Senior CyberSecurity Specialist - Engineer (SIEM/SOAR) @Newell Brands
All Others
Salary usd 108,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3wks ago

[Hiring] Senior CyberSecurity Specialist - Engineer (SIEM/SOAR) @Newell Brands

3wks ago - Newell Brands is hiring a remote Senior CyberSecurity Specialist - Engineer (SIEM/SOAR). πŸ’Έ Salary: usd 108,000 - 138,600 per year πŸ“Location: USA

Role Description

The Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. This role owns the full lifecycle of detection engineering – from ingestion and correlation through automated response – and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.

Key Responsibilities

  • Own SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mapping.
  • Serve as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experience.
  • Manage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillment.
  • Serve as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes and processing pipelines across cloud and on-premises worker groups.
  • Lead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources.
  • Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositories.
  • Build and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platforms.
  • Develop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumers.
  • Continuously measure and report detection coverage gaps and use-case performance (false positive rate).
  • Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycle.
  • Develop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response path.
  • Integrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feeds.
  • Document all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineer.
  • Define and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distribution.
  • Lead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generation.
  • Evaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance framework.
  • Partner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirements.
  • Own MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership.
  • Support incident response by providing platform-level investigation capability and post-incident forensic log review.
  • Participate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputs.

Qualifications

  • 5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment and detection rule development.
  • 3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case management.
  • Demonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent).
  • Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technology.
  • Proficiency in at least one scripting or query language such as Python or Powershell.
  • Expert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratch.
  • Working knowledge of MITRE ATT&CK framework and application to detection use case development.
  • Experience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIs.
  • Strong written communication: ability to document technical logic, playbooks, and runbooks to an operational standard.
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.

Preferred Qualifications

  • Experience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environment.
  • Exposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflows.
  • Familiarity with non-human identity (NHI) monitoring and agentic risk controls.
  • Experience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposure.
  • Certifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalent.
  • Familiarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deployments.

Benefits

  • The Remote base pay range for this position is from $108,000 to $138,600. Salary will be based on prior experience related to the skills required for this position.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior CyberSecurity Specialist - Engineer (SIEM/SOAR) @Newell Brands
All Others
Salary usd 108,000 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later