Expoint - all jobs in one place

Finding the best job has never been easier

Limitless High-tech career opportunities - Expoint

Palo Alto Staff Security Engineer SIEM & Data Management 
United States, California 
577352396

04.09.2024
Description

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Career

In this role, you will be responsible for executing security-related data engineering programs and managing data management & SIEM platforms. You will work very closely with the SOC and cross-functional teams to manage and develop tools and infrastructure that enable the Information Security team to prevent, detect, contain, and manage risks within the Palo Alto Networks Enterprise environment.

Your Impact

  • Log Management
    • Implement and manage log collection and storage solutions across various platforms, including servers, applications, and cloud services
    • Ensure logs are collected, parsed, and stored securely and complying with industry regulations and organizational policies
    • Review and optimize log retention policies and storage solutions to balance performance and compliance
  • SIEM Engineering
    • Design, deploy, and maintain the organization's SIEM platforms to ensure it effectively monitors and detects potential security threats
    • Develop and fine-tune SIEM rules, alerts, and dashboards to detect suspicious activities and reduce false positives
    • Integrate new data sources into the SIEM platform and ensure all relevant security data is captured and analyzed
  • Data Analysis
    • Analyze log and event data from multiple sources to identify patterns, anomalies, and potential security incidents
    • Perform threat hunting by proactively searching for signs of compromise or malicious activity in log data
    • Generate reports and dashboards to communicate findings to technical and non-technical stakeholders, including senior management
  • Incident Response Support
    • Collaborate with the incident response team to investigate and mitigate security incidents, providing insights derived from log and SIEM data
    • Provide recommendations for improvements based on incident analysis and lessons learned
  • Collaboration and Training
    • Work closely with IT, DevOps, and other security teams to ensure the continuous improvement of security monitoring capabilities
    • Mentor junior analysts on log management, SIEM operations, and data analysis techniques
    • Conduct training sessions on SIEM best practices and incident detection strategies
  • Compliance and Documentation
    • Ensure compliance with relevant industry standards and regulations (e.g., GDPR, HIPAA, PCI-DSS) concerning log management and data retention
    • Maintain comprehensive documentation for all log management, SIEM configurations, processes, and procedures

Your Experience

  • Bachelor’s degree in Information Security, Computer Science, Data Analytics, or a related field, or equivalent work experience or equivalent military experience required
  • 3+ years of experience in log management, SIEM engineering, and/or data analysis in a security context
  • Experience with popular SIEM platforms such as Splunk, IBM QRadar, ArcSight, or ELK/Elastic Stack
  • Strong understanding of log management principles, including log collection, parsing, storage, and analysis
  • Proficiency in SIEM configuration, rule creation, and alert tuning
  • Solid knowledge of cybersecurity concepts, including threat detection, incident response, and vulnerability management
  • Experience with scripting languages (e.g., Python, PowerShell) for data analysis and automation
  • Familiarity with regulatory requirements and standards (e.g., FedRAMP, MLPS, NIST, PCI) related to data retention and security monitoring
  • Excellent problem-solving skills and attention to detail
  • Strong communication skills, with the ability to present complex technical information to non-technical audiences

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $119,000/yr to $192,500/yr. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

Please note that we will not sponsor applicants for work visas for this position.

All your information will be kept confidential according to EEO guidelines.