Jobs · Georgia

Lead, Info Security Systems

Newell Brands · Atlanta, GA · 1 wk ago
Hybrid$108k–$139k/yrFull-time

Newell Brands is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid®, Sharpie®, Graco®, Coleman®, Oster®, and Yankee Candle®, supported by 24,000 teammates worldwide. Our culture is built on values of integrity, teamwork, passion for winning, ownership, and leadership, fostering a high-performing, inclusive, and collaborative environment.

About the role

This is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. The Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) owns the full lifecycle of detection engineering—from ingestion and correlation through automated response—and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This role is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.

Responsibilities

  • Own SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mapping
  • Serve as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experience
  • Manage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillment
  • Serve as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes, and processing pipelines across cloud and on-premises worker groups
  • Lead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources
  • Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositories
  • Build and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platforms
  • Develop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumers
  • Continuously measure and report detection coverage gaps and use-case performance (false positive rate)
  • Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycle
  • Develop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response path
  • Integrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feeds
  • Document all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineer
  • Define and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distribution
  • Lead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generation
  • Evaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance framework
  • Partner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirements
  • Own MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership
  • Support incident response by providing platform-level investigation capability and post-incident forensic log review
  • Participate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputs

Requirements

  • 5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment, and detection rule development
  • 3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case management
  • Demonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent)
  • Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technology
  • Proficiency in at least one scripting or query language such as Python or PowerShell
  • Expert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratch
  • Working knowledge of MITRE ATT&CK framework and application to detection use case development
  • Experience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIs
  • Strong written communication: ability to document technical logic, playbooks, and runbooks to an operational standard
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience

Preferred Qualifications

  • Experience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environment
  • Exposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflows
  • Familiarity with non-human identity (NHI) monitoring and agentic risk controls
  • Experience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposure
  • Certifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalent
  • Familiarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deployments

Pay

The remote base pay range for this position is from $108,000 to $138,600. Salary will be based on prior experience related to the skills required for this position.

Similar jobs

Lead, Information Security

Hancock WhitneyNew Orleans, LA· 1 mo ago
Information Technologyapply on hancockwhitney.wd5.myworkdayjobs.com

Information Security Lead

The Boler Company®Schaumburg, IL· 1 wk ago
Information Technology$115k–$150k/yrapply on recruiting.adp.com

Information Security Lead

Click Therapeutics, Inc.New York, NY· 2 mo ago
Information Technology$130k–$200k/yrapply on grnh.se