- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 5 days ago
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
The Lead SOC Engineer specializing in SIEM at CPX holds a critical position within the Security Operations Center, integrating technical leadership, design of SIEM architecture, and pre-sales support responsibilities. This role demands oversight of SIEM solution management and coordination, ensuring smooth day-to-day operations across various environments and clients. Reporting to the Senior SOC Engineering & Architecture Manager, this position requires substantial experience, especially in SIEM operational oversight and team guidance.
Key Duties and Responsibilities
- Direct the technical management and daily functioning of SIEM platforms including Splunk, Sentinel, LogRhythm, Qradar, and FortiSIEM.
- Supervise the upkeep and performance of log collection systems, particularly focusing on technologies such as CRIBL.
- Maintain health and reliability of SIEM systems via routine maintenance and system checks.
- Handle SIEM license management activities like forecasting demands, usage tracking, and liaising with sales teams for licensing estimates and renewals.
- Enhance SIEM data telemetry to ensure accurate and efficient log data collection, data correlation, and reporting.
- Establish and enforce consistent logging policies across all client systems and platforms to maintain data integrity and reliability.
- Mentor and guide SOC engineers in troubleshooting and resolving SIEM and log management challenges.
- Contribute technical expertise during pre-sales processes, providing license estimations and architectural advice.
- Work closely with management to develop and implement SIEM architectural strategies and process improvements to optimize SOC effectiveness.
- Deliver frequent reports on SIEM operations, license management, and overall SOC performance to relevant stakeholders.
Required Qualifications and Skills
- Extensive practical knowledge and expertise with SIEM technologies such as Splunk, Sentinel, LogRhythm, FortiSIEM, and log collection tools like CRIBL.
- Proven ability to lead technically in a dynamic, deadline-driven cybersecurity environment.
- Experience in pre-sales tasks, notably in preparing accurate SIEM license estimations.
- Thorough understanding of Security Operations Center workflows, cybersecurity fundamentals, and industry best practices.
- Strong analytical and problem-solving capabilities, with capacity to make informed decisions under pressure.
- Effective mentorship and team leadership skills.
- Outstanding communication skills, both verbal and written.
Certifications and Education
- Required certifications include CISSP, CISM, and Splunk Certified Architect or other recognized SIEM certifications.
- Desirable cloud certifications such as AWS Solutions Architect, Google Professional Cloud Architect, or Azure Solutions Architect Expert.
- Networking certifications like CCNA or CCNP are beneficial.
- A bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- At least 10 years of professional experience in SIEM and SOC operations, with significant leadership and architecture management roles.
How they work
Communication
Problem Solving
Leadership
Decision Making