Lead, Info Security Systems
Newell Brands is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid®, Sharpie®, Graco®, Coleman®, Oster®, and Yankee Candle®, supported by 24,000 teammates worldwide. Our culture is built on values of integrity, teamwork, passion for winning, ownership, and leadership, fostering a high-performing, inclusive, and collaborative environment.
About the role
This is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. The Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) owns the full lifecycle of detection engineering—from ingestion and correlation through automated response—and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This role is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.
Responsibilities
- Own SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mapping
- Serve as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experience
- Manage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillment
- Serve as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes, and processing pipelines across cloud and on-premises worker groups
- Lead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources
- Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositories
- Build and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platforms
- Develop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumers
- Continuously measure and report detection coverage gaps and use-case performance (false positive rate)
- Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycle
- Develop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response path
- Integrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feeds
- Document all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineer
- Define and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distribution
- Lead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generation
- Evaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance framework
- Partner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirements
- Own MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership
- Support incident response by providing platform-level investigation capability and post-incident forensic log review
- Participate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputs
Requirements
- 5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment, and detection rule development
- 3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case management
- Demonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent)
- Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technology
- Proficiency in at least one scripting or query language such as Python or PowerShell
- Expert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratch
- Working knowledge of MITRE ATT&CK framework and application to detection use case development
- Experience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIs
- Strong written communication: ability to document technical logic, playbooks, and runbooks to an operational standard
- Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
Preferred Qualifications
- Experience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environment
- Exposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflows
- Familiarity with non-human identity (NHI) monitoring and agentic risk controls
- Experience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposure
- Certifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalent
- Familiarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deployments
Pay
The remote base pay range for this position is from $108,000 to $138,600. Salary will be based on prior experience related to the skills required for this position.