Position Purpose:
The Home Depot is seeking a skilled Senior Cybersecurity Engineer with expertise on SIEM platforms such as Cortex XSIAM, Splunk, or similar tools. The ideal candidate will have a strong understanding of networking infrastructure, including core technologies and protocols. This role involves monitoring, analyzing, and responding to security events, as well as optimizing SIEM configurations to enhance threat detection and incident response capabilities.
Job Description:
Maintain day to day operational health monitoring of SIEM infrastructure and data feedsCoordinate or perform troubleshooting and break/fix efforts during service downtimeCollaborate with external teams to onboard new data sourcesApply event data to existing security use cases and modelsWrite custom extractions in RegExValidate appropriate extraction, parsing, and formatting in event dataCoordinate with technology teams to ensure appropriate log level configurationsReview and filter events to reduce unnecessary log ingestionConduct research to baseline normal activity and tune out noise from alertingTune security use cases and models to provide high fidelity alertingDevelop and configure dashboards for monitoring event trends and alertsConfigure reporting to provide key metrics and trends to leadershipCollaborate to develop new, custom security use cases, log correlations, and data modelsCollaborate to send alerting to Incident Management and/or SOAR platformsCollaborate to integrate automation with the SIEM platformCollaborate to ingest and apply enrichment data in the platformReview, test, and perform upgrades to SIEM platformMaintain updated service documentationCreate and maintain alert use case documentationProvide subject matter expertise for SIEM platform and processesPerform other related duties as assigned
Required Skills:
3+ years of cyber security work experience1+ years of SIEM specific work experience with platforms such as Cortex XSIAM, Splunk, etc.Good understanding of networking infrastructure concepts, technologies, and protocolsCapable of identifying gaps in logging/monitoring and recommending solutionsAble to bridge the gap between technical and non-technical constituentsSolid people, team, and communication skillsPreferred Skills:
CCSP, SSCP, GCDA, GSEC, or equivalent certificationsSIEM vendor specific certificationsExperience with PCI compliant environmentIncident Response / forensic work experienceExperience working with cloud-based solutions, such as Azure, GCPExperience with Linux/Unix AdministrationExperienced with writing formal reports
Key Responsibilities:
Direct Manager/Direct Reports:
Travel Requirements:
Physical Requirements:
Working Conditions:
Minimum Qualifications:
Minimum Education:
Preferred Education:
Minimum Years of Work Experience:
Competencies: