Summary
The Home Depot is seeking a Cybersecurity Engineer II to strengthen its cybersecurity operations through SIEM and EDR platforms such as Cortex XSIAM, Splunk, and CrowdStrike. The role focuses on maintaining and optimizing security monitoring and endpoint detection capabilities, developing detection rules and automation, investigating incidents, and collaborating with security and engineering teams to reduce risk.
Responsibilities
- Maintain day-to-day operational health of EDR and SIEM infrastructure
- Conduct research to baseline normal activity and tune out noise from alerting
- Tune security use cases to provide high fidelity alerts
- Collaborate to develop new, custom security use cases, log correlations, and detection rules
- Apply event data to existing security use cases and models
- Develop and configure dashboards for monitoring event trends and alerts
- Configure reporting to provide key metrics and trends
- Collaborate with external teams to onboard new data sources to SIEM
- Validate appropriate extraction, parsing, and formatting in event data
- Write custom field extractions in RegEx
- Perform troubleshooting and break/fix efforts during service disruptions
- Configure AV exceptions and blocks
- Maintain updated service documentation
- Perform other related duties as assigned
- 100% Deliver Execution & Problem Solving - Collaborate with Enterprise Technology to configure and integrate cybersecurity systems that mitigate risk; Troubleshoot and quickly resolve escalated incidents; Design, build, configure, maintain, monitor cybersecurity threat defense capabilities and user access management; Coordinate integration and collaboration with managed security providers; Investigate and recommend corrective actions related to incidents
Skills
- • 2+ years of cyber security work experience
- • 1+ years of SIEM or EDR specific work experience with platforms such as Cortex XSIAM, Splunk, CrowdStrike, etc
- • Good understanding of networking infrastructure concepts, technologies, and protocols
- • Capable of identifying gaps in logging/monitoring/endpoint protection and recommending solutions
- • Able to bridge the gap between technical and non-technical constituents
- • Solid people, team, and communication skills
- • No travel required
- • Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles
- • Must be eighteen years of age or older
- • Must be legally permitted to work in the United States
- • The knowledge, skills and abilities typically acquired through the completion of a bachelor's degree program or equivalent degree in a field of study related to the job
- • 2+
- • Security+ and SIEM Vendor Certification (any vendor) and EDR Vendor Certification (any vendor) or equivalent certifications
- • Incident Response / SOC work experience
- • Experience working with cloud-based solutions, such as Azure, GCP
- • Experience with Linux/Unix Administration
- • Experienced with writing formal reports
Qualifications
Must Haves
- • 2+ years of cyber security work experience
- • 1+ years of SIEM or EDR specific work experience with platforms such as Cortex XSIAM, Splunk, CrowdStrike, etc
- • Good understanding of networking infrastructure concepts, technologies, and protocols
- • Capable of identifying gaps in logging/monitoring/endpoint protection and recommending solutions
- • Able to bridge the gap between technical and non-technical constituents
- • Solid people, team, and communication skills
- • No travel required
- • Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles
- • Must be eighteen years of age or older
- • Must be legally permitted to work in the United States
- • The knowledge, skills and abilities typically acquired through the completion of a bachelor's degree program or equivalent degree in a field of study related to the job
- • 2+
Nice to Haves
- • Security+ and SIEM Vendor Certification (any vendor) and EDR Vendor Certification (any vendor) or equivalent certifications
- • Incident Response / SOC work experience
- • Experience working with cloud-based solutions, such as Azure, GCP
- • Experience with Linux/Unix Administration
- • Experienced with writing formal reports