Security EngineerArchitect (CISSPCISACISOSECURITYCEHOSCPGPEN)
Columbia, SC - USA
Job Summary
Job ID: SC-11297 ()
Remote/Local Security Engineer/Architect (CISSP/CISA/CISO/SECURITY/CEH/OSCP/GPEN) with SIEM Detection coverage gap remediation Threat Intelligence Python/Bash/PowerShell Sigma/Yara Tunning PALO ALTO CORTEX XSIAM Windows/Linux MITRE ATT&CK experience
Location: Columbia SC (Department of Administration)
Duration: 12 Months
Interview Process: 1 round Virtual/Online potential for a 2nd round onsite as needed
Work Location: Fully Remote
Candidate Location: No SC residency required. Open to nationwide candidates.
Required Education/Certifications:
BACHELORS DEGREE IN AN INFORMATION TECHNOLOGY OR INFORMATION SECURITY RELATED FIELD
EIGHT YEARS OF RELEVANT WORK EXPERIENCE MAY BE SUBSTITUTED IN LIEU OF EDUCATION
FIVE YEARS OF EXPERIENCE IN SUPPORTING LARGE IT ENVIRONMENTS AND/OR SYSTEM DEPLOYMENTS
5 years of Strong scripting and automation skills (Python Bash PowerShell or similar).
Understanding of Sigma YARA and other industry standard detection languages.
Familiarity with MITRE ATT&CK framework
Preferred Skills (rank in order of Importance):
Experience with the Palo Alto Cortex XSIAM platform.
Deep understanding of Windows/Linux artifacts.
Excellent communication and customer service skills for agency- facing engagement.
Experience in working in multi- tenancy environment
Experience in multi-agency or enterprise service projects.
Preferred Education/Certifications:
CISSP CISA CISO or equivalent advanced security certification.
Additional relevant certifications (e.g. CEH OSCP GPEN).
VENDOR CERTIFICATIONS IN DETECTION ENGINEERING.
Resource is local to Columbia South Carolina or a surrounding city in South Carolina
Scope of the project:
The position will work as a consulting Detection engineer within the Division of Information Security. This role will focus on creating tuning and maintaining new and existing detection rules within the State monitoring environment. Engaging directly with state agencies to promote support and improve adoption of centralized security services is a key focus. The engagement is expected to be needed for 12 months with the possibility of extension.
Daily Duties / Responsibilities:
PREFERENCE WILL BE GIVEN TO A CANDIDATE WHO CAN WORK ONSITE OVER HYBRID AND OVER FULL-TIME REMOTE (ON-SITE AS NEEDED).
Review and tune current detection rules within the State SIEM.
Perform Gap analysis of the current detection coverage.
Develop detection rules/solutions to cover found Gaps.
monitor threat intelligence sources for new use cases.
Work with State SOC analysts to create and tune rules.
Work with the State Threat Hunter to identify and remediate detection coverage gaps.
Document processes runbooks and troubleshooting steps related to the SOAR and integrations.
Coordinate with engineering SOC and agency staff as needed to meet goals.
Other duties as needed.
Additional skills and duties:
Proven experience with detection tuning/development..
Experience with dashboard creation and reporting.
innoSoul Inc. is an Information Technology company and offers technology solutions in various platforms to different business domains. More specifically business solutions for Application Development System integration network or software installation support Custom Web Development Hosting solutions. Our value-added solutions leverage technology to enhance business performance increase productivity and secure data.