus will be directed to SOAR automation integrating with other software solutions including ServiceNow, SIEM, IOC vendors, Vulnerability Management tools, and other security controls.  This leader will be the driver of innovation for automating Engineering/GSOC processes and data enrichment in the SIEM system.

    An ideal candidate will have extensive information security experience particularly in incident response, general security tool operations and able to apply that knowledge to drive future automation to reduce delivery times and process efficiencies. The Systems Security Engineer Lead will work closely with the various internal teams, including but not limited to cyber threat intelligence analysts, SOC analysts, incident management, server and network administrators, security tool administrators, and business unit customers.  

     

    Major Responsibilities include: 

    • Understand of various security controls and logs that feed the SIEM & UEBA technologies.  

    • Ability to dissect operational processes converting them to detailed requirements to build an automated workflow.  

    • Ability to lead and direct development efforts of a team of Python developers. 

    • Remediate vulnerabilities in the different application environments 

    • Work with the other security functions and product SMEs to identify opportunities to automate GSOC or engineering processes to prevent security threats. 

    • Development of parsers/field extractions into the SOAR platform 

    • Development of custom scripts as required to augment default SIEM functionality 

    • Participate in root cause analysis on security incidents and provide recommendations for containment and remediation 

    • Act as the liaison to business units to fulfill audit, regulatory compliance and/or corporate security policy requirements. 

    • Create, implement and maintain novel analytic methods and techniques for incident detection 

    • Ensure documentation for automation is available on team wiki- specifically including automated process flows across tools 

    Qualifications

    Required Qualifications: 

    • Prior experience developing on a SOAR platform automating security engineering or GSOC playbooks. 

    • Experience in gathering requirements of existing manual processes and converting them into automated workflows 

    • Understanding of various log formats and source data for SOAR Analysis 

    • Strong Experience in working in an Agile environment utilizing SCRUM or KANBAN methodologies 

    • Solid background with Windows and Linux platforms (security or system administration) 

    • Ability to effectively communicate with anyone, from end users to senior leadership- facilitating technical and non-technical conversations. 

    • Strong incident handling/incident response/security analytics skills 

    • Deep understanding of technical concepts including networking and various cyber attacks 

    • Solid comprehension of various security controls, capabilities and use in a corporate environment 

    • Exceptional problem-solving capabilities 

    • Strong Python development skills 

    • Strong experience in developing and maintaining Restful API’s 

    • Strong documentation and communication skills 

    • Demonstrated history of innovation and/or creativity 

    • Ability to drive process improvements and identify gaps 

    • Knowledge of programming/scripting fundamentals 

     

    Desired Skills & Experience: 

    • 5+ years’ of information security experience, preferably engineering or development 

    • 3+ years’ experience supporting a SOAR platform in a content development or administrative role 

    • 3+ years experience developing in Python 

    • 2+ years experience leading teams directing work efforts utilizing Agile methodologies 

    • 2+ years’ experience performing SOC analysis and/or incident response 

    • 2+ years experience working with cloud computing 

    • Bachelor’s Degree or higher degree in Computer Science, Information Security or similar discipline is preferred 

    • Experience with a wide range of security products 

    • Industry Security Certifications (CISSP, SANS) preferred 

    Additional Information

    Culture at Experian

    Our uniqueness is that we truly value yours.

    Experian's culture, people and environments are key differentiators. We take our people agenda very seriously. We focus on what truly matters; diversity and inclusion, work/life balance, flexible working, development, engagement, collaboration, wellness, reward & recognition, volunteering... the list goes on

    We’re an award-winning organization due to our strong people focus

    Experian isn't just growing, we're leveraging cutting edge data science, design thinking and passion to build tomorrow's credit solutions. Innovation is a critical part of Experian's DNA and culture

     

    Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a thriving, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is essential to our purpose of creating a better tomorrow. We value the uniqueness of every individual and want you to bring your whole, authentic self to work. For us, this is The Power of YOU and and it reflects what we believe.  See our DEI work in action!

    If you live in Colorado, Connecticut or New York City, please contact us at JobPostingInquiry@experian.com for the salary range of this position (include the exact Job Title as it reads above in your email). In addition to a competitive base salary and variable pay opportunity, Experian offers a comprehensive benefits package including health, life and disability insurance, generous paid time off including parental and family care leave, an employee stock purchase plan and a 401(k) plan with a company match.

    Experian Careers - Creating a better tomorrow together

    Find out what its like to work for Experian by clicking here

    Tags: Agile Analytics APIs Automation CISSP Cloud Compliance Computer Science Incident response Kanban Linux Python SANS Scripting Scrum SIEM SOAR SOC Threat intelligence Vulnerabilities Vulnerability management Windows

    Perks/benefits: 401(k) matching Competitive pay Equity Flex hours Flex vacation Health care Insurance Parental leave

    Regions: Remote/Anywhere North America
    Country: United States
    Job stats:  45  6  0

    More jobs like this

    Explore more InfoSec / Cybersecurity career opportunities

    Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.