Information Security Engineer – Security Automation and Response
About Our Client
This organization operates within the academic medical center sector, providing comprehensive healthcare services with a focus on advancing medical innovation and serving community health needs. It addresses challenges in healthcare delivery by integrating compassionate patient care with cutting-edge medical research and education, maintaining a significant presence and impact in its region.
About the Opportunity
The Information Security Engineer – Security Automation and Response role is dedicated to enhancing the security operations of the organization through automation and incident response. This position focuses on developing and maintaining automated security workflows that improve the efficiency of threat detection and response, contributing to the protection of sensitive information and the integrity of healthcare systems.
Responsibilities
- Develop, implement, and maintain SOAR playbooks to automate security tasks such as alert triage, threat investigation, and incident response.
- Utilize tools including SOAR platforms, Python, and API integrations for automation.
- Support initiatives to advance Security Operations capabilities using AI.
- Investigate malware, intrusions, unauthorized access, and data breaches.
- Analyze logs, memory, disk images, and network captures to assess attack scope and impact.
- Stay informed on cyber threats and improve Security Operations Center capabilities.
- Demonstrate strong knowledge of SIEM platforms and related query languages.
- Participate in Purple Team activities to enhance security posture.
- Engage in on-call rotations to respond to critical security events.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or equivalent education and experience.
- Minimum of 5 years in security-related roles or equivalent training.
- Proficiency in computing systems, network communications, and architecture.
- Effective written and verbal communication skills.
- Experience in SOAR playbook development.
- Programming or scripting skills in languages such as Python, PowerShell, or Go.
- Background in Incident Response and Threat Investigation.
- Knowledge of threat detection methods and logging systems.
- Security certifications preferred, including GIAC or CISSP.
Benefits
- Medical insurance
- Dental insurance
- 401(k) retirement plan