- Softthink Solutions Inc
- Washington, DC
- Full-Time
- 26 days ago
- $45,000 – $55,000
SIEM/SOAR Engineer - Cloud Sec Spec 3.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
SIEM/SOAR Engineer - Cloud Sec Spec 3: our view in 3 lines...
- The Role:This role is for an experienced engineer building and configuring a Google SecOps SIEM/SOAR environment for enterprise security operations.
- The Person:The person will configure ingestion pipelines, build detections and SOAR playbooks, integrate threat intelligence, tune false positives, support UEBA dashboards, and help with runbooks, analyst training, and operational transition.
- Requirements:The ideal candidate has 10+ years of experience with SIEM/SOAR platforms, Google SecOps preferred, plus detection rules, automation workflows, parser validation, cloud telemetry ingestion, threat intelligence integration, and CISSP or equivalent.
About the role
SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Washington, DC
Work Authorization: US Citizen
Location: Washington, DC
Work Authorization: US Citizen
Role Summary
The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.
Roles & Responsibilities
· Configure ingestion pipelines and validate end‑to‑end log flow.
· Implement Google curated detections and build custom detection rules.
· Develop SOAR playbooks for SBA’s top incident categories.
· Integrate threat intelligence sources (Mandiant, Virus Total).
· Tune detections to meet false‑positive thresholds.
· Support UEBA dashboard configuration and risk scoring.
· Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
· 10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
· Experience building detection rules, automation workflows, and parser validation.
· Experience with cloud telemetry ingestion (Azure, AWS, on-prem).
· Experience with threat intelligence integration.
Educational Qualification
· Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications
· Google SecOps, GIAC, CISSP, or equivalent preferred.

