1 result for Security Architect in Bloomington, MN
Cyber Security Engineer<p>We are inviting applications for the role of a Cyber Security Engineer based in Minneapolis, Minnesota. The successful candidate will play a crucial role in troubleshooting security events, incidents, and infrastructure events. </p><p><br></p><p>Key responsibilities:</p><p><br></p><p>• Ensuring the operational effectiveness and efficiency of Information Security tools such as Enterprise Syslog Servers, Intrusion Detection and Protection Systems (IDS/IPS), Microsoft Sentinel SIEM, CASB, Syslog, and other security tools.</p><p>• Monitoring the SIEM, IDS/IPS, CASB, XDR/EDR Agents, and Syslog Servers feeding the SIEM, along with other security monitoring solutions to ensure system health, completeness, and security monitoring effectiveness.</p><p>• Developing new SIEM detections in line with the MITRE ATT& CK framework and recommending SIEM, CASB and other security tool improvements.</p><p>• Leading the security team to maintain and improve secure and resilient cloud and on-premises monitoring processes, procedures, including the Incident Response Plan, IR playbooks, Operations playbooks, and communication plans.</p><p>• Automating repetitive tasks within the SOAR environment using ML/AI to drive efficiencies and focus on more advanced tasks.</p><p>• Refining, updating, and maintaining playbooks, policies, procedures, Information Security Standards, and Guidelines, aligning them with industry best practices.</p><p>• Coordinating activities and escalations with managed security service providers.</p><p>• Analyzing log source data across endpoints, databases, applications, identity management, networks, mobile devices, and cloud for any malicious activity.</p><p>• Recommending adjustments to security tool configurations to minimize false positives and suggesting improvements for monitoring logging, identity management, data protection, detection, and preventative controls.</p><p>• Collaborating with platform or business owners to identify security improvements, monitoring, and remediation efforts post-security assessments.</p><p>• Maintaining strong partnerships with security engineering, incident response, infrastructure, and IT teams to improve monitoring, workflow, and response capabilities.</p><p>• Serving as a third-level, triage support to cyber security, information security event, incident response tickets, mentoring entry level Security Operations Center staff, and leading the more difficult security alerts, events, and incidents</p>